| Server IP : 162.241.226.12 / Your IP : 216.73.217.142 Web Server : Apache System : Linux box5305.bluehost.com 5.14.0-687.39.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Aug 18 06:09:16 EDT 2026 x86_64 User : zphiblgz ( 1848) PHP Version : 8.1.34 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : ON Directory : /usr/local/apache/ |
Upload File : |
[Thu Sep 17 15:04:31.228385 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi: version 1.1-92
[Thu Sep 17 15:04:31.234272 2026] [:notice] [pid 955834:tid 955834] [host root@box5305.bluehost.com] mod_lsapi: Selfstarter 955834 started
[Thu Sep 17 15:04:31.306357 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.317090 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.358973 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.364318 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.365310 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.371373 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.395632 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.412943 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.413832 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.415317 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.416195 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.417075 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.418436 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.472902 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.473656 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.474556 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.479267 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.507448 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.508229 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.537600 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.565428 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.608415 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.609325 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.610076 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.614740 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.619296 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.642469 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.646032 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.646865 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.647793 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.648676 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.649501 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.650335 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.651260 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.651960 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.690861 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.726928 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.728650 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.733976 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.759966 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.781101 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.798175 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.799033 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.805782 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.808484 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.824258 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.827636 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.841372 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.844204 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.858381 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.860531 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.865430 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.873862 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.885409 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.889269 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.895423 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.901323 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.902842 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.930853 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.949928 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.951506 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.953885 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.959778 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.981620 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.992923 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.995413 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.997084 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.998452 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.999159 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.999979 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.004341 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.031762 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.033340 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.137794 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.145642 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.147718 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.150052 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.211711 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.228584 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.267030 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.282453 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:04:32.528388 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:04:32.533182 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:04:32.533193 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:04:33.584959 2026] [http2:info] [pid 955873:tid 955873] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:04:33.607870 2026] [security2:error] [pid 955873:tid 956009] [client 193.36.224.148:58615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhroYgAAARA"]
[Thu Sep 17 15:04:33.608008 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:44892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-blogs.php"] [unique_id "aqxV4RFTPRVSLOsRVhroXwAAAQs"]
[Thu Sep 17 15:04:33.608117 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:44892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-blogs.php"] [unique_id "aqxV4RFTPRVSLOsRVhroXwAAAQs"]
[Thu Sep 17 15:04:33.608822 2026] [fcgid:warn] [pid 955873:tid 956015] (70014)End of file found: [client 66.132.172.189:5576] mod_fcgid: can't get data from http client
[Thu Sep 17 15:04:33.609190 2026] [security2:error] [pid 955873:tid 956003] [client 141.98.252.162:56410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV4RFTPRVSLOsRVhroXgAAAQo"]
[Thu Sep 17 15:04:33.672181 2026] [security2:error] [pid 955873:tid 956015] [client 85.208.98.203:12988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/modernizr.custom.min.js"] [unique_id "aqxV4RFTPRVSLOsRVhrocQAAARY"]
[Thu Sep 17 15:04:33.747355 2026] [security2:error] [pid 955873:tid 956031] [client 52.231.79.181:1796] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "toolmix24.sinkgp.com"] [uri "/1.php"] [unique_id "aqxV4RFTPRVSLOsRVhroegAAASY"]
[Thu Sep 17 15:04:33.747462 2026] [security2:error] [pid 955873:tid 956031] [client 52.231.79.181:1796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/1.php"] [unique_id "aqxV4RFTPRVSLOsRVhroegAAASY"]
[Thu Sep 17 15:04:33.766729 2026] [security2:error] [pid 955873:tid 956019] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "aqxV4RFTPRVSLOsRVhroewAAARo"]
[Thu Sep 17 15:04:33.829147 2026] [security2:error] [pid 955873:tid 956041] [client 185.55.149.49:50267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogQAAATA"]
[Thu Sep 17 15:04:33.829249 2026] [security2:error] [pid 955873:tid 956041] [client 185.55.149.49:50267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogQAAATA"]
[Thu Sep 17 15:04:33.833377 2026] [security2:error] [pid 955873:tid 956076] [client 104.234.19.147:52503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhroggAAAVM"]
[Thu Sep 17 15:04:33.840522 2026] [security2:error] [pid 955873:tid 956048] [client 34.166.134.22:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/server-info.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogwAAATc"]
[Thu Sep 17 15:04:33.894088 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:57317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrohwAAARE"]
[Thu Sep 17 15:04:33.894197 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:57317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrohwAAARE"]
[Thu Sep 17 15:04:33.896898 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-constants.php"] [unique_id "aqxV4RFTPRVSLOsRVhroiAAAAVw"]
[Thu Sep 17 15:04:33.897015 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:58292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-constants.php"] [unique_id "aqxV4RFTPRVSLOsRVhroiAAAAVw"]
[Thu Sep 17 15:04:33.898363 2026] [security2:error] [pid 955873:tid 956049] [client 129.121.122.126:50765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhroeQAAATg"]
[Thu Sep 17 15:04:33.928269 2026] [security2:error] [pid 955873:tid 956089] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "aqxV4RFTPRVSLOsRVhrojAAAAWA"]
[Thu Sep 17 15:04:33.930797 2026] [security2:error] [pid 955873:tid 956022] [client 141.98.252.162:55638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV4RFTPRVSLOsRVhrojQAAAR0"]
[Thu Sep 17 15:04:33.943265 2026] [security2:error] [pid 955873:tid 956037] [client 104.234.53.11:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxV4RFTPRVSLOsRVhroiwAAASw"]
[Thu Sep 17 15:04:33.999408 2026] [security2:error] [pid 955873:tid 956101] [client 192.178.6.3:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxV4RFTPRVSLOsRVhrokgAAAWw"]
[Thu Sep 17 15:04:34.002584 2026] [security2:error] [pid 955873:tid 956072] [client 17.166.232.51:53846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogAABTwU"]
[Thu Sep 17 15:04:34.056746 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:37748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4hFTPRVSLOsRVhrolwAAAXo"]
[Thu Sep 17 15:04:34.057432 2026] [security2:error] [pid 955873:tid 956116] [client 104.234.19.146:35105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxV4hFTPRVSLOsRVhromAAAAXs"]
[Thu Sep 17 15:04:34.095295 2026] [security2:error] [pid 955873:tid 956123] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/symfony/.env"] [unique_id "aqxV4hFTPRVSLOsRVhronwAAAYI"]
[Thu Sep 17 15:04:34.156516 2026] [security2:error] [pid 955873:tid 956110] [client 52.231.79.181:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/new.php"] [unique_id "aqxV4hFTPRVSLOsRVhroogAAAXU"]
[Thu Sep 17 15:04:34.185447 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-filters.php"] [unique_id "aqxV4hFTPRVSLOsRVhropAAAAYc"]
[Thu Sep 17 15:04:34.185587 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:58306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-filters.php"] [unique_id "aqxV4hFTPRVSLOsRVhropAAAAYc"]
[Thu Sep 17 15:04:34.200927 2026] [security2:error] [pid 955873:tid 956120] [client 107.10.44.149:34735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhronAABfwo"]
[Thu Sep 17 15:04:34.265149 2026] [security2:error] [pid 955873:tid 956023] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/wordpress/.env"] [unique_id "aqxV4hFTPRVSLOsRVhroqQAAAR4"]
[Thu Sep 17 15:04:34.327737 2026] [security2:error] [pid 955873:tid 956018] [client 193.36.224.156:29277] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/file.php"] [unique_id "aqxV4hFTPRVSLOsRVhroqgAAARk"]
[Thu Sep 17 15:04:34.352981 2026] [security2:error] [pid 955873:tid 956113] [client 129.121.122.126:50796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhroowAAAXg"]
[Thu Sep 17 15:04:34.436883 2026] [security2:error] [pid 955873:tid 956005] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/wp/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrorwAAAQw"]
[Thu Sep 17 15:04:34.466171 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.224.217:37762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4hFTPRVSLOsRVhrosgAAAQo"]
[Thu Sep 17 15:04:34.474799 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:58314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-files.php"] [unique_id "aqxV4hFTPRVSLOsRVhroswAAARY"]
[Thu Sep 17 15:04:34.474958 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:58314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-files.php"] [unique_id "aqxV4hFTPRVSLOsRVhroswAAARY"]
[Thu Sep 17 15:04:34.516910 2026] [security2:error] [pid 955873:tid 956033] [client 129.121.122.126:50796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.122.121.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxV4hFTPRVSLOsRVhrorAAAASg"]
[Thu Sep 17 15:04:34.554712 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.134.22:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/server-status.php"] [unique_id "aqxV4hFTPRVSLOsRVhrotwAAAR8"]
[Thu Sep 17 15:04:34.569937 2026] [security2:error] [pid 955873:tid 956030] [client 52.231.79.181:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/num.php"] [unique_id "aqxV4hFTPRVSLOsRVhrouAAAASU"]
[Thu Sep 17 15:04:34.600047 2026] [security2:error] [pid 955873:tid 956065] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrouQAAAUg"]
[Thu Sep 17 15:04:34.652928 2026] [security2:error] [pid 955873:tid 956129] [client 198.46.193.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "commonearthjc.com"] [uri "/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhropwAAAYg"]
[Thu Sep 17 15:04:34.669634 2026] [security2:error] [pid 955873:tid 956031] [client 141.98.252.162:56422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/vendor/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrovAAAASY"]
[Thu Sep 17 15:04:34.680208 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/.env.swp"] [unique_id "aqxV4hFTPRVSLOsRVhrovQAAARo"]
[Thu Sep 17 15:04:34.763035 2026] [security2:error] [pid 955873:tid 956069] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/drupal/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrovwAAAUw"]
[Thu Sep 17 15:04:34.770998 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-functions.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowQAAAUs"]
[Thu Sep 17 15:04:34.771102 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-functions.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowQAAAUs"]
[Thu Sep 17 15:04:34.785154 2026] [security2:error] [pid 955873:tid 956014] [client 216.73.163.70:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowgAAARU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:34.824069 2026] [security2:error] [pid 955873:tid 956034] [client 5.189.145.112:52901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-login.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowAAAASk"], referer: binance.com
[Thu Sep 17 15:04:34.848711 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/.env~"] [unique_id "aqxV4hFTPRVSLOsRVhroxAAAAUE"]
[Thu Sep 17 15:04:34.875083 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:37776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4hFTPRVSLOsRVhroxQAAATA"]
[Thu Sep 17 15:04:34.926026 2026] [security2:error] [pid 955873:tid 956081] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/joomla/.env"] [unique_id "aqxV4hFTPRVSLOsRVhroxwAAAVg"]
[Thu Sep 17 15:04:34.930342 2026] [security2:error] [pid 955873:tid 956021] [client 178.20.44.82:51085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhrovgAAARw"], referer: https://berenice-vaucher.com/thank-you-for-your-comment/
[Thu Sep 17 15:04:34.977643 2026] [security2:error] [pid 955873:tid 956077] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhrohgABVAY"], referer: http://jenniferniesslein.com/old/
[Thu Sep 17 15:04:35.064974 2026] [autoindex:error] [pid 955873:tid 956008] [client 52.231.79.181:0] AH01276: Cannot serve directory /home3/gruposi4/public_html/toolmix24/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:04:35.076438 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:58330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-load.php"] [unique_id "aqxV4xFTPRVSLOsRVhro1gAAAWQ"]
[Thu Sep 17 15:04:35.076518 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:58330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-load.php"] [unique_id "aqxV4xFTPRVSLOsRVhro1gAAAWQ"]
[Thu Sep 17 15:04:35.093890 2026] [security2:error] [pid 955873:tid 956095] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/magento/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro2AAAAWY"]
[Thu Sep 17 15:04:35.153630 2026] [security2:error] [pid 955873:tid 956072] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro2QABTw0"], referer: http://jenniferniesslein.com/wordpress/
[Thu Sep 17 15:04:35.239362 2026] [security2:error] [pid 955873:tid 956102] [client 52.231.79.181:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/admin.php"] [unique_id "aqxV4xFTPRVSLOsRVhro3wAAAW0"]
[Thu Sep 17 15:04:35.256727 2026] [security2:error] [pid 955873:tid 956123] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/shopify/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro4QAAAYI"]
[Thu Sep 17 15:04:35.327976 2026] [security2:error] [pid 955873:tid 956115] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro4gABeg4"], referer: http://jenniferniesslein.com/wp/
[Thu Sep 17 15:04:35.418033 2026] [security2:error] [pid 955873:tid 956103] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/prestashop/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro5gAAAW4"]
[Thu Sep 17 15:04:35.486185 2026] [security2:error] [pid 955873:tid 956037] [client 107.10.44.149:54769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro6AABLA8"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260817231440&hideanons=1&hidebots=0&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:04:35.506625 2026] [security2:error] [pid 955873:tid 956006] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro6wABDRA"], referer: http://jenniferniesslein.com/backup/
[Thu Sep 17 15:04:35.514470 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:37790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4xFTPRVSLOsRVhro7QAAARk"]
[Thu Sep 17 15:04:35.550368 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-network.php"] [unique_id "aqxV4xFTPRVSLOsRVhro8AAAATk"]
[Thu Sep 17 15:04:35.550449 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:58338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-network.php"] [unique_id "aqxV4xFTPRVSLOsRVhro8AAAATk"]
[Thu Sep 17 15:04:35.581879 2026] [security2:error] [pid 955873:tid 956017] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/codeigniter/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro8gAAARg"]
[Thu Sep 17 15:04:35.640826 2026] [security2:error] [pid 955873:tid 956004] [client 52.231.79.181:1692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/13.php"] [unique_id "aqxV4xFTPRVSLOsRVhro9wAAAQs"]
[Thu Sep 17 15:04:35.657550 2026] [security2:error] [pid 955873:tid 956060] [client 104.234.19.145:28827] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxV4xFTPRVSLOsRVhro-wAAAUM"]
[Thu Sep 17 15:04:35.719418 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.134.22:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxV4xFTPRVSLOsRVhro_AAAAUc"]
[Thu Sep 17 15:04:35.743140 2026] [security2:error] [pid 955873:tid 956065] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cakephp/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro_gAAAUg"]
[Thu Sep 17 15:04:35.813324 2026] [security2:error] [pid 955873:tid 956046] [client 141.98.252.162:54307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/vendor/.env"] [unique_id "aqxV4xFTPRVSLOsRVhrpAAAAATU"]
[Thu Sep 17 15:04:35.833011 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env"] [unique_id "aqxV4xFTPRVSLOsRVhrpAwAAAUU"]
[Thu Sep 17 15:04:35.833060 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-settings.php"] [unique_id "aqxV4xFTPRVSLOsRVhrpBAAAAU0"]
[Thu Sep 17 15:04:35.833134 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:58354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-settings.php"] [unique_id "aqxV4xFTPRVSLOsRVhrpBAAAAU0"]
[Thu Sep 17 15:04:35.850330 2026] [security2:error] [pid 955873:tid 956027] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/js/email-subscribers-public.js"] [unique_id "aqxV4xFTPRVSLOsRVhrpBwAAASI"]
[Thu Sep 17 15:04:35.870986 2026] [security2:error] [pid 955873:tid 956019] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhrpAQABGhM"], referer: http://jenniferniesslein.com/new/
[Thu Sep 17 15:04:35.904473 2026] [security2:error] [pid 955873:tid 956068] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/zend/.env"] [unique_id "aqxV4xFTPRVSLOsRVhrpCAAAAUs"]
[Thu Sep 17 15:04:36.037326 2026] [security2:error] [pid 955873:tid 956124] [client 193.36.224.151:53785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-mail.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpDgAAAYM"]
[Thu Sep 17 15:04:36.058592 2026] [security2:error] [pid 955873:tid 956011] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpCwABEhQ"], referer: http://jenniferniesslein.com/blog/
[Thu Sep 17 15:04:36.071263 2026] [security2:error] [pid 955873:tid 956079] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/yii/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpEwAAAVY"]
[Thu Sep 17 15:04:36.075631 2026] [security2:error] [pid 955873:tid 956045] [client 52.231.79.181:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/222.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFQAAATQ"]
[Thu Sep 17 15:04:36.110110 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-site.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFgAAAVs"]
[Thu Sep 17 15:04:36.110174 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:58370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-site.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFgAAAVs"]
[Thu Sep 17 15:04:36.159994 2026] [security2:error] [pid 955873:tid 956033] [client 45.131.194.119:28015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFwAAASg"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:36.233679 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/laravel5/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpGgAAAQ8"]
[Thu Sep 17 15:04:36.348992 2026] [security2:error] [pid 955873:tid 956022] [client 104.234.19.148:32731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/ioxi-o.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpIQAAAR0"]
[Thu Sep 17 15:04:36.393100 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/nav-menu-template.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpIgAAAV4"]
[Thu Sep 17 15:04:36.393172 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:58376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/nav-menu-template.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpIgAAAV4"]
[Thu Sep 17 15:04:36.395070 2026] [security2:error] [pid 955873:tid 956104] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpIwAAAW8"]
[Thu Sep 17 15:04:36.415847 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.134.22:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpJAAAATg"]
[Thu Sep 17 15:04:36.458085 2026] [security2:error] [pid 955873:tid 956097] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/app/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpJQAAAWg"]
[Thu Sep 17 15:04:36.462419 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpJwAAAU4"]
[Thu Sep 17 15:04:36.462514 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:61569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpJwAAAU4"]
[Thu Sep 17 15:04:36.477957 2026] [security2:error] [pid 955873:tid 956106] [client 52.231.79.181:1723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/aa.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpKAAAAXE"]
[Thu Sep 17 15:04:36.556832 2026] [security2:error] [pid 955873:tid 956078] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpKwAAAVU"]
[Thu Sep 17 15:04:36.571827 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.bak"] [unique_id "aqxV5BFTPRVSLOsRVhrpLAAAAYI"]
[Thu Sep 17 15:04:36.616104 2026] [security2:error] [pid 955873:tid 956108] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/apps/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpLgAAAXM"]
[Thu Sep 17 15:04:36.636750 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.backup"] [unique_id "aqxV5BFTPRVSLOsRVhrpLwAAAUI"]
[Thu Sep 17 15:04:36.646031 2026] [security2:error] [pid 955873:tid 956039] [client 104.234.19.144:47643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpMAAAAS4"]
[Thu Sep 17 15:04:36.686440 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/option.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpMQAAAYU"]
[Thu Sep 17 15:04:36.686550 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:58390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/option.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpMQAAAYU"]
[Thu Sep 17 15:04:36.718834 2026] [security2:error] [pid 955873:tid 956127] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpMgAAAYY"]
[Thu Sep 17 15:04:36.720251 2026] [security2:error] [pid 955873:tid 956128] [client 141.98.252.162:56880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpMwAAAYc"]
[Thu Sep 17 15:04:36.774417 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpNwAAATI"]
[Thu Sep 17 15:04:36.810178 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.old"] [unique_id "aqxV5BFTPRVSLOsRVhrpOQAAASA"]
[Thu Sep 17 15:04:36.880770 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/v1/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpOgAAAVw"]
[Thu Sep 17 15:04:36.883875 2026] [security2:error] [pid 955873:tid 956099] [client 52.231.79.181:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/abcd.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpOwAAAWo"]
[Thu Sep 17 15:04:36.886253 2026] [security2:error] [pid 955873:tid 956029] [client 216.24.219.102:31797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/style.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpPAAAASQ"]
[Thu Sep 17 15:04:36.932222 2026] [security2:error] [pid 955873:tid 956130] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/web/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpPwAAAYk"]
[Thu Sep 17 15:04:36.976443 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:58402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/"] [unique_id "aqxV5BFTPRVSLOsRVhrpQQAAARk"]
[Thu Sep 17 15:04:37.044158 2026] [security2:error] [pid 955873:tid 956051] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/v2/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpTAAAATo"]
[Thu Sep 17 15:04:37.098043 2026] [security2:error] [pid 955873:tid 956129] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/site/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpUAAAAYg"]
[Thu Sep 17 15:04:37.101969 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.134.22:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpUQAAAQ4"]
[Thu Sep 17 15:04:37.156517 2026] [security2:error] [pid 955873:tid 956031] [client 104.234.19.149:26695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/style.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpVAAAASY"]
[Thu Sep 17 15:04:37.207162 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/rest/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpVQAAAUU"]
[Thu Sep 17 15:04:37.261234 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/public/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpVgAAARo"]
[Thu Sep 17 15:04:37.295751 2026] [security2:error] [pid 955873:tid 956046] [client 52.231.79.181:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/about.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWgAAATU"]
[Thu Sep 17 15:04:37.342313 2026] [security2:error] [pid 955873:tid 956016] [client 154.190.208.131:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWAAAARc"]
[Thu Sep 17 15:04:37.342454 2026] [security2:error] [pid 955873:tid 956016] [client 154.190.208.131:41558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWAAAARc"]
[Thu Sep 17 15:04:37.346390 2026] [security2:error] [pid 955873:tid 956096] [client 47.79.218.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpSgAAAWc"], referer: https://www.google.com/
[Thu Sep 17 15:04:37.352287 2026] [security2:error] [pid 955873:tid 956073] [client 45.146.54.110:65131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWQAAAVA"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:37.375123 2026] [security2:error] [pid 955873:tid 956048] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/graphql/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpXAAAATc"]
[Thu Sep 17 15:04:37.507018 2026] [security2:error] [pid 955873:tid 956045] [client 193.36.224.113:49547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/themes/style.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpYgAAATQ"]
[Thu Sep 17 15:04:37.543842 2026] [security2:error] [pid 955873:tid 956121] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/gateway/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpZgAAAYA"]
[Thu Sep 17 15:04:37.565177 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/"] [unique_id "aqxV5RFTPRVSLOsRVhrpZQAAAU0"]
[Thu Sep 17 15:04:37.617553 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/backend/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpaQAAAVc"]
[Thu Sep 17 15:04:37.709428 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:58402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/wp-includes/"] [unique_id "aqxV5RFTPRVSLOsRVhrpawAAARE"]
[Thu Sep 17 15:04:37.713129 2026] [security2:error] [pid 955873:tid 956033] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/microservice/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpbAAAASg"]
[Thu Sep 17 15:04:37.729294 2026] [security2:error] [pid 955873:tid 956091] [client 193.36.224.222:57855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-editor.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpbQAAAWI"]
[Thu Sep 17 15:04:37.750587 2026] [security2:error] [pid 955873:tid 956081] [client 52.231.79.181:1710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/admin.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpbgAAAVg"]
[Thu Sep 17 15:04:37.777004 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/server/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpbwAAAWA"]
[Thu Sep 17 15:04:37.814419 2026] [security2:error] [pid 955873:tid 956109] [client 34.166.134.22:35596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpcQAAAXQ"]
[Thu Sep 17 15:04:37.847641 2026] [security2:error] [pid 955873:tid 956079] [client 141.98.252.162:58057] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpdAAAAVY"]
[Thu Sep 17 15:04:37.881098 2026] [security2:error] [pid 955873:tid 956098] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpdgAAAWk"]
[Thu Sep 17 15:04:37.899146 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.swp"] [unique_id "aqxV5RFTPRVSLOsRVhrpeAAAAR0"]
[Thu Sep 17 15:04:37.913794 2026] [security2:error] [pid 955873:tid 956035] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/style.css"] [unique_id "aqxV5RFTPRVSLOsRVhrpeQAAASo"]
[Thu Sep 17 15:04:37.938355 2026] [security2:error] [pid 955873:tid 956104] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/frontend/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpegAAAW8"]
[Thu Sep 17 15:04:37.983573 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env~"] [unique_id "aqxV5RFTPRVSLOsRVhrpfAAAAW0"]
[Thu Sep 17 15:04:38.023774 2026] [security2:error] [pid 955873:tid 956092] [client 193.36.224.170:28531] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/lufix.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpfwAAAWM"]
[Thu Sep 17 15:04:38.047353 2026] [security2:error] [pid 955873:tid 956108] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/v3/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpgQAAAXM"]
[Thu Sep 17 15:04:38.074090 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpdQAAAWw"]
[Thu Sep 17 15:04:38.074118 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpdQAAAWw"]
[Thu Sep 17 15:04:38.098010 2026] [security2:error] [pid 955873:tid 956039] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/src/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrphAAAAS4"]
[Thu Sep 17 15:04:38.178337 2026] [security2:error] [pid 955873:tid 956078] [client 52.231.79.181:1716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/adminfuns.php"] [unique_id "aqxV5hFTPRVSLOsRVhrphgAAAVU"]
[Thu Sep 17 15:04:38.183406 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrphwAAAYI"]
[Thu Sep 17 15:04:38.183507 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:65308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrphwAAAYI"]
[Thu Sep 17 15:04:38.211203 2026] [security2:error] [pid 955873:tid 956088] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/dev/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpiAAAAV8"]
[Thu Sep 17 15:04:38.245099 2026] [security2:error] [pid 955873:tid 956103] [client 104.234.19.143:35355] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/txets.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpiwAAAW4"]
[Thu Sep 17 15:04:38.261019 2026] [security2:error] [pid 955873:tid 956119] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/core/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpjAAAAX4"]
[Thu Sep 17 15:04:38.350037 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/autoload.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpjgAAARk"]
[Thu Sep 17 15:04:38.350165 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:58402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/autoload.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpjgAAARk"]
[Thu Sep 17 15:04:38.374911 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/staging/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpjwAAAUM"]
[Thu Sep 17 15:04:38.416081 2026] [security2:error] [pid 955873:tid 956051] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/core/app/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpkgAAATo"]
[Thu Sep 17 15:04:38.507325 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.134.22:35606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxV5hFTPRVSLOsRVhrplAAAATI"]
[Thu Sep 17 15:04:38.519843 2026] [security2:error] [pid 955873:tid 956013] [client 193.36.224.150:57061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxV5hFTPRVSLOsRVhrplQAAARQ"]
[Thu Sep 17 15:04:38.544321 2026] [security2:error] [pid 955873:tid 956012] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/vendor/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrplgAAARM"]
[Thu Sep 17 15:04:38.575511 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/config/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpmwAAATE"]
[Thu Sep 17 15:04:38.577686 2026] [security2:error] [pid 955873:tid 956064] [client 52.231.79.181:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpnAAAAUc"]
[Thu Sep 17 15:04:38.628986 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/"] [unique_id "aqxV5hFTPRVSLOsRVhrpngAAAQs"]
[Thu Sep 17 15:04:38.631866 2026] [security2:error] [pid 955873:tid 956037] [client 115.244.164.14:57979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpnwAAASw"]
[Thu Sep 17 15:04:38.631939 2026] [security2:error] [pid 955873:tid 956037] [client 115.244.164.14:57979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpnwAAASw"]
[Thu Sep 17 15:04:38.665046 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/app/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpoAAAAR4"]
[Thu Sep 17 15:04:38.711711 2026] [security2:error] [pid 955873:tid 956020] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/lib/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpogAAARs"]
[Thu Sep 17 15:04:38.747894 2026] [security2:error] [pid 955873:tid 956066] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/private/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrppAAAAUk"]
[Thu Sep 17 15:04:38.762571 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/apps/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrppQAAAVM"]
[Thu Sep 17 15:04:38.775748 2026] [security2:error] [pid 955873:tid 956017] [client 193.36.224.168:24453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-admin/txets.php"] [unique_id "aqxV5hFTPRVSLOsRVhrppwAAARg"]
[Thu Sep 17 15:04:38.833325 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/"] [unique_id "aqxV5hFTPRVSLOsRVhrppgAAATc"]
[Thu Sep 17 15:04:38.881930 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/resources/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpqQAAAYM"]
[Thu Sep 17 15:04:38.908077 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/application/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpqwAAAVk"]
[Thu Sep 17 15:04:38.915376 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrprAAAATQ"]
[Thu Sep 17 15:04:38.929062 2026] [security2:error] [pid 955873:tid 956046] [client 104.28.198.244:22970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrprgAAATU"]
[Thu Sep 17 15:04:38.981026 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:58408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/wp-includes/php-ai-client/"] [unique_id "aqxV5hFTPRVSLOsRVhrpsAAAASg"]
[Thu Sep 17 15:04:39.002615 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/web/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpsQAAAWI"]
[Thu Sep 17 15:04:39.024170 2026] [security2:error] [pid 955873:tid 956118] [client 52.231.79.181:1714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/ae.php"] [unique_id "aqxV5xFTPRVSLOsRVhrptQAAAX0"]
[Thu Sep 17 15:04:39.056225 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/assets/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrptgAAAQ8"]
[Thu Sep 17 15:04:39.065966 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/bootstrap/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrptwAAAXQ"]
[Thu Sep 17 15:04:39.074811 2026] [security2:error] [pid 955873:tid 956058] [client 193.36.224.156:36251] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-includes/txets.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpuQAAAUE"]
[Thu Sep 17 15:04:39.098970 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/site/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpugAAATA"]
[Thu Sep 17 15:04:39.119553 2026] [security2:error] [pid 955873:tid 956046] [client 104.28.198.244:22970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrprgAAATU"]
[Thu Sep 17 15:04:39.189864 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.134.22:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpvQAAAVQ"]
[Thu Sep 17 15:04:39.221280 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/public/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpvwAAAU8"]
[Thu Sep 17 15:04:39.221281 2026] [security2:error] [pid 955873:tid 956090] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/uploads/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpvgAAAWE"]
[Thu Sep 17 15:04:39.225762 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/database/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpwAAAASo"]
[Thu Sep 17 15:04:39.345002 2026] [security2:error] [pid 955873:tid 956108] [client 193.36.224.220:62413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/goods.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpwwAAAXM"]
[Thu Sep 17 15:04:39.362259 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpvAAAAWU"]
[Thu Sep 17 15:04:39.362288 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpvAAAAWU"]
[Thu Sep 17 15:04:39.388850 2026] [security2:error] [pid 955873:tid 956110] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/internal/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpxQAAAXU"]
[Thu Sep 17 15:04:39.396373 2026] [security2:error] [pid 955873:tid 956101] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/storage/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpxgAAAWw"]
[Thu Sep 17 15:04:39.407763 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/backend/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpyQAAAYU"]
[Thu Sep 17 15:04:39.439338 2026] [security2:error] [pid 955873:tid 956092] [client 52.231.79.181:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/akcc.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpywAAAWM"]
[Thu Sep 17 15:04:39.454780 2026] [security2:error] [pid 955873:tid 956088] [client 134.185.85.61:63417] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "flatpad.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxV5xFTPRVSLOsRVhrpzQAAAV8"]
[Thu Sep 17 15:04:39.501636 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/server/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpzgAAAT8"]
[Thu Sep 17 15:04:39.502778 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/AiClient.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpzwAAAX4"]
[Thu Sep 17 15:04:39.502862 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:58408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/AiClient.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpzwAAAX4"]
[Thu Sep 17 15:04:39.513873 2026] [security2:error] [pid 955873:tid 956127] [client 200.82.236.45:55529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpygABhiM"]
[Thu Sep 17 15:04:39.550635 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/tools/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp0gAAAVw"]
[Thu Sep 17 15:04:39.555460 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/var/www/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp0wAAAXk"]
[Thu Sep 17 15:04:39.579962 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/frontend/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp1QAAARk"]
[Thu Sep 17 15:04:39.628465 2026] [security2:error] [pid 955873:tid 956060] [client 104.234.19.144:30979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/php8.php"] [unique_id "aqxV5xFTPRVSLOsRVhrp1gAAAUM"]
[Thu Sep 17 15:04:39.666167 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/src/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp1wAAAUg"]
[Thu Sep 17 15:04:39.712375 2026] [security2:error] [pid 955873:tid 956052] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/scripts/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp2QAAATs"]
[Thu Sep 17 15:04:39.724387 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/var/www/html/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp2gAAAXg"]
[Thu Sep 17 15:04:39.728858 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/core/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp2wAAARM"]
[Thu Sep 17 15:04:39.785127 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:58422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/"] [unique_id "aqxV5xFTPRVSLOsRVhrp3QAAATE"]
[Thu Sep 17 15:04:39.788550 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/core/app/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp3gAAAUc"]
[Thu Sep 17 15:04:39.798282 2026] [security2:error] [pid 955873:tid 956095] [client 45.146.54.109:44759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV5xFTPRVSLOsRVhrp3AAAAWY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:39.843538 2026] [security2:error] [pid 955873:tid 956004] [client 134.185.85.61:56053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "flatpad.com"] [uri "/media/system/js/core.js"] [unique_id "aqxV5xFTPRVSLOsRVhrp3wAAAQs"]
[Thu Sep 17 15:04:39.859826 2026] [security2:error] [pid 955873:tid 956043] [client 52.231.79.181:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/bak.php"] [unique_id "aqxV5xFTPRVSLOsRVhrp4AAAATI"]
[Thu Sep 17 15:04:39.873782 2026] [security2:error] [pid 955873:tid 956037] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/bin/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp4QAAASw"]
[Thu Sep 17 15:04:39.885304 2026] [security2:error] [pid 955873:tid 956036] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/current/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp4gAAASs"]
[Thu Sep 17 15:04:39.887946 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.134.22:35624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxV5xFTPRVSLOsRVhrp4wAAAXw"]
[Thu Sep 17 15:04:39.914503 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/config/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp5AAAARo"]
[Thu Sep 17 15:04:39.937074 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/"] [unique_id "aqxV5xFTPRVSLOsRVhrp5QAAAR4"]
[Thu Sep 17 15:04:40.011337 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/private/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp6AAAAVA"]
[Thu Sep 17 15:04:40.033310 2026] [security2:error] [pid 955873:tid 956005] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/demo1.min.js"] [unique_id "aqxV6BFTPRVSLOsRVhrp6gAAAQw"]
[Thu Sep 17 15:04:40.038147 2026] [security2:error] [pid 955873:tid 956063] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sbin/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp6wAAAUY"]
[Thu Sep 17 15:04:40.044924 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/release/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp7AAAARg"]
[Thu Sep 17 15:04:40.082464 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:58422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/wp-includes/php-ai-client/src/"] [unique_id "aqxV6BFTPRVSLOsRVhrp7QAAAUQ"]
[Thu Sep 17 15:04:40.084057 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/application/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp7gAAAT4"]
[Thu Sep 17 15:04:40.201601 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp7wAAASk"]
[Thu Sep 17 15:04:40.212335 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/releases/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp8AAAAVk"]
[Thu Sep 17 15:04:40.232452 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/bootstrap/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp8gAAAYA"]
[Thu Sep 17 15:04:40.299371 2026] [security2:error] [pid 955873:tid 956124] [client 52.231.79.181:2028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/cc.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp9AAAAYM"]
[Thu Sep 17 15:04:40.315391 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/database/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp9QAAAVs"]
[Thu Sep 17 15:04:40.370540 2026] [security2:error] [pid 955873:tid 956010] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp9wAAARE"]
[Thu Sep 17 15:04:40.371353 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/shared/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp-AAAAWI"]
[Thu Sep 17 15:04:40.401998 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/storage/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp_AAAAX0"]
[Thu Sep 17 15:04:40.415378 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp8QAAARA"]
[Thu Sep 17 15:04:40.415396 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp8QAAARA"]
[Thu Sep 17 15:04:40.447462 2026] [security2:error] [pid 955873:tid 956129] [client 216.73.163.43:47053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp_QAAAYg"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:40.511276 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/var/www/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqAAAAAVY"]
[Thu Sep 17 15:04:40.533288 2026] [security2:error] [pid 955873:tid 956105] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/deploy/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqAQAAAXA"]
[Thu Sep 17 15:04:40.533331 2026] [security2:error] [pid 955873:tid 956041] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/dashboard/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqAgAAATA"]
[Thu Sep 17 15:04:40.558238 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/MessageBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqBQAAAVQ"]
[Thu Sep 17 15:04:40.558348 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:58422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/MessageBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqBQAAAVQ"]
[Thu Sep 17 15:04:40.594047 2026] [security2:error] [pid 955873:tid 956054] [client 34.166.134.22:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php.old"] [unique_id "aqxV6BFTPRVSLOsRVhrqBwAAAT0"]
[Thu Sep 17 15:04:40.600223 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/var/www/html/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqCAAAAVo"]
[Thu Sep 17 15:04:40.687506 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/current/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqDAAAAXo"]
[Thu Sep 17 15:04:40.692552 2026] [security2:error] [pid 955873:tid 956038] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/build/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqDQAAAS0"]
[Thu Sep 17 15:04:40.695031 2026] [security2:error] [pid 955873:tid 956122] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/panel/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqDgAAAYE"]
[Thu Sep 17 15:04:40.706362 2026] [security2:error] [pid 955873:tid 956090] [client 52.231.79.181:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/chosen.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqEAAAAWE"]
[Thu Sep 17 15:04:40.761349 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/release/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqEwAAAUA"]
[Thu Sep 17 15:04:40.836295 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/PromptBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqFQAAAWM"]
[Thu Sep 17 15:04:40.836378 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:36664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/PromptBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqFQAAAWM"]
[Thu Sep 17 15:04:40.849625 2026] [security2:error] [pid 955873:tid 956088] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/dist/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqFgAAAV8"]
[Thu Sep 17 15:04:40.856884 2026] [security2:error] [pid 955873:tid 956120] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqFwAAAX8"]
[Thu Sep 17 15:04:40.899986 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/releases/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqGQAAAXY"]
[Thu Sep 17 15:04:40.981459 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/shared/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqGgAAAT8"]
[Thu Sep 17 15:04:41.004196 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/public_html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqGwAAAU4"]
[Thu Sep 17 15:04:41.017536 2026] [security2:error] [pid 955873:tid 956029] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqHgAAASQ"]
[Thu Sep 17 15:04:41.085766 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/deploy/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqIAAAATg"]
[Thu Sep 17 15:04:41.113405 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:36676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV6RFTPRVSLOsRVhrqIQAAATk"]
[Thu Sep 17 15:04:41.136598 2026] [security2:error] [pid 955873:tid 956127] [client 52.231.79.181:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/classwithtostring.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqIgAAAYY"]
[Thu Sep 17 15:04:41.162826 2026] [security2:error] [pid 955873:tid 956053] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/htdocs/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqIwAAATw"]
[Thu Sep 17 15:04:41.168044 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/build/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqJAAAARY"]
[Thu Sep 17 15:04:41.178805 2026] [security2:error] [pid 955873:tid 956051] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqJQAAATo"]
[Thu Sep 17 15:04:41.264699 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/dist/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqJwAAAXE"]
[Thu Sep 17 15:04:41.295596 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV6RFTPRVSLOsRVhrqJgAAAWo"]
[Thu Sep 17 15:04:41.295612 2026] [security2:error] [pid 955873:tid 956130] [client 34.166.134.22:32980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php~"] [unique_id "aqxV6RFTPRVSLOsRVhrqKgAAAYk"]
[Thu Sep 17 15:04:41.320634 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/www/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqLAAAASY"]
[Thu Sep 17 15:04:41.341419 2026] [security2:error] [pid 955873:tid 956064] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/store/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqLgAAAUc"]
[Thu Sep 17 15:04:41.436440 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/wp-includes/php-ai-client/src/"] [unique_id "aqxV6RFTPRVSLOsRVhrqMAAAAXw"]
[Thu Sep 17 15:04:41.481008 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqMQAAARo"]
[Thu Sep 17 15:04:41.486611 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/public_html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqMgAAAR4"]
[Thu Sep 17 15:04:41.502894 2026] [security2:error] [pid 955873:tid 956068] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/saas/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqNAAAAUs"]
[Thu Sep 17 15:04:41.540954 2026] [security2:error] [pid 955873:tid 956036] [client 52.231.79.181:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/wp-signup.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqNwAAASs"]
[Thu Sep 17 15:04:41.542233 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/htdocs/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqOAAAASs"]
[Thu Sep 17 15:04:41.579325 2026] [security2:error] [pid 955873:tid 956003] [client 45.146.54.112:47423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqNgAAAQo"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:41.623576 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/www/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqOwAAASE"]
[Thu Sep 17 15:04:41.636297 2026] [security2:error] [pid 955873:tid 956017] [client 141.98.252.162:61824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqPAAAARg"]
[Thu Sep 17 15:04:41.639105 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/live/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqPQAAAQ4"]
[Thu Sep 17 15:04:41.665057 2026] [security2:error] [pid 955873:tid 956011] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqQQAAARI"]
[Thu Sep 17 15:04:41.755170 2026] [security2:error] [pid 955873:tid 956061] [client 45.230.33.226:58507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqPgABRCs"]
[Thu Sep 17 15:04:41.755200 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqOgAAAQw"]
[Thu Sep 17 15:04:41.755217 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqOgAAAQw"]
[Thu Sep 17 15:04:41.778525 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqQwAAAYA"]
[Thu Sep 17 15:04:41.797274 2026] [security2:error] [pid 955873:tid 956096] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/prod/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqRQAAAWc"]
[Thu Sep 17 15:04:41.826604 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqRgAAAYM"]
[Thu Sep 17 15:04:41.856937 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/live/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqRwAAAVs"]
[Thu Sep 17 15:04:41.892847 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractDataTransferObject.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqSAAAAVc"]
[Thu Sep 17 15:04:41.892964 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:36676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractDataTransferObject.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqSAAAAVc"]
[Thu Sep 17 15:04:41.927952 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/prod/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqSQAAAVI"]
[Thu Sep 17 15:04:41.955820 2026] [security2:error] [pid 955873:tid 956010] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/dev/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqSgAAARE"]
[Thu Sep 17 15:04:41.957491 2026] [security2:error] [pid 955873:tid 956016] [client 52.231.79.181:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/doc.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqSwAAARc"]
[Thu Sep 17 15:04:41.984736 2026] [security2:error] [pid 955873:tid 956062] [client 34.166.134.22:32990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/info.php.bak"] [unique_id "aqxV6RFTPRVSLOsRVhrqTAAAAUU"]
[Thu Sep 17 15:04:41.988298 2026] [security2:error] [pid 955873:tid 956091] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/admin-panel/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqTQAAAWI"]
[Thu Sep 17 15:04:42.011981 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/dev/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqUAAAARA"]
[Thu Sep 17 15:04:42.094813 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/staging/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVAAAAS8"]
[Thu Sep 17 15:04:42.095320 2026] [security2:error] [pid 955873:tid 956079] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/trigger.min.js"] [unique_id "aqxV6hFTPRVSLOsRVhrqUwAAAVY"]
[Thu Sep 17 15:04:42.111308 2026] [security2:error] [pid 955873:tid 956105] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/staging/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVQAAAXA"]
[Thu Sep 17 15:04:42.154398 2026] [security2:error] [pid 955873:tid 956041] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/control-panel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVgAAATA"]
[Thu Sep 17 15:04:42.180491 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/opt/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVwAAAXs"]
[Thu Sep 17 15:04:42.185500 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractEnum.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqWAAAAVQ"]
[Thu Sep 17 15:04:42.185586 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:36692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractEnum.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqWAAAAVQ"]
[Thu Sep 17 15:04:42.265200 2026] [security2:error] [pid 955873:tid 956083] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/opt/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqWQAAAVo"]
[Thu Sep 17 15:04:42.273871 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/laravel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqWgAAATM"]
[Thu Sep 17 15:04:42.318355 2026] [security2:error] [pid 955873:tid 956102] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/user-panel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqWwAAAW0"]
[Thu Sep 17 15:04:42.376854 2026] [security2:error] [pid 955873:tid 956054] [client 52.231.79.181:1667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/edit.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqXAAAAT0"]
[Thu Sep 17 15:04:42.385312 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/symfony/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqXQAAAS0"]
[Thu Sep 17 15:04:42.424455 2026] [security2:error] [pid 955873:tid 956059] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/laravel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqXgAAAUI"]
[Thu Sep 17 15:04:42.472980 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:36698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/"] [unique_id "aqxV6hFTPRVSLOsRVhrqXwAAAW8"]
[Thu Sep 17 15:04:42.479820 2026] [security2:error] [pid 955873:tid 956098] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqYAAAAWk"]
[Thu Sep 17 15:04:42.534828 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/wordpress/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqYwAAAUA"]
[Thu Sep 17 15:04:42.583420 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/symfony/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqZQAAAVE"]
[Thu Sep 17 15:04:42.628637 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/"] [unique_id "aqxV6hFTPRVSLOsRVhrqZwAAATU"]
[Thu Sep 17 15:04:42.642964 2026] [security2:error] [pid 955873:tid 956078] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/express/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqaAAAAVU"]
[Thu Sep 17 15:04:42.661925 2026] [security2:error] [pid 955873:tid 956090] [client 185.55.149.49:50872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqaQAAAWE"]
[Thu Sep 17 15:04:42.662291 2026] [security2:error] [pid 955873:tid 956090] [client 185.55.149.49:50872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqaQAAAWE"]
[Thu Sep 17 15:04:42.666074 2026] [security2:error] [pid 955873:tid 956108] [client 34.166.134.22:32994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php.save"] [unique_id "aqxV6hFTPRVSLOsRVhrqagAAAXM"]
[Thu Sep 17 15:04:42.671591 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/wp/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqawAAAYI"]
[Thu Sep 17 15:04:42.696373 2026] [security2:error] [pid 955873:tid 956122] [client 141.98.252.162:57361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqbgAAAYE"]
[Thu Sep 17 15:04:42.738349 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/wordpress/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqcAAAAXI"]
[Thu Sep 17 15:04:42.769784 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cms/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqdAAAAXc"]
[Thu Sep 17 15:04:42.771487 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:36698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV6hFTPRVSLOsRVhrqdQAAAV4"]
[Thu Sep 17 15:04:42.776100 2026] [security2:error] [pid 955873:tid 956126] [client 52.231.79.181:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/worksec.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqdgAAAYU"]
[Thu Sep 17 15:04:42.805954 2026] [security2:error] [pid 955873:tid 956029] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/next/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqdwAAASQ"]
[Thu Sep 17 15:04:42.869360 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/drupal/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqeAAAAUM"]
[Thu Sep 17 15:04:42.886819 2026] [security2:error] [pid 955873:tid 956081] [client 204.14.250.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqcQAAAVg"], referer: https://facebook.com/
[Thu Sep 17 15:04:42.898848 2026] [security2:error] [pid 955873:tid 956065] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/wp/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqegAAAUg"]
[Thu Sep 17 15:04:42.968511 2026] [security2:error] [pid 955873:tid 956099] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/nuxt/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqfQAAAWo"]
[Thu Sep 17 15:04:42.976573 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/joomla/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqfgAAARM"]
[Thu Sep 17 15:04:43.059488 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cms/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqgQAAAXg"]
[Thu Sep 17 15:04:43.083592 2026] [security2:error] [pid 955873:tid 956095] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/magento/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqgwAAAWY"]
[Thu Sep 17 15:04:43.112125 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqfAAAAVw"]
[Thu Sep 17 15:04:43.112148 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqfAAAAVw"]
[Thu Sep 17 15:04:43.134918 2026] [security2:error] [pid 955873:tid 956024] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/nest/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqhQAAAR8"]
[Thu Sep 17 15:04:43.201804 2026] [security2:error] [pid 955873:tid 956027] [client 52.231.79.181:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/ultra.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqhwAAASI"]
[Thu Sep 17 15:04:43.222259 2026] [security2:error] [pid 955873:tid 956117] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/drupal/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqiAAAAXw"]
[Thu Sep 17 15:04:43.263366 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/AiClientExceptionInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqiQAAARo"]
[Thu Sep 17 15:04:43.263468 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:36698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/AiClientExceptionInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqiQAAARo"]
[Thu Sep 17 15:04:43.298327 2026] [security2:error] [pid 955873:tid 956023] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/react/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqigAAAR4"]
[Thu Sep 17 15:04:43.372745 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/shopify/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqjAAAAUs"]
[Thu Sep 17 15:04:43.374189 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.134.22:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqjQAAAQs"]
[Thu Sep 17 15:04:43.384339 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/joomla/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqjgAAAUY"]
[Thu Sep 17 15:04:43.447679 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/prestashop/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqjwAAARI"]
[Thu Sep 17 15:04:43.465268 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/vue/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqkAAAASk"]
[Thu Sep 17 15:04:43.542739 2026] [security2:error] [pid 955873:tid 956067] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/magento/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqkwAAAUo"]
[Thu Sep 17 15:04:43.544507 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/codeigniter/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqlAAAAUQ"]
[Thu Sep 17 15:04:43.559103 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/CachesDataInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqlgAAAYA"]
[Thu Sep 17 15:04:43.559199 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/CachesDataInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqlgAAAYA"]
[Thu Sep 17 15:04:43.616000 2026] [security2:error] [pid 955873:tid 956066] [client 52.231.79.181:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/gecko.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqlwAAAUk"]
[Thu Sep 17 15:04:43.627231 2026] [security2:error] [pid 955873:tid 956096] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/angular/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqmAAAAWc"]
[Thu Sep 17 15:04:43.707437 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/shopify/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqmwAAASg"]
[Thu Sep 17 15:04:43.751993 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cakephp/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqnAAAAYg"]
[Thu Sep 17 15:04:43.791501 2026] [security2:error] [pid 955873:tid 956058] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/svelte/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqnQAAAUE"]
[Thu Sep 17 15:04:43.849623 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithArrayTransformationInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqoAAAAXA"]
[Thu Sep 17 15:04:43.849791 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithArrayTransformationInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqoAAAAXA"]
[Thu Sep 17 15:04:43.850283 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/zend/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqnwAAAVY"]
[Thu Sep 17 15:04:43.873336 2026] [security2:error] [pid 955873:tid 956041] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/prestashop/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqoQAAATA"]
[Thu Sep 17 15:04:43.957300 2026] [security2:error] [pid 955873:tid 956035] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/vite/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqogAAASo"]
[Thu Sep 17 15:04:43.971788 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/yii/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqowAAAVo"]
[Thu Sep 17 15:04:44.032122 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/codeigniter/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqpAAAASc"]
[Thu Sep 17 15:04:44.034988 2026] [security2:error] [pid 955873:tid 956089] [client 52.231.79.181:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/goods.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqpgAAAWA"]
[Thu Sep 17 15:04:44.040960 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/laravel5/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqqAAAAXo"]
[Thu Sep 17 15:04:44.059470 2026] [security2:error] [pid 955873:tid 956062] [client 141.98.252.162:54306] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "162.241.226.11"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqqQAAAUU"]
[Thu Sep 17 15:04:44.071798 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.134.22:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqqgAAAS8"]
[Thu Sep 17 15:04:44.124813 2026] [security2:error] [pid 955873:tid 956054] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqqwAAAT0"]
[Thu Sep 17 15:04:44.133690 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithJsonSchemaInterface.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqrAAAAS0"]
[Thu Sep 17 15:04:44.133772 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithJsonSchemaInterface.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqrAAAAS0"]
[Thu Sep 17 15:04:44.157784 2026] [security2:error] [pid 955873:tid 956059] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/responsive-menu.min.js"] [unique_id "aqxV7BFTPRVSLOsRVhrqrQAAAUI"]
[Thu Sep 17 15:04:44.162589 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/v1/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqrgAAAWU"]
[Thu Sep 17 15:04:44.191272 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cakephp/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqrwAAAWk"]
[Thu Sep 17 15:04:44.291173 2026] [security2:error] [pid 955873:tid 956046] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/backups/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqsAAAATU"]
[Thu Sep 17 15:04:44.291877 2026] [security2:error] [pid 955873:tid 956074] [client 85.208.98.202:54165] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/images/spinner.gif"] [unique_id "aqxV7BFTPRVSLOsRVhrqsQAAAVE"]
[Thu Sep 17 15:04:44.300100 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/v2/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqsgAAAVU"]
[Thu Sep 17 15:04:44.355232 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/zend/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqswAAAYI"]
[Thu Sep 17 15:04:44.409495 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/v3/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqtAAAAYE"]
[Thu Sep 17 15:04:44.411322 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:36750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/"] [unique_id "aqxV7BFTPRVSLOsRVhrqtQAAAX8"]
[Thu Sep 17 15:04:44.461406 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqtwAAAWM"]
[Thu Sep 17 15:04:44.476388 2026] [security2:error] [pid 955873:tid 956108] [client 52.231.79.181:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/man.php"] [unique_id "aqxV7BFTPRVSLOsRVhrquAAAAXM"]
[Thu Sep 17 15:04:44.516038 2026] [security2:error] [pid 955873:tid 956101] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/yii/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrquQAAAWw"]
[Thu Sep 17 15:04:44.555624 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/v1/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqugAAAWQ"]
[Thu Sep 17 15:04:44.575992 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/"] [unique_id "aqxV7BFTPRVSLOsRVhrquwAAAXU"]
[Thu Sep 17 15:04:44.631928 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/tmp/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqvAAAAV0"]
[Thu Sep 17 15:04:44.646806 2026] [security2:error] [pid 955873:tid 956070] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqUgABTS4"], referer: http://radtechresourcegroup.net./blog/
[Thu Sep 17 15:04:44.676464 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/v2/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqvgAAAX4"]
[Thu Sep 17 15:04:44.683827 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/laravel5/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqvwAAATY"]
[Thu Sep 17 15:04:44.715136 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:36750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV7BFTPRVSLOsRVhrqwQAAATk"]
[Thu Sep 17 15:04:44.741941 2026] [security2:error] [pid 955873:tid 956116] [client 194.163.128.162:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqwwAAAXs"], referer: binance.com
[Thu Sep 17 15:04:44.756174 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/rest/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqxAAAATw"]
[Thu Sep 17 15:04:44.767357 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.134.22:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqxQAAAS4"]
[Thu Sep 17 15:04:44.801505 2026] [security2:error] [pid 955873:tid 956081] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/temp/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqxwAAAVg"]
[Thu Sep 17 15:04:44.823228 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/graphql/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqyAAAATo"]
[Thu Sep 17 15:04:44.868685 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/v1/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqzAAAAYc"]
[Thu Sep 17 15:04:44.885475 2026] [security2:error] [pid 955873:tid 956060] [client 52.231.79.181:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/wp-settings.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqzQAAAUM"]
[Thu Sep 17 15:04:44.963705 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/lab/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrq0QAAAXE"]
[Thu Sep 17 15:04:44.963737 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/gateway/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrq0AAAAQ0"]
[Thu Sep 17 15:04:45.030840 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/v2/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq0gAAAWo"]
[Thu Sep 17 15:04:45.090137 2026] [security2:error] [pid 955873:tid 956095] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/microservice/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq1AAAAWY"]
[Thu Sep 17 15:04:45.126516 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqywAAAV8"]
[Thu Sep 17 15:04:45.126534 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqywAAAV8"]
[Thu Sep 17 15:04:45.143024 2026] [security2:error] [pid 955873:tid 956052] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cronlab/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq1wAAATs"]
[Thu Sep 17 15:04:45.169766 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/service/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq2AAAAXw"]
[Thu Sep 17 15:04:45.197320 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/v3/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq2QAAAR4"]
[Thu Sep 17 15:04:45.264440 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/InvalidArgumentException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq3QAAAUs"]
[Thu Sep 17 15:04:45.264886 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:36750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/InvalidArgumentException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq3QAAAUs"]
[Thu Sep 17 15:04:45.269185 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/v3/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq3gAAAQs"]
[Thu Sep 17 15:04:45.272919 2026] [security2:error] [pid 955873:tid 956043] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq1gABMjU"], referer: http://radtechresourcegroup.net./wordpress/
[Thu Sep 17 15:04:45.285472 2026] [security2:error] [pid 955873:tid 956027] [client 52.231.79.181:2026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/k.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq3wAAASI"]
[Thu Sep 17 15:04:45.305797 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4AAAAWs"]
[Thu Sep 17 15:04:45.334810 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/dev/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4QAAAQo"]
[Thu Sep 17 15:04:45.352474 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/v1/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4gAAATE"]
[Thu Sep 17 15:04:45.412261 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/staging/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4wAAARs"]
[Thu Sep 17 15:04:45.467848 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/en/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq5AAAASk"]
[Thu Sep 17 15:04:45.473069 2026] [security2:error] [pid 955873:tid 956125] [client 34.166.134.22:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq5QAAAYQ"]
[Thu Sep 17 15:04:45.516826 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/vendor/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq5wAAAUQ"]
[Thu Sep 17 15:04:45.521916 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/v2/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq6AAAAYA"]
[Thu Sep 17 15:04:45.542673 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/RuntimeException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq6QAAASw"]
[Thu Sep 17 15:04:45.542749 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:36766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/RuntimeException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq6QAAASw"]
[Thu Sep 17 15:04:45.584404 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/lib/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq6gAAAWc"]
[Thu Sep 17 15:04:45.680408 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/rest/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq7QAAAQw"]
[Thu Sep 17 15:04:45.697032 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq6wAAAYM"]
[Thu Sep 17 15:04:45.699351 2026] [security2:error] [pid 955873:tid 956066] [client 52.231.79.181:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/autoload_classmap.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq7wAAAUk"]
[Thu Sep 17 15:04:45.730260 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/resources/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq8QAAAVM"]
[Thu Sep 17 15:04:45.821380 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/TokenLimitReachedException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq9AAAAXA"]
[Thu Sep 17 15:04:45.821470 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/TokenLimitReachedException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq9AAAAXA"]
[Thu Sep 17 15:04:45.836933 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/assets/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq9QAAATA"]
[Thu Sep 17 15:04:45.848577 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/graphql/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq9gAAASo"]
[Thu Sep 17 15:04:45.859807 2026] [security2:error] [pid 955873:tid 956048] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/psnlink/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq9wAAATc"]
[Thu Sep 17 15:04:45.884939 2026] [security2:error] [pid 955873:tid 956009] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq8gABEDg"], referer: http://radtechresourcegroup.net./wp/
[Thu Sep 17 15:04:45.910792 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/uploads/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq-AAAAX0"]
[Thu Sep 17 15:04:46.012324 2026] [security2:error] [pid 955873:tid 956054] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/gateway/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrq-QAAAT0"]
[Thu Sep 17 15:04:46.024611 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/internal/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrq-gAAAS0"]
[Thu Sep 17 15:04:46.029382 2026] [security2:error] [pid 955873:tid 956059] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/exapi/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrq-wAAAUI"]
[Thu Sep 17 15:04:46.104697 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:36778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/"] [unique_id "aqxV7hFTPRVSLOsRVhrq_QAAAWU"]
[Thu Sep 17 15:04:46.132121 2026] [security2:error] [pid 955873:tid 956062] [client 52.231.79.181:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/profile.php"] [unique_id "aqxV7hFTPRVSLOsRVhrq_wAAAUU"]
[Thu Sep 17 15:04:46.159337 2026] [security2:error] [pid 955873:tid 956032] [client 34.166.134.22:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrAAAAASc"]
[Thu Sep 17 15:04:46.164854 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/tools/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrAgAAAU8"]
[Thu Sep 17 15:04:46.174967 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/microservice/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrBQAAASM"]
[Thu Sep 17 15:04:46.194644 2026] [security2:error] [pid 955873:tid 956045] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sitemaps/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrBgAAATQ"]
[Thu Sep 17 15:04:46.199081 2026] [security2:error] [pid 955873:tid 956040] [client 216.73.163.37:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrBAAAAS8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:46.218101 2026] [security2:error] [pid 955873:tid 956046] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/css/email-subscribers-public.css"] [unique_id "aqxV7hFTPRVSLOsRVhrrCAAAATU"]
[Thu Sep 17 15:04:46.250997 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/scripts/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrCgAAAVU"]
[Thu Sep 17 15:04:46.256339 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/"] [unique_id "aqxV7hFTPRVSLOsRVhrrCQAAAVE"]
[Thu Sep 17 15:04:46.330310 2026] [security2:error] [pid 955873:tid 956108] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/service/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrDAAAAXM"]
[Thu Sep 17 15:04:46.353267 2026] [security2:error] [pid 955873:tid 956101] [client 85.208.98.202:54165] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/style.css"] [unique_id "aqxV7hFTPRVSLOsRVhrrDQAAAWw"]
[Thu Sep 17 15:04:46.393148 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/bin/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrDwAAAXc"]
[Thu Sep 17 15:04:46.394192 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV7hFTPRVSLOsRVhrrEAAAASU"]
[Thu Sep 17 15:04:46.463592 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sbin/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrEwAAAU0"]
[Thu Sep 17 15:04:46.480152 2026] [security2:error] [pid 955873:tid 956107] [client 216.73.163.52:41181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrEgAAAXI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:46.485607 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/v3/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrFAAAAU4"]
[Thu Sep 17 15:04:46.530220 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/local/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrFQAAAYU"]
[Thu Sep 17 15:04:46.543848 2026] [security2:error] [pid 955873:tid 956008] [client 52.231.79.181:2045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/server.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrFgAAAQ8"]
[Thu Sep 17 15:04:46.606104 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/portal/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrGAAAATk"]
[Thu Sep 17 15:04:46.756893 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrFwAAASQ"]
[Thu Sep 17 15:04:46.756916 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrFwAAASQ"]
[Thu Sep 17 15:04:46.772995 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/dashboard/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrIwAAAYY"]
[Thu Sep 17 15:04:46.852575 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.134.22:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/www/phpinfo.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrJgAAAXs"]
[Thu Sep 17 15:04:46.865133 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/panel/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrJwAAAXw"]
[Thu Sep 17 15:04:46.927681 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:36778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/WithDataCachingTrait.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrKQAAAQo"]
[Thu Sep 17 15:04:46.927773 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:36778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/WithDataCachingTrait.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrKQAAAQo"]
[Thu Sep 17 15:04:46.950329 2026] [security2:error] [pid 955873:tid 956113] [client 52.231.79.181:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/shell.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrKwAAAXg"]
[Thu Sep 17 15:04:46.962066 2026] [security2:error] [pid 955873:tid 956020] [client 185.191.171.18:50700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tab-funkenwerk.com"] [uri "/robots.txt"] [unique_id "aqxV7hFTPRVSLOsRVhrrLgAAARs"]
[Thu Sep 17 15:04:46.962137 2026] [security2:error] [pid 955873:tid 956020] [client 185.191.171.18:50700] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tab-funkenwerk.com"] [uri "/robots.txt"] [unique_id "aqxV7hFTPRVSLOsRVhrrLgAAARs"]
[Thu Sep 17 15:04:46.965694 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/crm/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrLwAAASE"]
[Thu Sep 17 15:04:46.981919 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/dev/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrMAAAATg"]
[Thu Sep 17 15:04:47.058270 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/erp/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrNAAAASw"]
[Thu Sep 17 15:04:47.143975 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/staging/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrNgAAAWI"]
[Thu Sep 17 15:04:47.178603 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/shop/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrNwAAAUE"]
[Thu Sep 17 15:04:47.213452 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:36786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/"] [unique_id "aqxV7xFTPRVSLOsRVhrrOgAAATA"]
[Thu Sep 17 15:04:47.222502 2026] [security2:error] [pid 955873:tid 956082] [client 85.208.96.196:26808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tab-funkenwerk.com"] [uri "/id91.html"] [unique_id "aqxV7xFTPRVSLOsRVhrrOwAAAVk"]
[Thu Sep 17 15:04:47.222576 2026] [security2:error] [pid 955873:tid 956082] [client 85.208.96.196:26808] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tab-funkenwerk.com"] [uri "/id91.html"] [unique_id "aqxV7xFTPRVSLOsRVhrrOwAAAVk"]
[Thu Sep 17 15:04:47.230140 2026] [security2:error] [pid 955873:tid 956077] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/logs/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrPAAAAVQ"]
[Thu Sep 17 15:04:47.246481 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrPQAAAWs"]
[Thu Sep 17 15:04:47.246839 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:62147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrPQAAAWs"]
[Thu Sep 17 15:04:47.260562 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/store/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrQAAAARw"]
[Thu Sep 17 15:04:47.301234 2026] [security2:error] [pid 955873:tid 956009] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/vendor/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrQwAAARA"]
[Thu Sep 17 15:04:47.357547 2026] [security2:error] [pid 955873:tid 956016] [client 52.231.79.181:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/t.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrRgAAARc"]
[Thu Sep 17 15:04:47.374106 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/"] [unique_id "aqxV7xFTPRVSLOsRVhrrRQAAAXo"]
[Thu Sep 17 15:04:47.393183 2026] [security2:error] [pid 955873:tid 956059] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cache/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrSQAAAUI"]
[Thu Sep 17 15:04:47.444214 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/saas/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrSgAAAW8"]
[Thu Sep 17 15:04:47.454235 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/lib/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrSwAAASc"]
[Thu Sep 17 15:04:47.476876 2026] [security2:error] [pid 955873:tid 956038] [client 103.190.46.235:6127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrSAABLUE"]
[Thu Sep 17 15:04:47.520758 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:36786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/wp-includes/php-ai-client/src/"] [unique_id "aqxV7xFTPRVSLOsRVhrrTQAAAVU"]
[Thu Sep 17 15:04:47.543817 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.134.22:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrTgAAAVo"]
[Thu Sep 17 15:04:47.551003 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/client/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrTwAAAVE"]
[Thu Sep 17 15:04:47.556456 2026] [security2:error] [pid 955873:tid 956123] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailer/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrUAAAAYI"]
[Thu Sep 17 15:04:47.606866 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/resources/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrVAAAARk"]
[Thu Sep 17 15:04:47.668215 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/project/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrVgAAAUA"]
[Thu Sep 17 15:04:47.718594 2026] [security2:error] [pid 955873:tid 956112] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mail/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrWgAAAXc"]
[Thu Sep 17 15:04:47.762151 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/assets/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrWwAAAVI"]
[Thu Sep 17 15:04:47.762816 2026] [security2:error] [pid 955873:tid 956103] [client 52.231.79.181:1709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/hello.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrXAAAAW4"]
[Thu Sep 17 15:04:47.764785 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/admin-panel/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrXgAAAT8"]
[Thu Sep 17 15:04:47.815357 2026] [security2:error] [pid 955873:tid 956094] [client 154.190.208.131:42122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrXwAAAWU"]
[Thu Sep 17 15:04:47.815478 2026] [security2:error] [pid 955873:tid 956094] [client 154.190.208.131:42122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrXwAAAWU"]
[Thu Sep 17 15:04:47.881108 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrVQAAAXM"]
[Thu Sep 17 15:04:47.881135 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrVQAAAXM"]
[Thu Sep 17 15:04:47.883691 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/email/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrYgAAAQ8"]
[Thu Sep 17 15:04:47.890825 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/control-panel/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrZAAAATk"]
[Thu Sep 17 15:04:47.920248 2026] [security2:error] [pid 955873:tid 956095] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/uploads/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrZgAAAWY"]
[Thu Sep 17 15:04:47.965839 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/user-panel/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrZwAAASQ"]
[Thu Sep 17 15:04:48.023842 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:36786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/AfterGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrraQAAAWo"]
[Thu Sep 17 15:04:48.023947 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:36786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/AfterGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrraQAAAWo"]
[Thu Sep 17 15:04:48.045827 2026] [security2:error] [pid 955873:tid 956088] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/smtp/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrragAAAV8"]
[Thu Sep 17 15:04:48.052420 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/node/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrbAAAARo"]
[Thu Sep 17 15:04:48.062238 2026] [security2:error] [pid 955873:tid 956060] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrZQABQ0Q"], referer: http://radtechresourcegroup.net./backup/
[Thu Sep 17 15:04:48.073391 2026] [security2:error] [pid 955873:tid 956117] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/internal/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrbQAAAXw"]
[Thu Sep 17 15:04:48.134628 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/express/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrbgAAAUs"]
[Thu Sep 17 15:04:48.209024 2026] [security2:error] [pid 955873:tid 956026] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailing/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrcwAAASE"]
[Thu Sep 17 15:04:48.218058 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/next/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrdQAAATg"]
[Thu Sep 17 15:04:48.228770 2026] [security2:error] [pid 955873:tid 956036] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/tools/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrdgAAASs"]
[Thu Sep 17 15:04:48.245809 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.134.22:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxV8BFTPRVSLOsRVhrreAAAASY"]
[Thu Sep 17 15:04:48.305001 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/BeforeGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrewAAATE"]
[Thu Sep 17 15:04:48.305097 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/BeforeGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrewAAATE"]
[Thu Sep 17 15:04:48.312889 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/nuxt/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrfAAAAWg"]
[Thu Sep 17 15:04:48.371397 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/notifications/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrfQAAASk"]
[Thu Sep 17 15:04:48.395719 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/scripts/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrfwAAAYA"]
[Thu Sep 17 15:04:48.407670 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/nest/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrgAAAAUo"]
[Thu Sep 17 15:04:48.424078 2026] [security2:error] [pid 955873:tid 956005] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrgQAAAQw"]
[Thu Sep 17 15:04:48.497276 2026] [security2:error] [pid 955873:tid 956066] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/link-prefetch.min.js"] [unique_id "aqxV8BFTPRVSLOsRVhrrggAAAUk"]
[Thu Sep 17 15:04:48.532956 2026] [security2:error] [pid 955873:tid 956041] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/notify/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrhQAAATA"]
[Thu Sep 17 15:04:48.534254 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/react/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrhgAAAVk"]
[Thu Sep 17 15:04:48.551966 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/bin/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrhwAAAVQ"]
[Thu Sep 17 15:04:48.573335 2026] [security2:error] [pid 955873:tid 956021] [client 85.208.98.202:54165] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/css/email-subscribers-public.css"] [unique_id "aqxV8BFTPRVSLOsRVhrriAAAARw"]
[Thu Sep 17 15:04:48.590998 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8BFTPRVSLOsRVhrrigAAARA"]
[Thu Sep 17 15:04:48.617218 2026] [security2:error] [pid 955873:tid 956048] [client 45.131.194.118:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.194.131.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV8BFTPRVSLOsRVhrriQAAATc"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:48.618418 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/vue/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrriwAAATM"]
[Thu Sep 17 15:04:48.649389 2026] [security2:error] [pid 955873:tid 956076] [client 45.169.98.18:49490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrjAAAAVM"]
[Thu Sep 17 15:04:48.649493 2026] [security2:error] [pid 955873:tid 956076] [client 45.169.98.18:49490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrjAAAAVM"]
[Thu Sep 17 15:04:48.682180 2026] [security2:error] [pid 955873:tid 956027] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrhAABIkY"], referer: http://radtechresourcegroup.net./old/
[Thu Sep 17 15:04:48.697030 2026] [security2:error] [pid 955873:tid 956016] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sender/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrkQAAARc"]
[Thu Sep 17 15:04:48.704407 2026] [security2:error] [pid 955873:tid 956054] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sbin/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrkwAAAT0"]
[Thu Sep 17 15:04:48.762032 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/angular/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrlgAAAVc"]
[Thu Sep 17 15:04:48.776737 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8BFTPRVSLOsRVhrrlAAAAW8"]
[Thu Sep 17 15:04:48.829793 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/svelte/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmAAAAXA"]
[Thu Sep 17 15:04:48.858670 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/local/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmQAAASM"]
[Thu Sep 17 15:04:48.859895 2026] [security2:error] [pid 955873:tid 956045] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/campaign/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmgAAATQ"]
[Thu Sep 17 15:04:48.895594 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/vite/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmwAAAUU"]
[Thu Sep 17 15:04:48.919548 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/wp-includes/php-ai-client/src/"] [unique_id "aqxV8BFTPRVSLOsRVhrrnQAAAVo"]
[Thu Sep 17 15:04:48.937388 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.134.22:33070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/site/phpinfo.php"] [unique_id "aqxV8BFTPRVSLOsRVhrroQAAAUQ"]
[Thu Sep 17 15:04:49.012672 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/portal/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrowAAARk"]
[Thu Sep 17 15:04:49.021701 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/backup/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrpAAAAUA"]
[Thu Sep 17 15:04:49.024454 2026] [security2:error] [pid 955873:tid 956101] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/newsletter/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrpQAAAWw"]
[Thu Sep 17 15:04:49.120267 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/backups/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrqQAAAWk"]
[Thu Sep 17 15:04:49.167986 2026] [security2:error] [pid 955873:tid 956094] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/dashboard/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrrwAAAWU"]
[Thu Sep 17 15:04:49.169098 2026] [security2:error] [pid 955873:tid 956040] [client 115.244.164.14:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrrAAAAS8"]
[Thu Sep 17 15:04:49.169177 2026] [security2:error] [pid 955873:tid 956040] [client 115.244.164.14:58638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrrAAAAS8"]
[Thu Sep 17 15:04:49.187278 2026] [security2:error] [pid 955873:tid 956108] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/ses/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrsAAAAXM"]
[Thu Sep 17 15:04:49.248380 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrpgAAAXc"]
[Thu Sep 17 15:04:49.248405 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrpgAAAXc"]
[Thu Sep 17 15:04:49.275614 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/old/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrtQAAAYk"]
[Thu Sep 17 15:04:49.302452 2026] [security2:error] [pid 955873:tid 956056] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrqgABP0k"], referer: http://radtechresourcegroup.net./new/
[Thu Sep 17 15:04:49.325530 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/panel/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrtgAAATU"]
[Thu Sep 17 15:04:49.354468 2026] [security2:error] [pid 955873:tid 956012] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sendgrid/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrtwAAARM"]
[Thu Sep 17 15:04:49.390584 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/tmp/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrugAAAYY"]
[Thu Sep 17 15:04:49.392564 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/"] [unique_id "aqxV8RFTPRVSLOsRVhrruwAAAVw"]
[Thu Sep 17 15:04:49.459680 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/temp/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrvAAAAYc"]
[Thu Sep 17 15:04:49.479308 2026] [security2:error] [pid 955873:tid 956081] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/crm/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrvQAAAVg"]
[Thu Sep 17 15:04:49.495551 2026] [security2:error] [pid 955873:tid 956117] [client 20.244.34.24:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrvgAAAXw"], referer: binance.com
[Thu Sep 17 15:04:49.523767 2026] [security2:error] [pid 955873:tid 956004] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sparkpost/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrvwAAAQs"]
[Thu Sep 17 15:04:49.534692 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/lab/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrwQAAAVA"]
[Thu Sep 17 15:04:49.549632 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/"] [unique_id "aqxV8RFTPRVSLOsRVhrrwgAAAXE"]
[Thu Sep 17 15:04:49.614513 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cronlab/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrxAAAATI"]
[Thu Sep 17 15:04:49.631650 2026] [security2:error] [pid 955873:tid 956099] [client 34.166.134.22:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxV8RFTPRVSLOsRVhrryAAAAWo"]
[Thu Sep 17 15:04:49.638052 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/erp/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrryQAAARg"]
[Thu Sep 17 15:04:49.649472 2026] [security2:error] [pid 955873:tid 956068] [client 179.6.7.127:35704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrwAABS0s"]
[Thu Sep 17 15:04:49.685559 2026] [security2:error] [pid 955873:tid 956097] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/postmark/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrzAAAAWg"]
[Thu Sep 17 15:04:49.693574 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8RFTPRVSLOsRVhrrzQAAARU"]
[Thu Sep 17 15:04:49.711286 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cron/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrzgAAASk"]
[Thu Sep 17 15:04:49.754059 2026] [security2:error] [pid 955873:tid 956064] [client 104.28.198.244:22541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr0gAAAUc"]
[Thu Sep 17 15:04:49.754130 2026] [security2:error] [pid 955873:tid 956064] [client 104.28.198.244:22541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr0gAAAUc"]
[Thu Sep 17 15:04:49.794091 2026] [security2:error] [pid 955873:tid 956084] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/shop/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr0wAAAVs"]
[Thu Sep 17 15:04:49.817038 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/en/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr1AAAAUo"]
[Thu Sep 17 15:04:49.850265 2026] [security2:error] [pid 955873:tid 956020] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailgun/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr1gAAARs"]
[Thu Sep 17 15:04:49.951729 2026] [security2:error] [pid 955873:tid 956124] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/store/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr2AAAAYM"]
[Thu Sep 17 15:04:49.997762 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/administrator/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr1wAAAYQ"]
[Thu Sep 17 15:04:50.015422 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr1QAAASA"]
[Thu Sep 17 15:04:50.015444 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr1QAAASA"]
[Thu Sep 17 15:04:50.016001 2026] [security2:error] [pid 955873:tid 956009] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mandrill/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr2wAAARA"]
[Thu Sep 17 15:04:50.115538 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/saas/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr4AAAAX0"]
[Thu Sep 17 15:04:50.136803 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/psnlink/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr4QAAAXQ"]
[Thu Sep 17 15:04:50.159575 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/File.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr4gAAARE"]
[Thu Sep 17 15:04:50.159639 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/File.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr4gAAARE"]
[Thu Sep 17 15:04:50.183363 2026] [security2:error] [pid 955873:tid 956080] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailjet/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr4wAAAVc"]
[Thu Sep 17 15:04:50.261519 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/exapi/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr5wAAAXA"]
[Thu Sep 17 15:04:50.277940 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/client/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr6AAAASM"]
[Thu Sep 17 15:04:50.322538 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.134.22:55142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr6wAAAXo"]
[Thu Sep 17 15:04:50.347226 2026] [security2:error] [pid 955873:tid 956114] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/brevo/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr7QAAAXk"]
[Thu Sep 17 15:04:50.378495 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sitemaps/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr7gAAAWA"]
[Thu Sep 17 15:04:50.424993 2026] [security2:error] [pid 955873:tid 956059] [client 47.79.201.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr3wAAAUI"], referer: https://www.google.com/
[Thu Sep 17 15:04:50.432523 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/project/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr7wAAAWM"]
[Thu Sep 17 15:04:50.442554 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:47698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/"] [unique_id "aqxV8hFTPRVSLOsRVhrr8AAAAYE"]
[Thu Sep 17 15:04:50.512359 2026] [security2:error] [pid 955873:tid 956018] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/transactional/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr8gAAARk"]
[Thu Sep 17 15:04:50.558191 2026] [security2:error] [pid 955873:tid 956101] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/classie.min.js"] [unique_id "aqxV8hFTPRVSLOsRVhrr9AAAAWw"]
[Thu Sep 17 15:04:50.572488 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aqxV8hFTPRVSLOsRVhrr9QAAAWU"]
[Thu Sep 17 15:04:50.585290 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/admin-panel/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr9wAAATY"]
[Thu Sep 17 15:04:50.597531 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/"] [unique_id "aqxV8hFTPRVSLOsRVhrr9gAAAS8"]
[Thu Sep 17 15:04:50.628169 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/logs/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr-QAAAXc"]
[Thu Sep 17 15:04:50.658591 2026] [security2:error] [pid 955873:tid 956063] [client 57.141.14.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr0AAAAUY"]
[Thu Sep 17 15:04:50.673603 2026] [security2:error] [pid 955873:tid 956056] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/bulk/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr-wAAAT8"]
[Thu Sep 17 15:04:50.717006 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cache/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr_gAAAQ0"]
[Thu Sep 17 15:04:50.744823 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:47698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8hFTPRVSLOsRVhrr_wAAAVI"]
[Thu Sep 17 15:04:50.751105 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/control-panel/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsAAAAAU4"]
[Thu Sep 17 15:04:50.800995 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aqxV8hFTPRVSLOsRVhrsAQAAAW0"]
[Thu Sep 17 15:04:50.808632 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailer/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsAgAAARM"]
[Thu Sep 17 15:04:50.835647 2026] [security2:error] [pid 955873:tid 956070] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/aws/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsAwAAAU0"]
[Thu Sep 17 15:04:50.871746 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mail/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsBAAAAV0"]
[Thu Sep 17 15:04:50.903600 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/user-panel/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsBgAAATk"]
[Thu Sep 17 15:04:50.935378 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/email/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsBwAAAVY"]
[Thu Sep 17 15:04:51.002536 2026] [security2:error] [pid 955873:tid 956127] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/azure/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsCAAAAYY"]
[Thu Sep 17 15:04:51.009962 2026] [security2:error] [pid 955873:tid 956095] [client 34.166.134.22:55154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsCQAAAWY"]
[Thu Sep 17 15:04:51.019849 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/smtp/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsCgAAARI"]
[Thu Sep 17 15:04:51.059461 2026] [security2:error] [pid 955873:tid 956088] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/node/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsDQAAAV8"]
[Thu Sep 17 15:04:51.062656 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8hFTPRVSLOsRVhrsBQAAAR0"]
[Thu Sep 17 15:04:51.062684 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8hFTPRVSLOsRVhrsBQAAAR0"]
[Thu Sep 17 15:04:51.100615 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailing/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsDwAAAX4"]
[Thu Sep 17 15:04:51.170229 2026] [security2:error] [pid 955873:tid 956117] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/gcp/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsEQAAAXw"]
[Thu Sep 17 15:04:51.205595 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:47698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/FileTypeEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsFgAAAR8"]
[Thu Sep 17 15:04:51.205682 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:47698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/FileTypeEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsFgAAAR8"]
[Thu Sep 17 15:04:51.211955 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/express/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsFwAAAXg"]
[Thu Sep 17 15:04:51.339299 2026] [security2:error] [pid 955873:tid 956014] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cloud/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsGgAAARU"]
[Thu Sep 17 15:04:51.348263 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/notifications/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsGwAAARg"]
[Thu Sep 17 15:04:51.364384 2026] [security2:error] [pid 955873:tid 956037] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aqxV8xFTPRVSLOsRVhrsHAAAASw"]
[Thu Sep 17 15:04:51.366706 2026] [security2:error] [pid 955873:tid 956096] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/next/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsHQAAAWc"]
[Thu Sep 17 15:04:51.446504 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/notify/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsHgAAAVs"]
[Thu Sep 17 15:04:51.496268 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/MediaOrientationEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsHwAAAYM"]
[Thu Sep 17 15:04:51.496336 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/MediaOrientationEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsHwAAAYM"]
[Thu Sep 17 15:04:51.504437 2026] [security2:error] [pid 955873:tid 956066] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/infrastructure/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsIAAAAUk"]
[Thu Sep 17 15:04:51.519109 2026] [security2:error] [pid 955873:tid 956041] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/nuxt/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsIQAAATA"]
[Thu Sep 17 15:04:51.564480 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sender/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsIgAAAVk"]
[Thu Sep 17 15:04:51.630897 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/campaign/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsJQAAAXs"]
[Thu Sep 17 15:04:51.671556 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/nest/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsKQAAATc"]
[Thu Sep 17 15:04:51.677317 2026] [security2:error] [pid 955873:tid 956076] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/docker/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsKwAAAVM"]
[Thu Sep 17 15:04:51.685960 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.134.22:55162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/core/phpinfo.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsLgAAAUo"]
[Thu Sep 17 15:04:51.774446 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/"] [unique_id "aqxV8xFTPRVSLOsRVhrsMQAAAXA"]
[Thu Sep 17 15:04:51.813524 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/newsletter/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsMwAAASM"]
[Thu Sep 17 15:04:51.828249 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/react/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsNAAAAVU"]
[Thu Sep 17 15:04:51.843644 2026] [security2:error] [pid 955873:tid 956083] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/k8s/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsNQAAAVo"]
[Thu Sep 17 15:04:51.859195 2026] [security2:error] [pid 955873:tid 956076] [client 216.73.163.58:30195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsMgAAAVM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:51.922315 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/ses/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsNwAAATQ"]
[Thu Sep 17 15:04:51.934786 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/"] [unique_id "aqxV8xFTPRVSLOsRVhrsNgAAAUw"]
[Thu Sep 17 15:04:51.985436 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/vue/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsOwAAAX8"]
[Thu Sep 17 15:04:52.013056 2026] [security2:error] [pid 955873:tid 956039] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/kubernetes/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsPAAAAS4"]
[Thu Sep 17 15:04:52.051538 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sendgrid/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsPQAAAU8"]
[Thu Sep 17 15:04:52.072240 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:47722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV9BFTPRVSLOsRVhrsPwAAAWE"]
[Thu Sep 17 15:04:52.128908 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sparkpost/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsQAAAAXY"]
[Thu Sep 17 15:04:52.140803 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/angular/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsQQAAAWM"]
[Thu Sep 17 15:04:52.174334 2026] [security2:error] [pid 955873:tid 956122] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/terraform/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsRAAAAYE"]
[Thu Sep 17 15:04:52.247078 2026] [security2:error] [pid 955873:tid 956038] [client 156.245.246.6:50647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enolastable.com"] [uri "/index.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsSQAAAS0"], referer: https://enolastable.com
[Thu Sep 17 15:04:52.259072 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/postmark/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsSgAAATY"]
[Thu Sep 17 15:04:52.295694 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/svelte/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsSwAAAS8"]
[Thu Sep 17 15:04:52.343702 2026] [security2:error] [pid 955873:tid 956112] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/ansible/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsTQAAAXc"]
[Thu Sep 17 15:04:52.385984 2026] [security2:error] [pid 955873:tid 956016] [client 34.166.134.22:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsUAAAARc"]
[Thu Sep 17 15:04:52.388966 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailgun/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsUQAAAWI"]
[Thu Sep 17 15:04:52.406101 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsRgAAAWw"]
[Thu Sep 17 15:04:52.406121 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsRgAAAWw"]
[Thu Sep 17 15:04:52.449795 2026] [security2:error] [pid 955873:tid 956006] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/vite/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsUwAAAQ0"]
[Thu Sep 17 15:04:52.486017 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mandrill/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsVQAAARM"]
[Thu Sep 17 15:04:52.508149 2026] [security2:error] [pid 955873:tid 956070] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/.git/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsVwAAAU0"]
[Thu Sep 17 15:04:52.544220 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/MimeType.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsWAAAAQ8"]
[Thu Sep 17 15:04:52.544326 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/MimeType.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsWAAAAQ8"]
[Thu Sep 17 15:04:52.566074 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailjet/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsWQAAAV0"]
[Thu Sep 17 15:04:52.602576 2026] [security2:error] [pid 955873:tid 956110] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/backup/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsWgAAAXU"]
[Thu Sep 17 15:04:52.675129 2026] [security2:error] [pid 955873:tid 956053] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/ci/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsXQAAATw"]
[Thu Sep 17 15:04:52.675988 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/brevo/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsXgAAAV4"]
[Thu Sep 17 15:04:52.757423 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/backups/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsZgAAAXI"]
[Thu Sep 17 15:04:52.766025 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/transactional/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsaAAAAQs"]
[Thu Sep 17 15:04:52.831452 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9BFTPRVSLOsRVhrsawAAAWo"]
[Thu Sep 17 15:04:52.831757 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/bulk/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsagAAAXg"]
[Thu Sep 17 15:04:52.835710 2026] [security2:error] [pid 955873:tid 956043] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cd/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsbAAAATI"]
[Thu Sep 17 15:04:52.872631 2026] [security2:error] [pid 955873:tid 955962] [remote 5.78.122.81:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.122.78.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beaglerescueleague.org"] [uri "/wp-admin/admin.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsaQABH1g"], referer: https://beaglerescueleague.org/wp-admin/admin.php?page=backwpuponboarding
[Thu Sep 17 15:04:52.913017 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/aws/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsbQAAARU"]
[Thu Sep 17 15:04:52.918586 2026] [security2:error] [pid 955873:tid 956034] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/old/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsbgAAASk"]
[Thu Sep 17 15:04:52.993923 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9BFTPRVSLOsRVhrsbwAAARg"]
[Thu Sep 17 15:04:52.997105 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/jenkins/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrscAAAAXE"]
[Thu Sep 17 15:04:53.029281 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/azure/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrscQAAAYA"]
[Thu Sep 17 15:04:53.083073 2026] [security2:error] [pid 955873:tid 956073] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/tmp/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrscgAAAVA"]
[Thu Sep 17 15:04:53.116827 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/gcp/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsdAAAASg"]
[Thu Sep 17 15:04:53.141705 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/wp-includes/php-ai-client/src/"] [unique_id "aqxV9RFTPRVSLOsRVhrsdQAAAUc"]
[Thu Sep 17 15:04:53.158229 2026] [security2:error] [pid 955873:tid 956084] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/gitlab/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsdwAAAVs"]
[Thu Sep 17 15:04:53.202133 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cloud/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsegAAAYU"]
[Thu Sep 17 15:04:53.244291 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/temp/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsewAAAVk"]
[Thu Sep 17 15:04:53.279077 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgQAAAWc"]
[Thu Sep 17 15:04:53.279176 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:61272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgQAAAWc"]
[Thu Sep 17 15:04:53.310974 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/infrastructure/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsgwAAATc"]
[Thu Sep 17 15:04:53.319709 2026] [security2:error] [pid 955873:tid 956058] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/github/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrshAAAAUE"]
[Thu Sep 17 15:04:53.399452 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/docker/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsiwAAAX0"]
[Thu Sep 17 15:04:53.405346 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/lab/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsjAAAASM"]
[Thu Sep 17 15:04:53.467742 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgAAAARw"]
[Thu Sep 17 15:04:53.467767 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgAAAARw"]
[Thu Sep 17 15:04:53.481881 2026] [security2:error] [pid 955873:tid 956061] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/actions/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsjgAAAUQ"]
[Thu Sep 17 15:04:53.522321 2026] [security2:error] [pid 955873:tid 956069] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/k8s/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsjwAAAUw"]
[Thu Sep 17 15:04:53.567931 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cronlab/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrskAAAASI"]
[Thu Sep 17 15:04:53.609944 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/"] [unique_id "aqxV9RFTPRVSLOsRVhrskgAAAS4"]
[Thu Sep 17 15:04:53.644061 2026] [security2:error] [pid 955873:tid 956072] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/circleci/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrskwAAAU8"]
[Thu Sep 17 15:04:53.673063 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/kubernetes/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrslQAAAWA"]
[Thu Sep 17 15:04:53.720680 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cron/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsmgAAAXY"]
[Thu Sep 17 15:04:53.739477 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/terraform/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsmwAAAVc"]
[Thu Sep 17 15:04:53.774072 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/"] [unique_id "aqxV9RFTPRVSLOsRVhrsnAAAAYE"]
[Thu Sep 17 15:04:53.806087 2026] [security2:error] [pid 955873:tid 956047] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/travis/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsngAAATY"]
[Thu Sep 17 15:04:53.838158 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/ansible/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsnwAAAS8"]
[Thu Sep 17 15:04:53.874841 2026] [security2:error] [pid 955873:tid 956103] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/en/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsogAAAW4"]
[Thu Sep 17 15:04:53.918234 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9RFTPRVSLOsRVhrspAAAATg"]
[Thu Sep 17 15:04:53.929835 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.git/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrspQAAAYI"]
[Thu Sep 17 15:04:53.969828 2026] [security2:error] [pid 955873:tid 956046] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/buildkite/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrspwAAATU"]
[Thu Sep 17 15:04:54.006277 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/ci/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsqQAAAVI"]
[Thu Sep 17 15:04:54.080391 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cd/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsrwAAASY"]
[Thu Sep 17 15:04:54.092097 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/administrator/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsqwAAAWk"]
[Thu Sep 17 15:04:54.132355 2026] [security2:error] [pid 955873:tid 956079] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mysql/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrssQAAAVY"]
[Thu Sep 17 15:04:54.181877 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/jenkins/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrssgAAAUg"]
[Thu Sep 17 15:04:54.246397 2026] [security2:error] [pid 955873:tid 956085] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/psnlink/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrstgAAAVw"]
[Thu Sep 17 15:04:54.247451 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrsrQAAAV0"]
[Thu Sep 17 15:04:54.247470 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrsrQAAAV0"]
[Thu Sep 17 15:04:54.253785 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/gitlab/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrstwAAATk"]
[Thu Sep 17 15:04:54.301285 2026] [security2:error] [pid 955873:tid 956014] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/postgres/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsuwAAARU"]
[Thu Sep 17 15:04:54.342405 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/github/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsvwAAAUM"]
[Thu Sep 17 15:04:54.390132 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/Message.php"] [unique_id "aqxV9hFTPRVSLOsRVhrswAAAAQo"]
[Thu Sep 17 15:04:54.390242 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/Message.php"] [unique_id "aqxV9hFTPRVSLOsRVhrswAAAAQo"]
[Thu Sep 17 15:04:54.399767 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/exapi/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrswQAAASE"]
[Thu Sep 17 15:04:54.453148 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/actions/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrswgAAAWg"]
[Thu Sep 17 15:04:54.464599 2026] [security2:error] [pid 955873:tid 956064] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mongodb/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrswwAAAUc"]
[Thu Sep 17 15:04:54.531075 2026] [core:error] [pid 955873:tid 956095] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:54.531095 2026] [core:error] [pid 955873:tid 956095] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:54.549092 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/circleci/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsygAAAVk"]
[Thu Sep 17 15:04:54.553581 2026] [security2:error] [pid 955873:tid 956125] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sitemaps/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrszAAAAYQ"]
[Thu Sep 17 15:04:54.587987 2026] [security2:error] [pid 955873:tid 956011] [client 45.146.54.107:57459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrsxwAAARI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:54.630271 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/travis/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrszwAAASM"]
[Thu Sep 17 15:04:54.632109 2026] [security2:error] [pid 955873:tid 956005] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/redis/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs0AAAAQw"]
[Thu Sep 17 15:04:54.666571 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/MessagePart.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs0gAAAXo"]
[Thu Sep 17 15:04:54.666687 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/MessagePart.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs0gAAAXo"]
[Thu Sep 17 15:04:54.728498 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/buildkite/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs2AAAAXc"]
[Thu Sep 17 15:04:54.737779 2026] [security2:error] [pid 955873:tid 956010] [client 3.82.141.143:8040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3AAAARE"]
[Thu Sep 17 15:04:54.744136 2026] [security2:error] [pid 955873:tid 956083] [client 3.82.141.143:8108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php.save"] [unique_id "aqxV9hFTPRVSLOsRVhrs4QAAAVo"]
[Thu Sep 17 15:04:54.745241 2026] [security2:error] [pid 955873:tid 956021] [client 3.82.141.143:7930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3QAAARw"]
[Thu Sep 17 15:04:54.746004 2026] [security2:error] [pid 955873:tid 956069] [client 3.82.141.143:7972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3gAAAUw"]
[Thu Sep 17 15:04:54.746316 2026] [security2:error] [pid 955873:tid 956020] [client 3.82.141.143:7914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3wAAARs"]
[Thu Sep 17 15:04:54.746948 2026] [security2:error] [pid 955873:tid 956076] [client 3.82.141.143:7998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs4AAAAVM"]
[Thu Sep 17 15:04:54.754933 2026] [security2:error] [pid 955873:tid 956061] [client 3.82.141.143:7886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env.bak"] [unique_id "aqxV9hFTPRVSLOsRVhrs5AAAAUQ"]
[Thu Sep 17 15:04:54.755120 2026] [security2:error] [pid 955873:tid 956062] [client 3.82.141.143:7948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs4gAAAUU"]
[Thu Sep 17 15:04:54.756044 2026] [security2:error] [pid 955873:tid 956055] [client 3.82.141.143:7960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs4wAAAT4"]
[Thu Sep 17 15:04:54.756387 2026] [security2:error] [pid 955873:tid 956120] [client 3.82.141.143:8130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs5QAAAX8"]
[Thu Sep 17 15:04:54.756953 2026] [security2:error] [pid 955873:tid 956025] [client 3.82.141.143:8184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php~"] [unique_id "aqxV9hFTPRVSLOsRVhrs5gAAASA"]
[Thu Sep 17 15:04:54.760575 2026] [security2:error] [pid 955873:tid 956089] [client 3.82.141.143:8146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs5wAAAWA"]
[Thu Sep 17 15:04:54.763197 2026] [security2:error] [pid 955873:tid 956027] [client 3.82.141.143:7860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs6AAAASI"]
[Thu Sep 17 15:04:54.763831 2026] [security2:error] [pid 955873:tid 956039] [client 3.82.141.143:7970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/web.config"] [unique_id "aqxV9hFTPRVSLOsRVhrs6gAAAS4"]
[Thu Sep 17 15:04:54.764698 2026] [security2:error] [pid 955873:tid 956054] [client 3.82.141.143:8006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs6QAAAT0"]
[Thu Sep 17 15:04:54.767783 2026] [security2:error] [pid 955873:tid 956045] [client 3.82.141.143:8042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs6wAAATQ"]
[Thu Sep 17 15:04:54.769283 2026] [security2:error] [pid 955873:tid 956032] [client 3.82.141.143:8046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7gAAASc"]
[Thu Sep 17 15:04:54.769339 2026] [security2:error] [pid 955873:tid 956111] [client 3.82.141.143:8032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7AAAAXY"]
[Thu Sep 17 15:04:54.769370 2026] [security2:error] [pid 955873:tid 956018] [client 3.82.141.143:7896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7QAAARk"]
[Thu Sep 17 15:04:54.771518 2026] [security2:error] [pid 955873:tid 956072] [client 3.82.141.143:8168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7wAAAU8"]
[Thu Sep 17 15:04:54.775560 2026] [security2:error] [pid 955873:tid 956080] [client 3.82.141.143:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.subscribe.faewave.com"] [uri "/config.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs8AAAAVc"]
[Thu Sep 17 15:04:54.776131 2026] [security2:error] [pid 955873:tid 956092] [client 3.82.141.143:8090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php.old"] [unique_id "aqxV9hFTPRVSLOsRVhrs8gAAAWM"]
[Thu Sep 17 15:04:54.777689 2026] [security2:error] [pid 955873:tid 956114] [client 3.82.141.143:8104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs8QAAAXk"]
[Thu Sep 17 15:04:54.783815 2026] [security2:error] [pid 955873:tid 956122] [client 3.82.141.143:8156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9AAAAYE"]
[Thu Sep 17 15:04:54.790310 2026] [security2:error] [pid 955873:tid 956103] [client 3.82.141.143:7912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9gAAAW4"]
[Thu Sep 17 15:04:54.790337 2026] [security2:error] [pid 955873:tid 956091] [client 3.82.141.143:8044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9QAAAWI"]
[Thu Sep 17 15:04:54.795053 2026] [security2:error] [pid 955873:tid 956051] [client 3.82.141.143:7988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9wAAATo"]
[Thu Sep 17 15:04:54.795857 2026] [security2:error] [pid 955873:tid 956007] [client 3.82.141.143:8054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs-gAAAQ4"]
[Thu Sep 17 15:04:54.797589 2026] [security2:error] [pid 955873:tid 956110] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/elasticsearch/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs-wAAAXU"]
[Thu Sep 17 15:04:54.797614 2026] [security2:error] [pid 955873:tid 956046] [client 3.82.141.143:8200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs-QAAATU"]
[Thu Sep 17 15:04:54.799921 2026] [security2:error] [pid 955873:tid 956123] [client 3.82.141.143:7864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs_AAAAYI"]
[Thu Sep 17 15:04:54.802731 2026] [security2:error] [pid 955873:tid 956101] [client 3.82.141.143:7984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs_gAAAWw"]
[Thu Sep 17 15:04:54.802813 2026] [security2:error] [pid 955873:tid 956056] [client 3.82.141.143:8132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs_wAAAT8"]
[Thu Sep 17 15:04:54.803376 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mysql/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrtAQAAAWQ"]
[Thu Sep 17 15:04:54.827559 2026] [security2:error] [pid 955873:tid 956042] [client 3.82.141.143:8058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php.bak"] [unique_id "aqxV9hFTPRVSLOsRVhrtBwAAATE"]
[Thu Sep 17 15:04:54.828533 2026] [security2:error] [pid 955873:tid 956013] [client 3.82.141.143:8004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env.backup"] [unique_id "aqxV9hFTPRVSLOsRVhrtBgAAARQ"]
[Thu Sep 17 15:04:54.828560 2026] [security2:error] [pid 955873:tid 956090] [client 3.82.141.143:7870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env.old"] [unique_id "aqxV9hFTPRVSLOsRVhrtBQAAAWE"]
[Thu Sep 17 15:04:54.829648 2026] [security2:error] [pid 955873:tid 956038] [client 3.82.141.143:8022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtBAAAAS0"]
[Thu Sep 17 15:04:54.829776 2026] [security2:error] [pid 955873:tid 956049] [client 3.82.141.143:7938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtAwAAATg"]
[Thu Sep 17 15:04:54.830273 2026] [security2:error] [pid 955873:tid 956059] [client 3.82.141.143:8080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtCAAAAUI"]
[Thu Sep 17 15:04:54.833571 2026] [security2:error] [pid 955873:tid 956104] [client 3.82.141.143:8126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtCQAAAW8"]
[Thu Sep 17 15:04:54.834925 2026] [security2:error] [pid 955873:tid 956016] [client 3.82.141.143:7852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtCgAAARc"]
[Thu Sep 17 15:04:54.900869 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/postgres/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrtDQAAAUM"]
[Thu Sep 17 15:04:54.954092 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/ModelMessage.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtEQAAAW0"]
[Thu Sep 17 15:04:54.954168 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/ModelMessage.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtEQAAAW0"]
[Thu Sep 17 15:04:54.970879 2026] [security2:error] [pid 955873:tid 956125] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/rabbitmq/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrtEgAAAYQ"]
[Thu Sep 17 15:04:55.102825 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mongodb/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtFAAAATA"]
[Thu Sep 17 15:04:55.147468 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/logs/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtFwAAAQw"]
[Thu Sep 17 15:04:55.147517 2026] [security2:error] [pid 955873:tid 956028] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/kafka/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtGAAAASM"]
[Thu Sep 17 15:04:55.166180 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/redis/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtGQAAAWU"]
[Thu Sep 17 15:04:55.230980 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/elasticsearch/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtHQAAARs"]
[Thu Sep 17 15:04:55.248263 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/UserMessage.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtHwAAAVM"]
[Thu Sep 17 15:04:55.248361 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:47764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/UserMessage.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtHwAAAVM"]
[Thu Sep 17 15:04:55.301367 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cache/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtIgAAAUU"]
[Thu Sep 17 15:04:55.309488 2026] [security2:error] [pid 955873:tid 956055] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/queue/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtIwAAAT4"]
[Thu Sep 17 15:04:55.313935 2026] [security2:error] [pid 955873:tid 956120] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/rabbitmq/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtJAAAAX8"]
[Thu Sep 17 15:04:55.389885 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/kafka/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtJQAAASA"]
[Thu Sep 17 15:04:55.419913 2026] [security2:error] [pid 955873:tid 956054] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "aqxV9xFTPRVSLOsRVhrtJgAAAT0"]
[Thu Sep 17 15:04:55.453547 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailer/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtJwAAATQ"]
[Thu Sep 17 15:04:55.471218 2026] [security2:error] [pid 955873:tid 956032] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/worker/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtKAAAASc"]
[Thu Sep 17 15:04:55.502599 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/queue/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtKQAAARk"]
[Thu Sep 17 15:04:55.531331 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:47774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/"] [unique_id "aqxV9xFTPRVSLOsRVhrtKwAAAU4"]
[Thu Sep 17 15:04:55.581616 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/worker/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtLAAAATY"]
[Thu Sep 17 15:04:55.612400 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mail/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtLQAAAVc"]
[Thu Sep 17 15:04:55.635257 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/job/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtLgAAAWM"]
[Thu Sep 17 15:04:55.648118 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "aqxV9xFTPRVSLOsRVhrtLwAAAXk"]
[Thu Sep 17 15:04:55.678241 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/job/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtMgAAAW4"]
[Thu Sep 17 15:04:55.686462 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/"] [unique_id "aqxV9xFTPRVSLOsRVhrtMQAAAYE"]
[Thu Sep 17 15:04:55.764971 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/email/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtNwAAAYI"]
[Thu Sep 17 15:04:55.770980 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/test/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtOAAAAQ0"]
[Thu Sep 17 15:04:55.801132 2026] [security2:error] [pid 955873:tid 956130] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtOgAAAYk"]
[Thu Sep 17 15:04:55.827228 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:47774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9xFTPRVSLOsRVhrtOwAAAWw"]
[Thu Sep 17 15:04:55.853141 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/qa/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtPAAAAT8"]
[Thu Sep 17 15:04:55.917600 2026] [security2:error] [pid 955873:tid 956090] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/smtp/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtPwAAAWE"]
[Thu Sep 17 15:04:55.924828 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/preview/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtQwAAAS0"]
[Thu Sep 17 15:04:55.963758 2026] [security2:error] [pid 955873:tid 956059] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtRAAAAUI"]
[Thu Sep 17 15:04:56.011718 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/beta/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtRwAAAUA"]
[Thu Sep 17 15:04:56.028913 2026] [security2:error] [pid 955873:tid 956065] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/Total-Soft-Calendar/CSS/totalsoft.css"] [unique_id "aqxV-BFTPRVSLOsRVhrtSAAAAUg"]
[Thu Sep 17 15:04:56.073207 2026] [security2:error] [pid 955873:tid 956022] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailing/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtSQAAAR0"]
[Thu Sep 17 15:04:56.091929 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/uat/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtSgAAAXM"]
[Thu Sep 17 15:04:56.144405 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/preview/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtSwAAAVw"]
[Thu Sep 17 15:04:56.147167 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtRQAAAYc"]
[Thu Sep 17 15:04:56.147186 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtRQAAAYc"]
[Thu Sep 17 15:04:56.208850 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/stage/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtTgAAATI"]
[Thu Sep 17 15:04:56.233616 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/notifications/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtUgAAASY"]
[Thu Sep 17 15:04:56.306752 2026] [security2:error] [pid 955873:tid 956017] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtVgAAARg"]
[Thu Sep 17 15:04:56.313076 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/development/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtVwAAAXg"]
[Thu Sep 17 15:04:56.319637 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartChannelEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtWAAAAQo"]
[Thu Sep 17 15:04:56.319735 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartChannelEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtWAAAAQo"]
[Thu Sep 17 15:04:56.381030 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/production/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtWwAAAV8"]
[Thu Sep 17 15:04:56.391945 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/notify/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtXAAAASE"]
[Thu Sep 17 15:04:56.418905 2026] [core:error] [pid 955873:tid 956067] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:56.418920 2026] [core:error] [pid 955873:tid 956067] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:56.468369 2026] [security2:error] [pid 955873:tid 956097] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/uat/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtXgAAAWg"]
[Thu Sep 17 15:04:56.480063 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/config/app/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtXwAAATs"]
[Thu Sep 17 15:04:56.544709 2026] [security2:error] [pid 955873:tid 956102] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sender/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtYAAAAW0"]
[Thu Sep 17 15:04:56.608081 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.224.217:40334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtYQAAAR4"]
[Thu Sep 17 15:04:56.618920 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartTypeEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtYwAAAU0"]
[Thu Sep 17 15:04:56.618994 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartTypeEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtYwAAAU0"]
[Thu Sep 17 15:04:56.631256 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtZgAAAYM"]
[Thu Sep 17 15:04:56.665037 2026] [security2:error] [pid 955873:tid 955973] [remote 216.73.217.142:18291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxV-BFTPRVSLOsRVhrtaAABQWM"]
[Thu Sep 17 15:04:56.702828 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/campaign/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtawAAAX0"]
[Thu Sep 17 15:04:56.796838 2026] [security2:error] [pid 955873:tid 956021] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtbgAAARw"]
[Thu Sep 17 15:04:56.857047 2026] [security2:error] [pid 955873:tid 956109] [client 127.0.0.1:46532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxV-BFTPRVSLOsRVhrtcAAAAXQ"]
[Thu Sep 17 15:04:56.857055 2026] [security2:error] [pid 955873:tid 956083] [client 74.7.241.176:49614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wxv.noo.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxV-BFTPRVSLOsRVhrtbwAAAVo"]
[Thu Sep 17 15:04:56.858240 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/newsletter/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtcQAAAVU"]
[Thu Sep 17 15:04:56.898568 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:47790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessageRoleEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtcgAAAT4"]
[Thu Sep 17 15:04:56.898645 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:47790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessageRoleEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtcgAAAT4"]
[Thu Sep 17 15:04:56.949895 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/info.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtdAAAARs"]
[Thu Sep 17 15:04:56.958241 2026] [security2:error] [pid 955873:tid 956025] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtdgAAASA"]
[Thu Sep 17 15:04:57.010016 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/ses/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtegAAATQ"]
[Thu Sep 17 15:04:57.085773 2026] [security2:error] [pid 955873:tid 956080] [client 20.244.34.24:63582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtewAAAVc"], referer: binance.com
[Thu Sep 17 15:04:57.120787 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/config/app/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtfAAAAWM"]
[Thu Sep 17 15:04:57.162639 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sendgrid/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtfQAAAXk"]
[Thu Sep 17 15:04:57.190828 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/ModalityEnum.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtfgAAAW4"]
[Thu Sep 17 15:04:57.190908 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/ModalityEnum.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtfgAAAW4"]
[Thu Sep 17 15:04:57.296455 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/php.php"] [unique_id "aqxV-RFTPRVSLOsRVhrthwAAAYI"]
[Thu Sep 17 15:04:57.305521 2026] [security2:error] [pid 955873:tid 956056] [client 34.95.193.102:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php"] [unique_id "aqxV-RFTPRVSLOsRVhrthgAAAT8"]
[Thu Sep 17 15:04:57.315596 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sparkpost/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtiAAAAQ4"]
[Thu Sep 17 15:04:57.451532 2026] [security2:error] [pid 955873:tid 956037] [client 216.73.163.56:45159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtiQAAASw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:57.467841 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-RFTPRVSLOsRVhrtjwAAAVw"]
[Thu Sep 17 15:04:57.470765 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/postmark/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtkQAAAYc"]
[Thu Sep 17 15:04:57.522607 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:40364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/i.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtlAAAAV4"]
[Thu Sep 17 15:04:57.560544 2026] [security2:error] [pid 955873:tid 956086] [client 85.208.98.197:18625] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/totop.min.js"] [unique_id "aqxV-RFTPRVSLOsRVhrtlQAAAV0"]
[Thu Sep 17 15:04:57.624770 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailgun/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtlwAAAUM"]
[Thu Sep 17 15:04:57.641536 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-RFTPRVSLOsRVhrtlgAAAXg"]
[Thu Sep 17 15:04:57.777191 2026] [security2:error] [pid 955873:tid 956068] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mandrill/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtoAAAAUs"]
[Thu Sep 17 15:04:57.779823 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/wp-includes/php-ai-client/src/"] [unique_id "aqxV-RFTPRVSLOsRVhrtogAAASQ"]
[Thu Sep 17 15:04:57.790050 2026] [security2:error] [pid 955873:tid 956088] [client 34.95.193.102:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/info.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtowAAAV8"]
[Thu Sep 17 15:04:57.795602 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/pi.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtpAAAASg"]
[Thu Sep 17 15:04:57.932498 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailjet/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtqAAAAX0"]
[Thu Sep 17 15:04:58.023350 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtqgAAAVM"]
[Thu Sep 17 15:04:58.087085 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/brevo/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtrgAAAS8"]
[Thu Sep 17 15:04:58.091530 2026] [security2:error] [pid 955873:tid 956062] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/jquery/ui/core.min.js"] [unique_id "aqxV-hFTPRVSLOsRVhrtrwAAAUU"]
[Thu Sep 17 15:04:58.120073 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtpQAAAR8"]
[Thu Sep 17 15:04:58.120101 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtpQAAAR8"]
[Thu Sep 17 15:04:58.122452 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/pinfo.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtsAAAAXQ"]
[Thu Sep 17 15:04:58.242761 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/transactional/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrttwAAAUw"]
[Thu Sep 17 15:04:58.251787 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtuAAAAXc"]
[Thu Sep 17 15:04:58.257987 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/"] [unique_id "aqxV-hFTPRVSLOsRVhrtugAAAS4"]
[Thu Sep 17 15:04:58.258108 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:62741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtuQAAAUE"]
[Thu Sep 17 15:04:58.258207 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:62741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtuQAAAUE"]
[Thu Sep 17 15:04:58.288251 2026] [security2:error] [pid 955873:tid 956005] [client 34.95.193.102:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/php.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtuwAAAQw"]
[Thu Sep 17 15:04:58.366987 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:41344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtvwAAATc"]
[Thu Sep 17 15:04:58.372910 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:41344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtvwAAATc"]
[Thu Sep 17 15:04:58.396433 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/bulk/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtwQAAAVc"]
[Thu Sep 17 15:04:58.400723 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.224.217:40386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/test.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtwgAAASc"]
[Thu Sep 17 15:04:58.412344 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/"] [unique_id "aqxV-hFTPRVSLOsRVhrtwAAAATY"]
[Thu Sep 17 15:04:58.493746 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtwwAAATo"]
[Thu Sep 17 15:04:58.549157 2026] [security2:error] [pid 955873:tid 956090] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/aws/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtxQAAAWE"]
[Thu Sep 17 15:04:58.593575 2026] [security2:error] [pid 955873:tid 956007] [client 216.73.163.43:41291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtxAAAAQ4"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:58.655681 2026] [security2:error] [pid 955873:tid 956050] [client 5.189.145.112:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-login.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtyAAAATk"], referer: binance.com
[Thu Sep 17 15:04:58.697867 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-hFTPRVSLOsRVhrtyQAAAYE"]
[Thu Sep 17 15:04:58.711564 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/azure/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtzAAAAYc"]
[Thu Sep 17 15:04:58.722339 2026] [security2:error] [pid 955873:tid 956072] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtzQAAAU8"]
[Thu Sep 17 15:04:58.778426 2026] [security2:error] [pid 955873:tid 956049] [client 34.95.193.102:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/i.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt1wAAATg"]
[Thu Sep 17 15:04:58.854252 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.224.217:40400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/p.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt2gAAASk"]
[Thu Sep 17 15:04:58.863779 2026] [security2:error] [pid 955873:tid 956087] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/gcp/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrt3AAAAV4"]
[Thu Sep 17 15:04:58.940081 2026] [security2:error] [pid 955873:tid 956043] [client 216.73.163.57:51655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt3wAAATI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:58.949856 2026] [security2:error] [pid 955873:tid 956022] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrt4wAAAR0"]
[Thu Sep 17 15:04:59.033144 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt2QAAASU"]
[Thu Sep 17 15:04:59.033166 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt2QAAASU"]
[Thu Sep 17 15:04:59.138182 2026] [security2:error] [pid 955873:tid 956031] [client 45.169.98.18:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5gAAASY"]
[Thu Sep 17 15:04:59.138298 2026] [security2:error] [pid 955873:tid 956031] [client 45.169.98.18:50427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5gAAASY"]
[Thu Sep 17 15:04:59.175729 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/OperationInterface.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5wAAASg"]
[Thu Sep 17 15:04:59.175816 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/OperationInterface.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5wAAASg"]
[Thu Sep 17 15:04:59.178250 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "aqxV-xFTPRVSLOsRVhrt6AAAATs"]
[Thu Sep 17 15:04:59.178799 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/debug.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt6QAAAVg"]
[Thu Sep 17 15:04:59.264989 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/pi.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt7AAAAXE"]
[Thu Sep 17 15:04:59.462949 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/"] [unique_id "aqxV-xFTPRVSLOsRVhrt8QAAAVo"]
[Thu Sep 17 15:04:59.513813 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.224.217:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt8gAAARU"]
[Thu Sep 17 15:04:59.616703 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/"] [unique_id "aqxV-xFTPRVSLOsRVhrt9QAAAXQ"]
[Thu Sep 17 15:04:59.669386 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt-wAAAWU"]
[Thu Sep 17 15:04:59.669459 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:59299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt-wAAAWU"]
[Thu Sep 17 15:04:59.677869 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "aqxV-xFTPRVSLOsRVhrt_AAAAXc"]
[Thu Sep 17 15:04:59.696709 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cloud/.env"] [unique_id "aqxV-xFTPRVSLOsRVhrt_gAAAVU"]
[Thu Sep 17 15:04:59.756348 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.193.102:43888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/pinfo.php"] [unique_id "aqxV-xFTPRVSLOsRVhruAQAAAUU"]
[Thu Sep 17 15:04:59.760412 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:47804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-xFTPRVSLOsRVhruAgAAASA"]
[Thu Sep 17 15:04:59.851580 2026] [security2:error] [pid 955873:tid 956115] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/infrastructure/.env"] [unique_id "aqxV-xFTPRVSLOsRVhruBgAAAXo"]
[Thu Sep 17 15:04:59.854073 2026] [security2:error] [pid 955873:tid 956071] [client 67.205.2.98:36740] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.luxelivinglv.com"] [uri "/"] [unique_id "aqxV-xFTPRVSLOsRVhruBwAAAU4"]
[Thu Sep 17 15:04:59.869071 2026] [security2:error] [pid 955873:tid 956091] [client 45.146.54.111:31707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV-xFTPRVSLOsRVhruBQAAAWI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:59.886827 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:40420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/test/phpinfo.php"] [unique_id "aqxV-xFTPRVSLOsRVhruCAAAATY"]
[Thu Sep 17 15:04:59.907561 2026] [security2:error] [pid 955873:tid 956093] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "aqxV-xFTPRVSLOsRVhruCgAAAWQ"]
[Thu Sep 17 15:05:00.008267 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/docker/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruCwAAAYc"]
[Thu Sep 17 15:05:00.042065 2026] [security2:error] [pid 955873:tid 956122] [client 67.205.2.98:36742] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.luxelivinglv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxV_BFTPRVSLOsRVhruDAAAAYE"]
[Thu Sep 17 15:05:00.094924 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-xFTPRVSLOsRVhruCQAAAX8"]
[Thu Sep 17 15:05:00.094944 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-xFTPRVSLOsRVhruCQAAAX8"]
[Thu Sep 17 15:05:00.139091 2026] [security2:error] [pid 955873:tid 956034] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruDQAAASk"]
[Thu Sep 17 15:05:00.156089 2026] [security2:error] [pid 955873:tid 956043] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/Total-Soft-Calendar/JS/Total-Soft-Calendar-Widget.js"] [unique_id "aqxV_BFTPRVSLOsRVhruDgAAATI"]
[Thu Sep 17 15:05:00.161704 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/k8s/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruDwAAARg"]
[Thu Sep 17 15:05:00.162946 2026] [security2:error] [pid 955873:tid 956057] [client 104.28.198.244:22864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV_BFTPRVSLOsRVhruEAAAAUA"]
[Thu Sep 17 15:05:00.233814 2026] [security2:error] [pid 955873:tid 956026] [client 67.205.2.98:36758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.205.67.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.luxelivinglv.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruFgAAASE"]
[Thu Sep 17 15:05:00.239269 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:47804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/GenerativeAiOperation.php"] [unique_id "aqxV_BFTPRVSLOsRVhruFwAAASo"]
[Thu Sep 17 15:05:00.239344 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:47804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/GenerativeAiOperation.php"] [unique_id "aqxV_BFTPRVSLOsRVhruFwAAASo"]
[Thu Sep 17 15:05:00.260018 2026] [security2:error] [pid 955873:tid 956049] [client 34.95.193.102:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/test.php"] [unique_id "aqxV_BFTPRVSLOsRVhruGQAAATg"]
[Thu Sep 17 15:05:00.323860 2026] [security2:error] [pid 955873:tid 956016] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/kubernetes/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruGgAAARc"]
[Thu Sep 17 15:05:00.342315 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxV_BFTPRVSLOsRVhruGwAAAUM"]
[Thu Sep 17 15:05:00.356741 2026] [security2:error] [pid 955873:tid 956057] [client 104.28.198.244:22864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV_BFTPRVSLOsRVhruEAAAAUA"]
[Thu Sep 17 15:05:00.370228 2026] [security2:error] [pid 955873:tid 956085] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruHQAAAVw"]
[Thu Sep 17 15:05:00.440637 2026] [security2:error] [pid 955873:tid 956042] [client 67.205.2.98:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.205.67.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.luxelivinglv.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxV_BFTPRVSLOsRVhruHwAAATE"]
[Thu Sep 17 15:05:00.489312 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/terraform/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruIQAAASY"]
[Thu Sep 17 15:05:00.533076 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:46998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/"] [unique_id "aqxV_BFTPRVSLOsRVhruIwAAAXE"]
[Thu Sep 17 15:05:00.601840 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruJQAAAVk"]
[Thu Sep 17 15:05:00.649013 2026] [security2:error] [pid 955873:tid 956097] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/ansible/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruJgAAAWg"]
[Thu Sep 17 15:05:00.691324 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:40444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/old/phpinfo.php"] [unique_id "aqxV_BFTPRVSLOsRVhruKQAAARE"]
[Thu Sep 17 15:05:00.695566 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/"] [unique_id "aqxV_BFTPRVSLOsRVhruKAAAAWY"]
[Thu Sep 17 15:05:00.808246 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/.git/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruLwAAAXQ"]
[Thu Sep 17 15:05:00.828258 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/core/app/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruMQAAAWU"]
[Thu Sep 17 15:05:00.834739 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:46998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV_BFTPRVSLOsRVhruMgAAAUw"]
[Thu Sep 17 15:05:00.963762 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/ci/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruNwAAATc"]
[Thu Sep 17 15:05:00.982608 2026] [security2:error] [pid 955873:tid 956024] [client 34.95.193.102:43908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/p.php"] [unique_id "aqxV_BFTPRVSLOsRVhruOQAAAR8"]
[Thu Sep 17 15:05:01.013243 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.224.217:42612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxV_RFTPRVSLOsRVhruOgAAAVE"]
[Thu Sep 17 15:05:01.056893 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruOwAAAT4"]
[Thu Sep 17 15:05:01.120035 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cd/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruPQAAAUY"]
[Thu Sep 17 15:05:01.211612 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruOAAAASA"]
[Thu Sep 17 15:05:01.211636 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruOAAAASA"]
[Thu Sep 17 15:05:01.276004 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/jenkins/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruQgAAASc"]
[Thu Sep 17 15:05:01.285602 2026] [security2:error] [pid 955873:tid 956056] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruQwAAAT8"]
[Thu Sep 17 15:05:01.347165 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:42616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/public/phpinfo.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRAAAAYk"]
[Thu Sep 17 15:05:01.348866 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:46998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/OperationStateEnum.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRQAAAQ4"]
[Thu Sep 17 15:05:01.348941 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:46998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/OperationStateEnum.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRQAAAQ4"]
[Thu Sep 17 15:05:01.430773 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/gitlab/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruRgAAAU4"]
[Thu Sep 17 15:05:01.479437 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.193.102:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/debug.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRwAAAV0"]
[Thu Sep 17 15:05:01.516309 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruSQAAAW8"]
[Thu Sep 17 15:05:01.585604 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/github/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruSgAAATY"]
[Thu Sep 17 15:05:01.625211 2026] [security2:error] [pid 955873:tid 956064] [client 108.88.72.220:41155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV_RFTPRVSLOsRVhruSAABRwo"], referer: https://www.google.com/
[Thu Sep 17 15:05:01.626258 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:47014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxV_RFTPRVSLOsRVhruSwAAAWQ"]
[Thu Sep 17 15:05:01.744826 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/bootstrap/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruTwAAASI"]
[Thu Sep 17 15:05:01.747230 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/actions/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruUgAAATU"]
[Thu Sep 17 15:05:01.768021 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.224.217:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/php-info.php"] [unique_id "aqxV_RFTPRVSLOsRVhruVAAAASw"]
[Thu Sep 17 15:05:01.825460 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxV_RFTPRVSLOsRVhruUwAAAS4"]
[Thu Sep 17 15:05:01.905602 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/circleci/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruWQAAATI"]
[Thu Sep 17 15:05:01.965032 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:47014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/wp-includes/php-ai-client/src/"] [unique_id "aqxV_RFTPRVSLOsRVhruWwAAASo"]
[Thu Sep 17 15:05:01.972837 2026] [security2:error] [pid 955873:tid 956072] [client 34.95.193.102:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/admin/phpinfo.php"] [unique_id "aqxV_RFTPRVSLOsRVhruXAAAAU8"]
[Thu Sep 17 15:05:01.974282 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruXQAAATg"]
[Thu Sep 17 15:05:02.004408 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:42630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpversion.php"] [unique_id "aqxV_hFTPRVSLOsRVhruXgAAASE"]
[Thu Sep 17 15:05:02.062274 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/travis/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruXwAAAUM"]
[Thu Sep 17 15:05:02.202142 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruZQAAAV8"]
[Thu Sep 17 15:05:02.209509 2026] [security2:error] [pid 955873:tid 956098] [client 57.141.14.91:45032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "calgarytelephone.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruJAABaQE"]
[Thu Sep 17 15:05:02.215962 2026] [security2:error] [pid 955873:tid 956059] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/buildkite/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruZgAAAUI"]
[Thu Sep 17 15:05:02.219082 2026] [security2:error] [pid 955873:tid 956033] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/show-hide.min.js"] [unique_id "aqxV_hFTPRVSLOsRVhruZwAAASg"]
[Thu Sep 17 15:05:02.326787 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_hFTPRVSLOsRVhruYQAAAVw"]
[Thu Sep 17 15:05:02.326809 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_hFTPRVSLOsRVhruYQAAAVw"]
[Thu Sep 17 15:05:02.361085 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:42644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/_phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhruagAAAVg"]
[Thu Sep 17 15:05:02.369803 2026] [security2:error] [pid 955873:tid 956070] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mysql/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruawAAAU0"]
[Thu Sep 17 15:05:02.430213 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrubAAAATM"]
[Thu Sep 17 15:05:02.459969 2026] [security2:error] [pid 955873:tid 956102] [client 34.95.193.102:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/test/phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhrubQAAAW0"]
[Thu Sep 17 15:05:02.466596 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/AbstractProvider.php"] [unique_id "aqxV_hFTPRVSLOsRVhrubgAAAXs"]
[Thu Sep 17 15:05:02.466701 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:47014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/AbstractProvider.php"] [unique_id "aqxV_hFTPRVSLOsRVhrubgAAAXs"]
[Thu Sep 17 15:05:02.526419 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/postgres/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrubwAAAVk"]
[Thu Sep 17 15:05:02.649873 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/old_phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhrucQAAAWg"]
[Thu Sep 17 15:05:02.657668 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrucgAAARU"]
[Thu Sep 17 15:05:02.683164 2026] [security2:error] [pid 955873:tid 956124] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mongodb/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrudQAAAYM"]
[Thu Sep 17 15:05:02.740741 2026] [security2:error] [pid 955873:tid 956065] [client 216.73.163.52:31047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV_hFTPRVSLOsRVhrucwAAAUg"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:02.761732 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/"] [unique_id "aqxV_hFTPRVSLOsRVhruegAAAYQ"]
[Thu Sep 17 15:05:02.836638 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/redis/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruewAAAUU"]
[Thu Sep 17 15:05:02.886666 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/current/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrufAAAAR8"]
[Thu Sep 17 15:05:02.932197 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/"] [unique_id "aqxV_hFTPRVSLOsRVhrufQAAAVE"]
[Thu Sep 17 15:05:02.950397 2026] [security2:error] [pid 955873:tid 956045] [client 34.95.193.102:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/dev/phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhrufgAAATQ"]
[Thu Sep 17 15:05:02.951401 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/server-info.php"] [unique_id "aqxV_hFTPRVSLOsRVhrufwAAATc"]
[Thu Sep 17 15:05:02.952193 2026] [security2:error] [pid 955873:tid 956080] [client 20.244.34.24:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxV_hFTPRVSLOsRVhrugAAAAVc"], referer: binance.com
[Thu Sep 17 15:05:02.990141 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/elasticsearch/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrugwAAASc"]
[Thu Sep 17 15:05:03.078943 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:47016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxV_xFTPRVSLOsRVhruhwAAAYg"]
[Thu Sep 17 15:05:03.114816 2026] [security2:error] [pid 955873:tid 956038] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/release/.env"] [unique_id "aqxV_xFTPRVSLOsRVhruiAAAAS0"]
[Thu Sep 17 15:05:03.145602 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/rabbitmq/.env"] [unique_id "aqxV_xFTPRVSLOsRVhruiQAAAYI"]
[Thu Sep 17 15:05:03.305737 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/kafka/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrujgAAAUE"]
[Thu Sep 17 15:05:03.342097 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.224.217:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/server-status.php"] [unique_id "aqxV_xFTPRVSLOsRVhrukAAAAUc"]
[Thu Sep 17 15:05:03.343690 2026] [security2:error] [pid 955873:tid 956091] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/releases/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrujwAAAWI"]
[Thu Sep 17 15:05:03.415813 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhrujAAAAW8"]
[Thu Sep 17 15:05:03.415838 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhrujAAAAW8"]
[Thu Sep 17 15:05:03.450509 2026] [security2:error] [pid 955873:tid 956009] [client 108.88.72.220:50619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhrukQABEAM"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726005457&hideliu=1&hideminor=1&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:05:03.456167 2026] [security2:error] [pid 955873:tid 956093] [client 34.95.193.102:43950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/old/phpinfo.php"] [unique_id "aqxV_xFTPRVSLOsRVhrukwAAAWQ"]
[Thu Sep 17 15:05:03.464025 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/queue/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrulAAAAR4"]
[Thu Sep 17 15:05:03.486892 2026] [security2:error] [pid 955873:tid 956115] [client 47.79.206.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhruigAAAXo"], referer: https://www.google.com/
[Thu Sep 17 15:05:03.559787 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:47016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModel.php"] [unique_id "aqxV_xFTPRVSLOsRVhrulgAAAX8"]
[Thu Sep 17 15:05:03.559873 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:47016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModel.php"] [unique_id "aqxV_xFTPRVSLOsRVhrulgAAAX8"]
[Thu Sep 17 15:05:03.570998 2026] [security2:error] [pid 955873:tid 956034] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrumAAAASk"]
[Thu Sep 17 15:05:03.619141 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/worker/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrumgAAATI"]
[Thu Sep 17 15:05:03.772795 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/job/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrusgAAAYA"]
[Thu Sep 17 15:05:03.796232 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxV_xFTPRVSLOsRVhruswAAASg"]
[Thu Sep 17 15:05:03.798422 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrutAAAATs"]
[Thu Sep 17 15:05:03.840037 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModelMetadataDirectory.php"] [unique_id "aqxV_xFTPRVSLOsRVhrutQAAAVw"]
[Thu Sep 17 15:05:03.840117 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModelMetadataDirectory.php"] [unique_id "aqxV_xFTPRVSLOsRVhrutQAAAVw"]
[Thu Sep 17 15:05:03.925742 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/test/.env"] [unique_id "aqxV_xFTPRVSLOsRVhruugAAASQ"]
[Thu Sep 17 15:05:03.945429 2026] [security2:error] [pid 955873:tid 956098] [client 34.95.193.102:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/tmp/phpinfo.php"] [unique_id "aqxV_xFTPRVSLOsRVhruuwAAAWk"]
[Thu Sep 17 15:05:04.003946 2026] [security2:error] [pid 955873:tid 956031] [client 185.55.149.49:61895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWABFTPRVSLOsRVhruvQAAASY"]
[Thu Sep 17 15:05:04.004025 2026] [security2:error] [pid 955873:tid 956031] [client 185.55.149.49:61895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWABFTPRVSLOsRVhruvQAAASY"]
[Thu Sep 17 15:05:04.026120 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/build/.env"] [unique_id "aqxWABFTPRVSLOsRVhruvgAAAVk"]
[Thu Sep 17 15:05:04.086030 2026] [security2:error] [pid 955873:tid 956095] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/qa/.env"] [unique_id "aqxWABFTPRVSLOsRVhruvwAAAWY"]
[Thu Sep 17 15:05:04.134000 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:47030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiProvider.php"] [unique_id "aqxWABFTPRVSLOsRVhruwAAAAVA"]
[Thu Sep 17 15:05:04.134083 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:47030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiProvider.php"] [unique_id "aqxWABFTPRVSLOsRVhruwAAAAVA"]
[Thu Sep 17 15:05:04.177750 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhruwQAAARE"]
[Thu Sep 17 15:05:04.242378 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/preview/.env"] [unique_id "aqxWABFTPRVSLOsRVhruyQAAARI"]
[Thu Sep 17 15:05:04.254944 2026] [security2:error] [pid 955873:tid 956021] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/dist/.env"] [unique_id "aqxWABFTPRVSLOsRVhruygAAARw"]
[Thu Sep 17 15:05:04.284490 2026] [security2:error] [pid 955873:tid 956083] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/jquery/jquery.min.js"] [unique_id "aqxWABFTPRVSLOsRVhruzAAAAVo"]
[Thu Sep 17 15:05:04.395274 2026] [security2:error] [pid 955873:tid 956094] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/beta/.env"] [unique_id "aqxWABFTPRVSLOsRVhruzwAAAWU"]
[Thu Sep 17 15:05:04.438574 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:47038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/"] [unique_id "aqxWABFTPRVSLOsRVhru0AAAAVM"]
[Thu Sep 17 15:05:04.448873 2026] [security2:error] [pid 955873:tid 956024] [client 34.95.193.102:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/public/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhru0QAAAR8"]
[Thu Sep 17 15:05:04.483849 2026] [security2:error] [pid 955873:tid 956080] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "aqxWABFTPRVSLOsRVhru0wAAAVc"]
[Thu Sep 17 15:05:04.530853 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhru1QAAATQ"]
[Thu Sep 17 15:05:04.535979 2026] [security2:error] [pid 955873:tid 956089] [client 216.73.163.50:52373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWABFTPRVSLOsRVhru1AAAAWA"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:04.558861 2026] [security2:error] [pid 955873:tid 956087] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/uat/.env"] [unique_id "aqxWABFTPRVSLOsRVhru1gAAAV4"]
[Thu Sep 17 15:05:04.605990 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/"] [unique_id "aqxWABFTPRVSLOsRVhru1wAAAW4"]
[Thu Sep 17 15:05:04.715997 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "aqxWABFTPRVSLOsRVhru3AAAAYg"]
[Thu Sep 17 15:05:04.724079 2026] [security2:error] [pid 955873:tid 956119] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/stage/.env"] [unique_id "aqxWABFTPRVSLOsRVhru3QAAAX4"]
[Thu Sep 17 15:05:04.754336 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:47038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/"] [unique_id "aqxWABFTPRVSLOsRVhru3gAAAWw"]
[Thu Sep 17 15:05:04.844859 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhru3wAAAS0"]
[Thu Sep 17 15:05:04.894200 2026] [security2:error] [pid 955873:tid 956012] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/development/.env"] [unique_id "aqxWABFTPRVSLOsRVhru4AAAARM"]
[Thu Sep 17 15:05:04.946187 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "aqxWABFTPRVSLOsRVhru5AAAAXk"]
[Thu Sep 17 15:05:05.049513 2026] [security2:error] [pid 955873:tid 956093] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/production/.env"] [unique_id "aqxWARFTPRVSLOsRVhru5gAAAWQ"]
[Thu Sep 17 15:05:05.087297 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWABFTPRVSLOsRVhru4QAAAW8"]
[Thu Sep 17 15:05:05.087314 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWABFTPRVSLOsRVhru4QAAAW8"]
[Thu Sep 17 15:05:05.091079 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.224.217:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWARFTPRVSLOsRVhru5wAAATU"]
[Thu Sep 17 15:05:05.173939 2026] [security2:error] [pid 955873:tid 956128] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "aqxWARFTPRVSLOsRVhru6AAAAYc"]
[Thu Sep 17 15:05:05.203310 2026] [security2:error] [pid 955873:tid 956112] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/config/app/.env"] [unique_id "aqxWARFTPRVSLOsRVhru6wAAAXc"]
[Thu Sep 17 15:05:05.209309 2026] [security2:error] [pid 955873:tid 956111] [client 34.95.193.102:40044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/php-info.php"] [unique_id "aqxWARFTPRVSLOsRVhru7AAAAXY"]
[Thu Sep 17 15:05:05.224491 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:47038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/ApiBasedModelInterface.php"] [unique_id "aqxWARFTPRVSLOsRVhru7wAAASk"]
[Thu Sep 17 15:05:05.224556 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:47038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/ApiBasedModelInterface.php"] [unique_id "aqxWARFTPRVSLOsRVhru7wAAASk"]
[Thu Sep 17 15:05:05.359122 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php"] [unique_id "aqxWARFTPRVSLOsRVhru8AAAATY"]
[Thu Sep 17 15:05:05.401727 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/live/.env"] [unique_id "aqxWARFTPRVSLOsRVhru8gAAAUo"]
[Thu Sep 17 15:05:05.447075 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.224.217:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWARFTPRVSLOsRVhru9AAAASw"]
[Thu Sep 17 15:05:05.528823 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/GenerateTextApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru9gAAAXA"]
[Thu Sep 17 15:05:05.528902 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/GenerateTextApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru9gAAAXA"]
[Thu Sep 17 15:05:05.629864 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "aqxWARFTPRVSLOsRVhru9wAAAV8"]
[Thu Sep 17 15:05:05.701399 2026] [security2:error] [pid 955873:tid 956049] [client 34.95.193.102:40060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpversion.php"] [unique_id "aqxWARFTPRVSLOsRVhru-gAAATg"]
[Thu Sep 17 15:05:05.799408 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxWARFTPRVSLOsRVhru_AAAAVI"]
[Thu Sep 17 15:05:05.838742 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/ListModelsApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru_QAAAR0"]
[Thu Sep 17 15:05:05.838839 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:47062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/ListModelsApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru_QAAAR0"]
[Thu Sep 17 15:05:05.848221 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/info.php"] [unique_id "aqxWARFTPRVSLOsRVhru_gAAAYA"]
[Thu Sep 17 15:05:05.862420 2026] [security2:error] [pid 955873:tid 956106] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "aqxWARFTPRVSLOsRVhru_wAAAXE"]
[Thu Sep 17 15:05:06.090280 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvAwAAASs"]
[Thu Sep 17 15:05:06.114049 2026] [security2:error] [pid 955873:tid 956116] [client 110.226.207.129:36024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvAQABeys"]
[Thu Sep 17 15:05:06.126073 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:42736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php.old"] [unique_id "aqxWAhFTPRVSLOsRVhrvBQAAASM"]
[Thu Sep 17 15:05:06.126094 2026] [security2:error] [pid 955873:tid 956107] [client 216.73.163.43:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvBAAAAXI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:06.140523 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:47078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/"] [unique_id "aqxWAhFTPRVSLOsRVhrvBgAAAWY"]
[Thu Sep 17 15:05:06.188202 2026] [security2:error] [pid 955873:tid 956031] [client 34.95.193.102:40066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/_phpinfo.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvBwAAASY"]
[Thu Sep 17 15:05:06.295950 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/"] [unique_id "aqxWAhFTPRVSLOsRVhrvCwAAARE"]
[Thu Sep 17 15:05:06.322013 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/php.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvDAAAARg"]
[Thu Sep 17 15:05:06.322475 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/opt/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvDQAAAX0"]
[Thu Sep 17 15:05:06.413964 2026] [security2:error] [pid 955873:tid 956015] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/link-prefetch.min.js"] [unique_id "aqxWAhFTPRVSLOsRVhrvEAAAARY"]
[Thu Sep 17 15:05:06.437676 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWAhFTPRVSLOsRVhrvEQAAAVo"]
[Thu Sep 17 15:05:06.474946 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.224.217:42740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php~"] [unique_id "aqxWAhFTPRVSLOsRVhrvEgAAARI"]
[Thu Sep 17 15:05:06.551625 2026] [security2:error] [pid 955873:tid 956125] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvFQAAAYQ"]
[Thu Sep 17 15:05:06.707056 2026] [security2:error] [pid 955873:tid 956094] [client 34.95.193.102:40078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/old_phpinfo.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvHAAAAWU"]
[Thu Sep 17 15:05:06.759952 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvFgAAAVM"]
[Thu Sep 17 15:05:06.759973 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvFgAAAVM"]
[Thu Sep 17 15:05:06.791637 2026] [security2:error] [pid 955873:tid 956099] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvHgAAAWo"]
[Thu Sep 17 15:05:06.800636 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.219.249:56878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/i.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvHwAAAVE"]
[Thu Sep 17 15:05:06.899927 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ModelMetadataDirectoryInterface.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvIQAAAS0"]
[Thu Sep 17 15:05:06.900059 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ModelMetadataDirectoryInterface.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvIQAAAS0"]
[Thu Sep 17 15:05:06.953580 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/info.php.bak"] [unique_id "aqxWAhFTPRVSLOsRVhrvJQAAAT8"]
[Thu Sep 17 15:05:07.194412 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:47080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderAvailabilityInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvKwAAAW8"]
[Thu Sep 17 15:05:07.194493 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:47080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderAvailabilityInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvKwAAAW8"]
[Thu Sep 17 15:05:07.197366 2026] [security2:error] [pid 955873:tid 956130] [client 34.95.193.102:40094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/server-info.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvLAAAAYk"]
[Thu Sep 17 15:05:07.210400 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php.save"] [unique_id "aqxWAxFTPRVSLOsRVhrvLgAAAYI"]
[Thu Sep 17 15:05:07.274176 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.219.249:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/pi.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvLwAAAR4"]
[Thu Sep 17 15:05:07.488037 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMwAAAQs"]
[Thu Sep 17 15:05:07.488141 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMwAAAQs"]
[Thu Sep 17 15:05:07.497602 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:42772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvNAAAATI"]
[Thu Sep 17 15:05:07.506187 2026] [security2:error] [pid 955873:tid 956128] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "aqxWAxFTPRVSLOsRVhrvNQAAAYc"]
[Thu Sep 17 15:05:07.696572 2026] [security2:error] [pid 955873:tid 956072] [client 34.95.193.102:40106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/server-status.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvOQAAAU8"]
[Thu Sep 17 15:05:07.749464 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:56890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/pinfo.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvOwAAASE"]
[Thu Sep 17 15:05:07.759961 2026] [security2:error] [pid 955873:tid 956068] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "aqxWAxFTPRVSLOsRVhrvPAAAAUs"]
[Thu Sep 17 15:05:07.776529 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderOperationsHandlerInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPQAAAXA"]
[Thu Sep 17 15:05:07.776605 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderOperationsHandlerInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPQAAAXA"]
[Thu Sep 17 15:05:07.798382 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:42780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPgAAAXg"]
[Thu Sep 17 15:05:07.995139 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "aqxWAxFTPRVSLOsRVhrvQAAAASQ"]
[Thu Sep 17 15:05:08.009445 2026] [security2:error] [pid 955873:tid 956022] [client 159.146.33.234:3450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPwABHTg"]
[Thu Sep 17 15:05:08.020967 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvQQAAAUA"]
[Thu Sep 17 15:05:08.062386 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:47116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderWithOperationsHandlerInterface.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvQgAAATs"]
[Thu Sep 17 15:05:08.062465 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:47116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderWithOperationsHandlerInterface.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvQgAAATs"]
[Thu Sep 17 15:05:08.230607 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/drupal/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrvRwAAASs"]
[Thu Sep 17 15:05:08.231150 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.219.249:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/test.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvSAAAATM"]
[Thu Sep 17 15:05:08.323329 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvTQAAAW0"]
[Thu Sep 17 15:05:08.358241 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:47118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/"] [unique_id "aqxWBBFTPRVSLOsRVhrvUQAAATE"]
[Thu Sep 17 15:05:08.418989 2026] [security2:error] [pid 955873:tid 956118] [client 216.24.219.38:42627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/000.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvUwAAAX0"]
[Thu Sep 17 15:05:08.464873 2026] [security2:error] [pid 955873:tid 956021] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/joomla/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrvVgAAARw"]
[Thu Sep 17 15:05:08.476543 2026] [security2:error] [pid 955873:tid 956109] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/Total-Soft-Calendar/CSS/Total-Soft-Calendar-Widget.css"] [unique_id "aqxWBBFTPRVSLOsRVhrvVwAAAXQ"]
[Thu Sep 17 15:05:08.510343 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/"] [unique_id "aqxWBBFTPRVSLOsRVhrvWQAAARY"]
[Thu Sep 17 15:05:08.515099 2026] [security2:error] [pid 955873:tid 956006] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "bajansoaps.com"] [uri "/index.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMgAAAQ0"]
[Thu Sep 17 15:05:08.515125 2026] [security2:error] [pid 955873:tid 956006] [client 74.7.175.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bajansoaps.com"] [uri "/index.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMgAAAQ0"]
[Thu Sep 17 15:05:08.517573 2026] [security2:error] [pid 955873:tid 956112] [client 74.7.175.191:32940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "bajansoaps.com"] [uri "/robots.txt"] [unique_id "aqxWAxFTPRVSLOsRVhrvMAABdzY"]
[Thu Sep 17 15:05:08.546100 2026] [security2:error] [pid 955873:tid 956054] [client 208.109.3.11:55984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bluetech.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvTgAAAXs"]
[Thu Sep 17 15:05:08.652195 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:47118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWBBFTPRVSLOsRVhrvWwAAAWU"]
[Thu Sep 17 15:05:08.664695 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvXAAAATQ"]
[Thu Sep 17 15:05:08.669570 2026] [security2:error] [pid 955873:tid 956099] [client 193.36.224.113:54553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/about.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvXgAAAWo"]
[Thu Sep 17 15:05:08.672313 2026] [security2:error] [pid 955873:tid 956074] [client 34.95.193.102:40120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWBBFTPRVSLOsRVhrvYAAAAVE"]
[Thu Sep 17 15:05:08.695248 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/magento/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrvaQAAAYg"]
[Thu Sep 17 15:05:08.863411 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdAAAAWk"]
[Thu Sep 17 15:05:08.863576 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:41908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdAAAAWk"]
[Thu Sep 17 15:05:08.870444 2026] [security2:error] [pid 955873:tid 956009] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bajansoaps.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvcgAAARA"], referer: https://bajansoaps.com/robots.txt
[Thu Sep 17 15:05:08.873082 2026] [security2:error] [pid 955873:tid 956119] [client 74.7.175.191:32952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bajansoaps.com"] [uri "/robots.txt"] [unique_id "aqxWBBFTPRVSLOsRVhrvbgABfkU"], referer: https://bajansoaps.com/robots.txt
[Thu Sep 17 15:05:08.891910 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:42820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/www/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdQAAAW8"]
[Thu Sep 17 15:05:08.908701 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.219.249:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/p.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdgAAAX8"]
[Thu Sep 17 15:05:08.918802 2026] [security2:error] [pid 955873:tid 956034] [client 193.36.224.148:37877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdwAAASk"]
[Thu Sep 17 15:05:08.925116 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/shopify/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrveAAAARo"]
[Thu Sep 17 15:05:08.964789 2026] [security2:error] [pid 955873:tid 956046] [client 20.244.34.24:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxWBBFTPRVSLOsRVhrveQAAATU"], referer: binance.com
[Thu Sep 17 15:05:08.974600 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvcAAAAQ4"]
[Thu Sep 17 15:05:08.974623 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvcAAAAQ4"]
[Thu Sep 17 15:05:09.005523 2026] [security2:error] [pid 955873:tid 956126] [client 186.105.232.15:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvegAAAYU"]
[Thu Sep 17 15:05:09.005619 2026] [security2:error] [pid 955873:tid 956126] [client 186.105.232.15:63317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvegAAAYU"]
[Thu Sep 17 15:05:09.126871 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvfAAAAXU"]
[Thu Sep 17 15:05:09.126954 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:47118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvfAAAAXU"]
[Thu Sep 17 15:05:09.155771 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/prestashop/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrvfQAAATI"]
[Thu Sep 17 15:05:09.166058 2026] [security2:error] [pid 955873:tid 956047] [client 34.95.193.102:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/mail/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvfgAAATY"]
[Thu Sep 17 15:05:09.269085 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.224.217:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvgQAAASo"]
[Thu Sep 17 15:05:09.386547 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/codeigniter/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrvgwAAAVQ"]
[Thu Sep 17 15:05:09.387686 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/debug.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhAAAASE"]
[Thu Sep 17 15:05:09.407420 2026] [security2:error] [pid 955873:tid 956061] [client 193.36.224.113:56739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/about.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhQAAAUQ"]
[Thu Sep 17 15:05:09.417378 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:47124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderModelsMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhgAAAV8"]
[Thu Sep 17 15:05:09.417484 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:47124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderModelsMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhgAAAV8"]
[Thu Sep 17 15:05:09.563760 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.224.217:42840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrviAAAARc"]
[Thu Sep 17 15:05:09.625387 2026] [security2:error] [pid 955873:tid 956091] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cakephp/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrviQAAAWI"]
[Thu Sep 17 15:05:09.658470 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvjAAAAS4"]
[Thu Sep 17 15:05:09.658642 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvjAAAAS4"]
[Thu Sep 17 15:05:09.671310 2026] [security2:error] [pid 955873:tid 956082] [client 216.24.219.104:42489] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvkAAAAVk"]
[Thu Sep 17 15:05:09.677389 2026] [security2:error] [pid 955873:tid 956075] [client 34.95.193.102:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvkQAAAVI"]
[Thu Sep 17 15:05:09.703450 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:47128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/"] [unique_id "aqxWBRFTPRVSLOsRVhrvkwAAATM"]
[Thu Sep 17 15:05:09.722136 2026] [security2:error] [pid 955873:tid 956005] [client 40.77.167.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.breathingboxing.org"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruNgAAAQw"]
[Thu Sep 17 15:05:09.821574 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/site/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvlQAAATg"]
[Thu Sep 17 15:05:09.855638 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/zend/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrvlwAAARg"]
[Thu Sep 17 15:05:09.869121 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/"] [unique_id "aqxWBRFTPRVSLOsRVhrvlgAAARs"]
[Thu Sep 17 15:05:09.873196 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvmAAAASM"]
[Thu Sep 17 15:05:09.915160 2026] [security2:error] [pid 955873:tid 956118] [client 193.36.224.169:21963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-includes/hp2.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvmQAAAX0"]
[Thu Sep 17 15:05:10.030865 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:47128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWBhFTPRVSLOsRVhrvnQAAAUU"]
[Thu Sep 17 15:05:10.087882 2026] [security2:error] [pid 955873:tid 956006] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/yii/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvoAAAAQ0"]
[Thu Sep 17 15:05:10.122677 2026] [security2:error] [pid 955873:tid 956108] [client 216.73.163.55:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvnwAAAXM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:10.131906 2026] [security2:error] [pid 955873:tid 956069] [client 34.23.224.217:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvogAAAUw"]
[Thu Sep 17 15:05:10.174051 2026] [security2:error] [pid 955873:tid 956033] [client 34.95.193.102:40152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvpQAAASg"]
[Thu Sep 17 15:05:10.299161 2026] [security2:error] [pid 955873:tid 956073] [client 115.244.164.14:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvqQAAAVA"]
[Thu Sep 17 15:05:10.299262 2026] [security2:error] [pid 955873:tid 956073] [client 115.244.164.14:59970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvqQAAAVA"]
[Thu Sep 17 15:05:10.318803 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/laravel5/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvqgAAAUE"]
[Thu Sep 17 15:05:10.350970 2026] [security2:error] [pid 955873:tid 956076] [client 34.154.219.249:39338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvqwAAAVM"]
[Thu Sep 17 15:05:10.351775 2026] [security2:error] [pid 955873:tid 956048] [client 193.36.224.149:50437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/bless.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvrAAAATc"]
[Thu Sep 17 15:05:10.359179 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvowAAAV4"]
[Thu Sep 17 15:05:10.359199 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvowAAAV4"]
[Thu Sep 17 15:05:10.428128 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:42862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvsgAAAWA"]
[Thu Sep 17 15:05:10.501608 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ProviderTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvtgAAAYU"]
[Thu Sep 17 15:05:10.501705 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ProviderTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvtgAAAYU"]
[Thu Sep 17 15:05:10.539124 2026] [security2:error] [pid 955873:tid 956050] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/classie.min.js"] [unique_id "aqxWBhFTPRVSLOsRVhrvtwAAATk"]
[Thu Sep 17 15:05:10.550029 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvuAAAAQs"]
[Thu Sep 17 15:05:10.583970 2026] [security2:error] [pid 955873:tid 956047] [client 193.36.224.167:46673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/goods.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvuQAAATY"]
[Thu Sep 17 15:05:10.672020 2026] [security2:error] [pid 955873:tid 956115] [client 34.95.193.102:40154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvugAAAXo"]
[Thu Sep 17 15:05:10.778412 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.224.217:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvvgAAASc"]
[Thu Sep 17 15:05:10.781252 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvvwAAATo"]
[Thu Sep 17 15:05:10.783353 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:38416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ToolTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwAAAASw"]
[Thu Sep 17 15:05:10.783562 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:38416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ToolTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwAAAASw"]
[Thu Sep 17 15:05:10.853538 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:39348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwQAAASE"]
[Thu Sep 17 15:05:10.905438 2026] [security2:error] [pid 955873:tid 956106] [client 216.24.219.104:39637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/blurbs.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwgAAAXE"]
[Thu Sep 17 15:05:11.016362 2026] [security2:error] [pid 955873:tid 956057] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/v3/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrvwwAAAUA"]
[Thu Sep 17 15:05:11.070636 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWBxFTPRVSLOsRVhrvxQAAAVI"]
[Thu Sep 17 15:05:11.098046 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:39326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/core/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrvxwAAAUM"]
[Thu Sep 17 15:05:11.106206 2026] [access_compat:error] [pid 955873:tid 956036] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/travel-mosaics-16-glorious-budapest
[Thu Sep 17 15:05:11.147052 2026] [security2:error] [pid 955873:tid 956107] [client 216.24.219.32:36777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxWBxFTPRVSLOsRVhrvyQAAAXI"]
[Thu Sep 17 15:05:11.182996 2026] [security2:error] [pid 955873:tid 956039] [client 34.95.193.102:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrvzAAAAS4"]
[Thu Sep 17 15:05:11.248334 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/v1/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrvzgAAAW0"]
[Thu Sep 17 15:05:11.283083 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWBxFTPRVSLOsRVhrvzQAAAVU"]
[Thu Sep 17 15:05:11.331232 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.219.249:39362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv0AAAAS8"]
[Thu Sep 17 15:05:11.417025 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv0QAAATg"]
[Thu Sep 17 15:05:11.426154 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWBxFTPRVSLOsRVhrv0gAAASM"]
[Thu Sep 17 15:05:11.479564 2026] [security2:error] [pid 955873:tid 956085] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/v2/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrv1AAAAVw"]
[Thu Sep 17 15:05:11.600735 2026] [security2:error] [pid 955873:tid 956062] [client 193.36.224.219:32861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/abcd.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv1wAAAUU"]
[Thu Sep 17 15:05:11.632473 2026] [security2:error] [pid 955873:tid 956083] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.ncz.ihh.mybluehost.me"] [uri "/cgi-sys/404.html"] [unique_id "aqxWBxFTPRVSLOsRVhrv2QAAAVo"]
[Thu Sep 17 15:05:11.648251 2026] [security2:error] [pid 955873:tid 956109] [client 74.7.175.173:33612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.ncz.ihh.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWBxFTPRVSLOsRVhrv1gABdFA"]
[Thu Sep 17 15:05:11.667793 2026] [security2:error] [pid 955873:tid 956118] [client 34.95.193.102:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php.bak"] [unique_id "aqxWBxFTPRVSLOsRVhrv2gAAAX0"]
[Thu Sep 17 15:05:11.714539 2026] [security2:error] [pid 955873:tid 956095] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/rest/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrv3wAAAWY"]
[Thu Sep 17 15:05:11.744786 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv1QAAATs"]
[Thu Sep 17 15:05:11.744807 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv1QAAATs"]
[Thu Sep 17 15:05:11.818578 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.219.249:39368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv4wAAAXY"]
[Thu Sep 17 15:05:11.880990 2026] [security2:error] [pid 955873:tid 956045] [client 104.234.19.143:43675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv5AAAATQ"]
[Thu Sep 17 15:05:11.887747 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/"] [unique_id "aqxWBxFTPRVSLOsRVhrv5gAAAYg"]
[Thu Sep 17 15:05:11.947269 2026] [security2:error] [pid 955873:tid 956101] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/graphql/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrv6AAAAWw"]
[Thu Sep 17 15:05:12.045987 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/"] [unique_id "aqxWCBFTPRVSLOsRVhrv6gAAARI"]
[Thu Sep 17 15:05:12.150948 2026] [security2:error] [pid 955873:tid 956018] [client 34.95.193.102:40172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php.old"] [unique_id "aqxWCBFTPRVSLOsRVhrv8AAAARk"]
[Thu Sep 17 15:05:12.187322 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/gateway/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrv9QAAAWE"]
[Thu Sep 17 15:05:12.190465 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWCBFTPRVSLOsRVhrv9gAAAYk"]
[Thu Sep 17 15:05:12.291474 2026] [security2:error] [pid 955873:tid 956074] [client 192.178.6.4:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv-QAAAVE"]
[Thu Sep 17 15:05:12.292183 2026] [security2:error] [pid 955873:tid 956003] [client 34.154.219.249:39380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv-gAAAQo"]
[Thu Sep 17 15:05:12.433122 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/microservice/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrwAAAAAQ4"]
[Thu Sep 17 15:05:12.488121 2026] [security2:error] [pid 955873:tid 956008] [client 193.36.224.150:28791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/dex.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwAgAAAQ8"]
[Thu Sep 17 15:05:12.526642 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv_AAAARM"]
[Thu Sep 17 15:05:12.526676 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv_AAAARM"]
[Thu Sep 17 15:05:12.609185 2026] [security2:error] [pid 955873:tid 956122] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/demo1.min.js"] [unique_id "aqxWCBFTPRVSLOsRVhrwBAAAAYE"]
[Thu Sep 17 15:05:12.656638 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php~"] [unique_id "aqxWCBFTPRVSLOsRVhrwBwAAAWM"]
[Thu Sep 17 15:05:12.666187 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/service/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrwCAAAATY"]
[Thu Sep 17 15:05:12.683082 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/AbstractClientDiscoveryStrategy.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwCQAAAU8"]
[Thu Sep 17 15:05:12.683158 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/AbstractClientDiscoveryStrategy.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwCQAAAU8"]
[Thu Sep 17 15:05:12.836082 2026] [security2:error] [pid 955873:tid 956067] [client 216.24.219.103:35087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwEgAAAUo"]
[Thu Sep 17 15:05:12.909743 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/v3/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrwFAAAAVQ"]
[Thu Sep 17 15:05:12.959920 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:38440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/"] [unique_id "aqxWCBFTPRVSLOsRVhrwGAAAAXE"]
[Thu Sep 17 15:05:12.980682 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.219.249:39384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/php-info.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwGgAAAVI"]
[Thu Sep 17 15:05:13.142154 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/"] [unique_id "aqxWCRFTPRVSLOsRVhrwHQAAAS4"]
[Thu Sep 17 15:05:13.143672 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/dev/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwHgAAAW0"]
[Thu Sep 17 15:05:13.167129 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.193.102:40182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/info.php.bak"] [unique_id "aqxWCRFTPRVSLOsRVhrwHwAAAUM"]
[Thu Sep 17 15:05:13.167649 2026] [security2:error] [pid 955873:tid 956022] [client 216.24.219.97:20753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwIAAAAR0"]
[Thu Sep 17 15:05:13.324033 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:38440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWCRFTPRVSLOsRVhrwJAAAARs"]
[Thu Sep 17 15:05:13.376504 2026] [security2:error] [pid 955873:tid 956081] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/staging/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwJgAAAVg"]
[Thu Sep 17 15:05:13.443016 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:39398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpversion.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKQAAAU4"]
[Thu Sep 17 15:05:13.480586 2026] [security2:error] [pid 955873:tid 956083] [client 193.36.224.156:37887] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKwAAAVo"]
[Thu Sep 17 15:05:13.611849 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwLQAAATs"]
[Thu Sep 17 15:05:13.660817 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKgAAAWg"]
[Thu Sep 17 15:05:13.660844 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKgAAAWg"]
[Thu Sep 17 15:05:13.669950 2026] [security2:error] [pid 955873:tid 956116] [client 34.95.193.102:40194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php.save"] [unique_id "aqxWCRFTPRVSLOsRVhrwLgAAAXs"]
[Thu Sep 17 15:05:13.823650 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:38440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/HeadersCollection.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwMQAAAYg"]
[Thu Sep 17 15:05:13.823783 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:38440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/HeadersCollection.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwMQAAAYg"]
[Thu Sep 17 15:05:13.844586 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/lib/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwMgAAAWU"]
[Thu Sep 17 15:05:13.885628 2026] [security2:error] [pid 955873:tid 956031] [client 20.244.34.24:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwMwAAASY"], referer: binance.com
[Thu Sep 17 15:05:13.912483 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.219.249:39404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/_phpinfo.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwNgAAAXY"]
[Thu Sep 17 15:05:14.040775 2026] [security2:error] [pid 955873:tid 956018] [client 216.24.219.103:49323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwOgAAARk"]
[Thu Sep 17 15:05:14.076234 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/resources/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwOwAAAWE"]
[Thu Sep 17 15:05:14.106494 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:38448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/"] [unique_id "aqxWChFTPRVSLOsRVhrwPAAAAVE"]
[Thu Sep 17 15:05:14.173706 2026] [security2:error] [pid 955873:tid 956009] [client 34.95.193.102:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/staging/phpinfo.php"] [unique_id "aqxWChFTPRVSLOsRVhrwPgAAARA"]
[Thu Sep 17 15:05:14.266241 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/"] [unique_id "aqxWChFTPRVSLOsRVhrwQQAAAXM"]
[Thu Sep 17 15:05:14.329958 2026] [security2:error] [pid 955873:tid 956046] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/assets/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwQwAAATU"]
[Thu Sep 17 15:05:14.395075 2026] [security2:error] [pid 955873:tid 956104] [client 34.154.219.249:39410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWChFTPRVSLOsRVhrwRgAAAW8"]
[Thu Sep 17 15:05:14.423204 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:38448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWChFTPRVSLOsRVhrwRwAAAXU"]
[Thu Sep 17 15:05:14.527239 2026] [security2:error] [pid 955873:tid 956120] [client 216.73.163.40:32879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWChFTPRVSLOsRVhrwSQAAAX8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:14.567274 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/uploads/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwSwAAAXA"]
[Thu Sep 17 15:05:14.672377 2026] [security2:error] [pid 955873:tid 956032] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/totop.min.js"] [unique_id "aqxWChFTPRVSLOsRVhrwTAAAASc"]
[Thu Sep 17 15:05:14.673137 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.193.102:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/beta/phpinfo.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTQAAAV0"]
[Thu Sep 17 15:05:14.735575 2026] [security2:error] [pid 955873:tid 956051] [client 216.24.219.101:29579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTgAAATo"]
[Thu Sep 17 15:05:14.737626 2026] [security2:error] [pid 955873:tid 956124] [client 185.55.149.49:62500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTwAAAYM"]
[Thu Sep 17 15:05:14.737732 2026] [security2:error] [pid 955873:tid 956124] [client 185.55.149.49:62500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTwAAAYM"]
[Thu Sep 17 15:05:14.755728 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwSgAAASo"]
[Thu Sep 17 15:05:14.755747 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwSgAAASo"]
[Thu Sep 17 15:05:14.803266 2026] [security2:error] [pid 955873:tid 956063] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.hendersonlife.info"] [uri "/index.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv8QAAAUY"]
[Thu Sep 17 15:05:14.803647 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwVAAAAVQ"]
[Thu Sep 17 15:05:14.805148 2026] [security2:error] [pid 955873:tid 956055] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.hendersonlife.info"] [uri "/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwLAAAAT4"], referer: http://mail.hendersonlife.info/api/session/properties
[Thu Sep 17 15:05:14.876924 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.219.249:39422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/server-info.php"] [unique_id "aqxWChFTPRVSLOsRVhrwVgAAASw"]
[Thu Sep 17 15:05:14.921387 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/ClientWithOptionsInterface.php"] [unique_id "aqxWChFTPRVSLOsRVhrwVwAAASs"]
[Thu Sep 17 15:05:14.921505 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/ClientWithOptionsInterface.php"] [unique_id "aqxWChFTPRVSLOsRVhrwVwAAASs"]
[Thu Sep 17 15:05:15.037365 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/tools/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwWAAAAUI"]
[Thu Sep 17 15:05:15.139058 2026] [security2:error] [pid 955873:tid 956030] [client 216.24.219.103:51063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwWQAAASU"]
[Thu Sep 17 15:05:15.170182 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.193.102:50748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/uat/phpinfo.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwWwAAAWs"]
[Thu Sep 17 15:05:15.182806 2026] [security2:error] [pid 955873:tid 956053] [client 216.73.163.62:48143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwWgAAATw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:15.198403 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/HttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwXAAAAQw"]
[Thu Sep 17 15:05:15.198499 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:38454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/HttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwXAAAAQw"]
[Thu Sep 17 15:05:15.267463 2026] [security2:error] [pid 955873:tid 956081] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/scripts/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwYAAAAVg"]
[Thu Sep 17 15:05:15.368437 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:39438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/server-status.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYQAAAVU"]
[Thu Sep 17 15:05:15.418488 2026] [security2:error] [pid 955873:tid 956028] [client 216.24.219.102:24413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/file.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYgAAASM"]
[Thu Sep 17 15:05:15.479569 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:38458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/RequestAuthenticationInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYwAAAS8"]
[Thu Sep 17 15:05:15.479673 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:38458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/RequestAuthenticationInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYwAAAS8"]
[Thu Sep 17 15:05:15.499336 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/bin/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwZAAAAX0"]
[Thu Sep 17 15:05:15.653902 2026] [security2:error] [pid 955873:tid 956117] [client 34.95.193.102:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/qa/phpinfo.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwZQAAAXw"]
[Thu Sep 17 15:05:15.731413 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sbin/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwZwAAAXs"]
[Thu Sep 17 15:05:15.760081 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithHttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwagAAAUk"]
[Thu Sep 17 15:05:15.760176 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithHttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwagAAAUk"]
[Thu Sep 17 15:05:15.909568 2026] [security2:error] [pid 955873:tid 956056] [client 216.73.163.36:48715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwbgAAAT8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:15.963866 2026] [security2:error] [pid 955873:tid 956018] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwcgAAARk"]
[Thu Sep 17 15:05:16.078510 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:38474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithRequestAuthenticationInterface.php"] [unique_id "aqxWDBFTPRVSLOsRVhrweQAAASg"]
[Thu Sep 17 15:05:16.078653 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:38474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithRequestAuthenticationInterface.php"] [unique_id "aqxWDBFTPRVSLOsRVhrweQAAASg"]
[Thu Sep 17 15:05:16.162742 2026] [security2:error] [pid 955873:tid 956025] [client 34.95.193.102:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/preview/phpinfo.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwegAAASA"]
[Thu Sep 17 15:05:16.198039 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwewAAAUc"]
[Thu Sep 17 15:05:16.227794 2026] [security2:error] [pid 955873:tid 956009] [client 49.13.167.123:36836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.geekngamer.com"] [uri "/index.html"] [unique_id "aqxWDBFTPRVSLOsRVhrwfAAAARA"], referer: http://www.geekngamer.com
[Thu Sep 17 15:05:16.252275 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.219.249:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWDBFTPRVSLOsRVhrwfwAAAQ4"]
[Thu Sep 17 15:05:16.374424 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:38476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/"] [unique_id "aqxWDBFTPRVSLOsRVhrwggAAAR8"]
[Thu Sep 17 15:05:16.432950 2026] [security2:error] [pid 955873:tid 956110] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/dashboard/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwgwAAAXU"]
[Thu Sep 17 15:05:16.488702 2026] [security2:error] [pid 955873:tid 956112] [client 65.111.15.248:19041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.enduringwanderlust.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrweAAAAXc"]
[Thu Sep 17 15:05:16.542779 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/"] [unique_id "aqxWDBFTPRVSLOsRVhrwhgAAAU0"]
[Thu Sep 17 15:05:16.662311 2026] [security2:error] [pid 955873:tid 956128] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/panel/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwigAAAYc"]
[Thu Sep 17 15:05:16.688809 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:38476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWDBFTPRVSLOsRVhrwiwAAAU8"]
[Thu Sep 17 15:05:16.728076 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.219.249:39452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwjgAAAXk"]
[Thu Sep 17 15:05:16.733992 2026] [security2:error] [pid 955873:tid 956088] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/trigger.min.js"] [unique_id "aqxWDBFTPRVSLOsRVhrwkAAAAV8"]
[Thu Sep 17 15:05:16.791774 2026] [security2:error] [pid 955873:tid 956080] [client 20.244.34.24:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwlwAAAVc"], referer: binance.com
[Thu Sep 17 15:05:16.836734 2026] [security2:error] [pid 955873:tid 956087] [client 66.249.66.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grieveonpurpose.com"] [uri "/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwRAAAAV4"]
[Thu Sep 17 15:05:16.841912 2026] [security2:error] [pid 955873:tid 956061] [client 193.36.224.168:28343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwmgAAAUQ"]
[Thu Sep 17 15:05:16.892309 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwmwAAAVk"]
[Thu Sep 17 15:05:16.962497 2026] [security2:error] [pid 955873:tid 956016] [client 34.95.193.102:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/www/phpinfo.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwnAAAARc"]
[Thu Sep 17 15:05:16.965291 2026] [security2:error] [pid 955873:tid 956062] [client 85.208.98.197:44667] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/comment-reply.min.js"] [unique_id "aqxWDBFTPRVSLOsRVhrwnQAAAUU"]
[Thu Sep 17 15:05:17.037004 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwmQAAAWI"]
[Thu Sep 17 15:05:17.037029 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwmQAAAWI"]
[Thu Sep 17 15:05:17.124556 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/erp/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwoAAAAS4"]
[Thu Sep 17 15:05:17.171762 2026] [security2:error] [pid 955873:tid 956107] [client 45.190.220.230:12947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwngABcmM"]
[Thu Sep 17 15:05:17.175648 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/ApiKeyRequestAuthentication.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwoQAAAUo"]
[Thu Sep 17 15:05:17.175781 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:38476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/ApiKeyRequestAuthentication.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwoQAAAUo"]
[Thu Sep 17 15:05:17.197551 2026] [security2:error] [pid 955873:tid 956084] [client 216.24.219.103:40327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-mail.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwogAAAVs"]
[Thu Sep 17 15:05:17.226296 2026] [security2:error] [pid 955873:tid 956041] [client 34.154.219.249:39468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwowAAATA"]
[Thu Sep 17 15:05:17.364375 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/shop/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwqAAAAW4"]
[Thu Sep 17 15:05:17.457141 2026] [security2:error] [pid 955873:tid 956030] [client 34.95.193.102:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwqQAAASU"]
[Thu Sep 17 15:05:17.458344 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:38478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Request.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwqgAAASM"]
[Thu Sep 17 15:05:17.458430 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:38478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Request.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwqgAAASM"]
[Thu Sep 17 15:05:17.597109 2026] [security2:error] [pid 955873:tid 956125] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/store/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwrAAAAYQ"]
[Thu Sep 17 15:05:17.704775 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.219.249:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrQAAAXQ"]
[Thu Sep 17 15:05:17.727889 2026] [security2:error] [pid 955873:tid 956066] [client 216.24.219.104:42769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/ioxi-o.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrgAAAUk"]
[Thu Sep 17 15:05:17.736414 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/RequestOptions.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrwAAAVA"]
[Thu Sep 17 15:05:17.736492 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:38480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/RequestOptions.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrwAAAVA"]
[Thu Sep 17 15:05:17.830723 2026] [security2:error] [pid 955873:tid 956018] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/saas/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwtAAAARk"]
[Thu Sep 17 15:05:17.934111 2026] [security2:error] [pid 955873:tid 956085] [client 45.146.54.106:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwtQAAAVw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:17.955813 2026] [security2:error] [pid 955873:tid 956056] [client 34.95.193.102:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwtgAAAT8"]
[Thu Sep 17 15:05:17.974300 2026] [security2:error] [pid 955873:tid 956033] [client 216.24.219.36:25473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwtwAAASg"]
[Thu Sep 17 15:05:18.018247 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:38482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Response.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuAAAAT0"]
[Thu Sep 17 15:05:18.018328 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:38482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Response.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuAAAAT0"]
[Thu Sep 17 15:05:18.045978 2026] [security2:error] [pid 955873:tid 956130] [client 162.241.226.11:20026] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "reedcustomprinting.com"] [uri "/wp-cron.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuQAAAYk"]
[Thu Sep 17 15:05:18.051801 2026] [security2:error] [pid 955873:tid 956106] [client 4.240.114.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwlQAAAXE"], referer: binance.com
[Thu Sep 17 15:05:18.066242 2026] [security2:error] [pid 955873:tid 956074] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/client/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwugAAAVE"]
[Thu Sep 17 15:05:18.124523 2026] [security2:error] [pid 955873:tid 956044] [client 194.163.128.162:49844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuwAAATM"], referer: binance.com
[Thu Sep 17 15:05:18.191523 2026] [security2:error] [pid 955873:tid 956079] [client 34.154.219.249:39500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwvAAAAVY"]
[Thu Sep 17 15:05:18.304933 2026] [security2:error] [pid 955873:tid 956096] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwwAAAAWc"]
[Thu Sep 17 15:05:18.313874 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:38496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/"] [unique_id "aqxWDhFTPRVSLOsRVhrwwQAAASI"]
[Thu Sep 17 15:05:18.472954 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/site/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwxAAAAQ8"]
[Thu Sep 17 15:05:18.478837 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/"] [unique_id "aqxWDhFTPRVSLOsRVhrwwwAAAW8"]
[Thu Sep 17 15:05:18.533280 2026] [security2:error] [pid 955873:tid 956127] [client 216.24.219.88:27027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/style.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwxQAAAYY"]
[Thu Sep 17 15:05:18.543411 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/admin-panel/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwxgAAAXc"]
[Thu Sep 17 15:05:18.622086 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:38496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWDhFTPRVSLOsRVhrwyAAAARI"]
[Thu Sep 17 15:05:18.651087 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.219.249:39512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwyQAAAYE"]
[Thu Sep 17 15:05:18.778580 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/control-panel/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwzQAAATY"]
[Thu Sep 17 15:05:18.800049 2026] [security2:error] [pid 955873:tid 956128] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/modernizr.custom.min.js"] [unique_id "aqxWDhFTPRVSLOsRVhrwzgAAAYc"]
[Thu Sep 17 15:05:18.872193 2026] [security2:error] [pid 955873:tid 956086] [client 193.36.224.226:34873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/style.php"] [unique_id "aqxWDhFTPRVSLOsRVhrw0AAAAV0"]
[Thu Sep 17 15:05:18.951952 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwzAAAAWA"]
[Thu Sep 17 15:05:18.951974 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwzAAAAWA"]
[Thu Sep 17 15:05:18.983326 2026] [security2:error] [pid 955873:tid 956115] [client 34.95.193.102:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/docs/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrw0QAAAXo"]
[Thu Sep 17 15:05:19.013671 2026] [security2:error] [pid 955873:tid 956080] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/user-panel/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw1AAAAVc"]
[Thu Sep 17 15:05:19.039922 2026] [security2:error] [pid 955873:tid 956068] [client 85.208.98.197:44667] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/akismet/_inc/akismet-frontend.js"] [unique_id "aqxWDxFTPRVSLOsRVhrw1QAAAUs"]
[Thu Sep 17 15:05:19.100377 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/HttpMethodEnum.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw1wAAATE"]
[Thu Sep 17 15:05:19.100482 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/HttpMethodEnum.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw1wAAATE"]
[Thu Sep 17 15:05:19.144463 2026] [security2:error] [pid 955873:tid 956051] [client 34.154.219.249:39524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWDxFTPRVSLOsRVhrw2AAAATo"]
[Thu Sep 17 15:05:19.249822 2026] [security2:error] [pid 955873:tid 956062] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/node/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw3QAAAUU"]
[Thu Sep 17 15:05:19.351604 2026] [security2:error] [pid 955873:tid 956102] [client 146.190.145.25:56998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "greenbrickbuilders.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWDxFTPRVSLOsRVhrw3wAAAW0"]
[Thu Sep 17 15:05:19.405887 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:38498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/RequestAuthenticationMethod.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4AAAAXI"]
[Thu Sep 17 15:05:19.405980 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:38498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/RequestAuthenticationMethod.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4AAAAXI"]
[Thu Sep 17 15:05:19.413236 2026] [security2:error] [pid 955873:tid 956084] [client 104.234.19.146:64915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/themes/style.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4QAAAVs"]
[Thu Sep 17 15:05:19.452164 2026] [security2:error] [pid 955873:tid 956063] [client 146.190.145.25:57004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "greenbrickbuilders.com"] [uri "/"] [unique_id "aqxWDxFTPRVSLOsRVhrw4gAAAUY"]
[Thu Sep 17 15:05:19.471647 2026] [security2:error] [pid 955873:tid 956039] [client 34.95.193.102:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4wAAAS4"]
[Thu Sep 17 15:05:19.481598 2026] [security2:error] [pid 955873:tid 956032] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/express/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw5AAAASc"]
[Thu Sep 17 15:05:19.551007 2026] [security2:error] [pid 955873:tid 956103] [client 146.190.145.25:57014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "greenbrickbuilders.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWDxFTPRVSLOsRVhrw5QAAAW4"]
[Thu Sep 17 15:05:19.627050 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.219.249:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWDxFTPRVSLOsRVhrw6AAAAQw"]
[Thu Sep 17 15:05:19.680277 2026] [security2:error] [pid 955873:tid 956060] [client 216.24.219.20:35539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-editor.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw6gAAAUM"]
[Thu Sep 17 15:05:19.687967 2026] [security2:error] [pid 955873:tid 956113] [client 154.190.208.131:42481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw6wAAAXg"]
[Thu Sep 17 15:05:19.688068 2026] [security2:error] [pid 955873:tid 956113] [client 154.190.208.131:42481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw6wAAAXg"]
[Thu Sep 17 15:05:19.693567 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:38500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/"] [unique_id "aqxWDxFTPRVSLOsRVhrw7AAAAQ0"]
[Thu Sep 17 15:05:19.716247 2026] [security2:error] [pid 955873:tid 956026] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/next/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw7QAAASE"]
[Thu Sep 17 15:05:19.858017 2026] [security2:error] [pid 955873:tid 956118] [client 14.186.236.226:64111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw8AABfW4"]
[Thu Sep 17 15:05:19.867306 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/"] [unique_id "aqxWDxFTPRVSLOsRVhrw8gAAATs"]
[Thu Sep 17 15:05:19.913033 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw8wAAAU4"]
[Thu Sep 17 15:05:19.913128 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:63905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw8wAAAU4"]
[Thu Sep 17 15:05:19.951710 2026] [security2:error] [pid 955873:tid 956109] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/nuxt/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw9AAAAXQ"]
[Thu Sep 17 15:05:19.955301 2026] [security2:error] [pid 955873:tid 956125] [client 34.95.193.102:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw9QAAAYQ"]
[Thu Sep 17 15:05:20.013140 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:38500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWEBFTPRVSLOsRVhrw9gAAASQ"]
[Thu Sep 17 15:05:20.114419 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php~"] [unique_id "aqxWEBFTPRVSLOsRVhrw9wAAAUw"]
[Thu Sep 17 15:05:20.116492 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-AAAAUk"]
[Thu Sep 17 15:05:20.116572 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:51559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-AAAAUk"]
[Thu Sep 17 15:05:20.162214 2026] [security2:error] [pid 955873:tid 956056] [client 216.24.219.20:57117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/lufix.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-gAAAT8"]
[Thu Sep 17 15:05:20.185725 2026] [security2:error] [pid 955873:tid 956097] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/nest/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrw-wAAAWg"]
[Thu Sep 17 15:05:20.338287 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-QAAAVw"]
[Thu Sep 17 15:05:20.338310 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-QAAAVw"]
[Thu Sep 17 15:05:20.369161 2026] [security2:error] [pid 955873:tid 956031] [client 216.73.163.57:39229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw_wAAASY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:20.417674 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/react/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrxAAAAAT4"]
[Thu Sep 17 15:05:20.444179 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/core/phpinfo.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxAwAAAXE"]
[Thu Sep 17 15:05:20.481074 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:38500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ClientException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxBAAAAUc"]
[Thu Sep 17 15:05:20.481156 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:38500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ClientException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxBAAAAUc"]
[Thu Sep 17 15:05:20.606190 2026] [security2:error] [pid 955873:tid 956003] [client 34.154.219.249:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/info.php.bak"] [unique_id "aqxWEBFTPRVSLOsRVhrxBgAAAQo"]
[Thu Sep 17 15:05:20.657617 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/vue/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrxBwAAAR8"]
[Thu Sep 17 15:05:20.718654 2026] [security2:error] [pid 955873:tid 956110] [client 162.241.226.11:43422] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxCQAAAXU"]
[Thu Sep 17 15:05:20.757446 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/NetworkException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxCgAAAYY"]
[Thu Sep 17 15:05:20.757534 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/NetworkException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxCgAAAYY"]
[Thu Sep 17 15:05:20.821124 2026] [security2:error] [pid 955873:tid 956012] [client 115.244.164.14:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxDgAAARM"]
[Thu Sep 17 15:05:20.824868 2026] [security2:error] [pid 955873:tid 956012] [client 115.244.164.14:60630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxDgAAARM"]
[Thu Sep 17 15:05:20.862567 2026] [security2:error] [pid 955873:tid 956046] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/responsive-menu.min.js"] [unique_id "aqxWEBFTPRVSLOsRVhrxEAAAATU"]
[Thu Sep 17 15:05:20.895553 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/angular/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrxEgAAAQs"]
[Thu Sep 17 15:05:20.918436 2026] [security2:error] [pid 955873:tid 956128] [client 216.24.219.21:27637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/txets.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxEwAAAYc"]
[Thu Sep 17 15:05:20.956671 2026] [security2:error] [pid 955873:tid 956122] [client 40.77.167.93:7810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.chriswestlake.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxEQABgXU"]
[Thu Sep 17 15:05:20.960527 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/includes/phpinfo.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxFAAAASk"]
[Thu Sep 17 15:05:21.039843 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/RedirectException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxFQAAAS0"]
[Thu Sep 17 15:05:21.039955 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/RedirectException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxFQAAAS0"]
[Thu Sep 17 15:05:21.101353 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.219.249:56310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWERFTPRVSLOsRVhrxFgAAAWA"]
[Thu Sep 17 15:05:21.128521 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/svelte/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxGAAAATE"]
[Thu Sep 17 15:05:21.296601 2026] [security2:error] [pid 955873:tid 956088] [client 216.24.219.100:40273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxWERFTPRVSLOsRVhrxHgAAAV8"]
[Thu Sep 17 15:05:21.328876 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:45610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ResponseException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxHwAAATI"]
[Thu Sep 17 15:05:21.328967 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:45610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ResponseException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxHwAAATI"]
[Thu Sep 17 15:05:21.361066 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/vite/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxIAAAASs"]
[Thu Sep 17 15:05:21.392383 2026] [security2:error] [pid 955873:tid 956114] [client 85.208.98.197:44667] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxWERFTPRVSLOsRVhrxFwAAAXk"]
[Thu Sep 17 15:05:21.423375 2026] [authz_core:error] [pid 955873:tid 956075] [client 4.240.114.86:56504] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:05:21.569878 2026] [security2:error] [pid 955873:tid 956059] [client 34.154.219.249:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWERFTPRVSLOsRVhrxJAAAAUI"]
[Thu Sep 17 15:05:21.596722 2026] [security2:error] [pid 955873:tid 956084] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxJQAAAVs"]
[Thu Sep 17 15:05:21.750939 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:45616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ServerException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxKQAAAS4"]
[Thu Sep 17 15:05:21.751014 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:45616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ServerException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxKQAAAS4"]
[Thu Sep 17 15:05:21.828627 2026] [security2:error] [pid 955873:tid 956022] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/backups/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxLwAAAR0"]
[Thu Sep 17 15:05:22.008986 2026] [security2:error] [pid 955873:tid 956095] [client 193.36.224.212:55615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/txets.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMQAAAWY"]
[Thu Sep 17 15:05:22.042087 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:45622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporter.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMgAAAXw"]
[Thu Sep 17 15:05:22.042166 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:45622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporter.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMgAAAXw"]
[Thu Sep 17 15:05:22.050589 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.219.249:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMwAAAUM"]
[Thu Sep 17 15:05:22.063171 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxNAAAAU4"]
[Thu Sep 17 15:05:22.295028 2026] [security2:error] [pid 955873:tid 956020] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/tmp/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxOQAAARs"]
[Thu Sep 17 15:05:22.330794 2026] [security2:error] [pid 955873:tid 956048] [client 104.234.19.143:50819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-includes/txets.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxOwAAATc"]
[Thu Sep 17 15:05:22.340502 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporterFactory.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxPAAAAWE"]
[Thu Sep 17 15:05:22.340572 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:45634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporterFactory.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxPAAAAWE"]
[Thu Sep 17 15:05:22.529352 2026] [security2:error] [pid 955873:tid 956097] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/temp/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxPgAAAWg"]
[Thu Sep 17 15:05:22.534414 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxPwAAAUw"]
[Thu Sep 17 15:05:22.589392 2026] [security2:error] [pid 955873:tid 956031] [client 20.244.34.24:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxQAAAASY"], referer: binance.com
[Thu Sep 17 15:05:22.621818 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:45640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/"] [unique_id "aqxWEhFTPRVSLOsRVhrxQgAAAUc"]
[Thu Sep 17 15:05:22.735251 2026] [security2:error] [pid 955873:tid 956033] [client 216.24.219.100:46229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/goods.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxRQAAASg"]
[Thu Sep 17 15:05:22.763761 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/lab/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxRgAAARA"]
[Thu Sep 17 15:05:22.792782 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/"] [unique_id "aqxWEhFTPRVSLOsRVhrxRwAAAVY"]
[Thu Sep 17 15:05:22.930777 2026] [security2:error] [pid 955873:tid 956104] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "aqxWEhFTPRVSLOsRVhrxSQAAAW8"]
[Thu Sep 17 15:05:22.933568 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:45640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWEhFTPRVSLOsRVhrxSwAAAVM"]
[Thu Sep 17 15:05:23.003897 2026] [security2:error] [pid 955873:tid 956010] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cronlab/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxTQAAARE"]
[Thu Sep 17 15:05:23.011058 2026] [security2:error] [pid 955873:tid 956019] [client 216.24.219.20:63647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/php8.php"] [unique_id "aqxWExFTPRVSLOsRVhrxTgAAARo"]
[Thu Sep 17 15:05:23.028754 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.219.249:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWExFTPRVSLOsRVhrxTwAAAVE"]
[Thu Sep 17 15:05:23.159001 2026] [security2:error] [pid 955873:tid 956127] [client 40.77.167.136:5692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.chriswestlake.com"] [uri "/index.php"] [unique_id "aqxWExFTPRVSLOsRVhrxUgABhno"]
[Thu Sep 17 15:05:23.168288 2026] [autoindex:error] [pid 955873:tid 956008] [client 34.178.167.214:53054] AH01276: Cannot serve directory /home1/gscqjxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:23.252649 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxVAAAATY"]
[Thu Sep 17 15:05:23.265279 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWExFTPRVSLOsRVhrxUAAAAYU"]
[Thu Sep 17 15:05:23.265304 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWExFTPRVSLOsRVhrxUAAAAYU"]
[Thu Sep 17 15:05:23.405162 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:45640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithHttpTransporterTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxWgAAARI"]
[Thu Sep 17 15:05:23.405239 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:45640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithHttpTransporterTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxWgAAARI"]
[Thu Sep 17 15:05:23.487818 2026] [security2:error] [pid 955873:tid 956065] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/en/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxXAAAAUg"]
[Thu Sep 17 15:05:23.499275 2026] [security2:error] [pid 955873:tid 956086] [client 34.154.219.249:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWExFTPRVSLOsRVhrxXgAAAV0"]
[Thu Sep 17 15:05:23.582417 2026] [security2:error] [pid 955873:tid 956082] [client 127.0.0.1:16106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxWExFTPRVSLOsRVhrxYAAAAVk"]
[Thu Sep 17 15:05:23.582535 2026] [security2:error] [pid 955873:tid 956042] [client 74.7.228.39:37526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.pazcreativehomes.com"] [uri "/robots.txt"] [unique_id "aqxWExFTPRVSLOsRVhrxXwABMXw"]
[Thu Sep 17 15:05:23.682565 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:45646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithRequestAuthenticationTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxZQAAAUE"]
[Thu Sep 17 15:05:23.682985 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:45646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithRequestAuthenticationTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxZQAAAUE"]
[Thu Sep 17 15:05:23.766515 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/administrator/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxZgAAATk"]
[Thu Sep 17 15:05:23.962095 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:45662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/"] [unique_id "aqxWExFTPRVSLOsRVhrxbAAAAW0"]
[Thu Sep 17 15:05:23.989611 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.219.249:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWExFTPRVSLOsRVhrxbQAAAVI"]
[Thu Sep 17 15:05:23.999518 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/psnlink/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxbgAAAWM"]
[Thu Sep 17 15:05:24.122732 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/"] [unique_id "aqxWFBFTPRVSLOsRVhrxcgAAAXI"]
[Thu Sep 17 15:05:24.231638 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/exapi/.env"] [unique_id "aqxWFBFTPRVSLOsRVhrxcwAAAV4"]
[Thu Sep 17 15:05:24.260967 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:45662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWFBFTPRVSLOsRVhrxdQAAAXA"]
[Thu Sep 17 15:05:24.461508 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxfQAAAVU"]
[Thu Sep 17 15:05:24.545256 2026] [security2:error] [pid 955873:tid 956015] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sitemaps/.env"] [unique_id "aqxWFBFTPRVSLOsRVhrxgQAAARY"]
[Thu Sep 17 15:05:24.592420 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxewAAAW4"]
[Thu Sep 17 15:05:24.592441 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxewAAAW4"]
[Thu Sep 17 15:05:24.733287 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:45662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ErrorMessageExtractor.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxhgAAARs"]
[Thu Sep 17 15:05:24.733363 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:45662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ErrorMessageExtractor.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxhgAAARs"]
[Thu Sep 17 15:05:24.835173 2026] [autoindex:error] [pid 955873:tid 956106] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:24.835622 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFBFTPRVSLOsRVhrxkAAAAXE"]
[Thu Sep 17 15:05:24.837208 2026] [security2:error] [pid 955873:tid 956031] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/uploads/"] [unique_id "aqxWFBFTPRVSLOsRVhrxjgAAASY"]
[Thu Sep 17 15:05:24.934018 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.219.249:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxlgAAARk"]
[Thu Sep 17 15:05:24.934867 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env"] [unique_id "aqxWFBFTPRVSLOsRVhrxlQAAAQ4"]
[Thu Sep 17 15:05:25.036940 2026] [autoindex:error] [pid 955873:tid 956003] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.037391 2026] [security2:error] [pid 955873:tid 956003] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxmwAAAQo"]
[Thu Sep 17 15:05:25.043634 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:45664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ResponseUtil.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxnAAAATM"]
[Thu Sep 17 15:05:25.043737 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:45664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ResponseUtil.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxnAAAATM"]
[Thu Sep 17 15:05:25.044257 2026] [security2:error] [pid 955873:tid 956019] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/"] [unique_id "aqxWFBFTPRVSLOsRVhrxmQAAARo"]
[Thu Sep 17 15:05:25.095033 2026] [authz_core:error] [pid 955873:tid 956010] [client 4.240.114.86:58652] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:05:25.205869 2026] [security2:error] [pid 955873:tid 956047] [client 216.73.163.45:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxoQAAATY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:25.289369 2026] [autoindex:error] [pid 955873:tid 956063] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.289828 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxqAAAAUY"]
[Thu Sep 17 15:05:25.303485 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/css/"] [unique_id "aqxWFRFTPRVSLOsRVhrxpQAAASc"]
[Thu Sep 17 15:05:25.323683 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFRFTPRVSLOsRVhrxqwAAAYE"]
[Thu Sep 17 15:05:25.324006 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/logs/.env"] [unique_id "aqxWFRFTPRVSLOsRVhrxqgAAAXo"]
[Thu Sep 17 15:05:25.393146 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.219.249:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxrAAAARI"]
[Thu Sep 17 15:05:25.412448 2026] [security2:error] [pid 955873:tid 956126] [client 185.55.149.49:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxrQAAAYU"]
[Thu Sep 17 15:05:25.412558 2026] [security2:error] [pid 955873:tid 956126] [client 185.55.149.49:56772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxrQAAAYU"]
[Thu Sep 17 15:05:25.498099 2026] [autoindex:error] [pid 955873:tid 956121] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.498547 2026] [security2:error] [pid 955873:tid 956121] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxswAAAYA"]
[Thu Sep 17 15:05:25.527154 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFRFTPRVSLOsRVhrxsAAAAVk"]
[Thu Sep 17 15:05:25.531349 2026] [security2:error] [pid 955873:tid 956042] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/ID3/"] [unique_id "aqxWFRFTPRVSLOsRVhrxsQAAATE"]
[Thu Sep 17 15:05:25.666766 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWFRFTPRVSLOsRVhrxuAAAAWk"]
[Thu Sep 17 15:05:25.733855 2026] [autoindex:error] [pid 955873:tid 956014] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.734539 2026] [security2:error] [pid 955873:tid 956014] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxvgAAARU"]
[Thu Sep 17 15:05:25.795498 2026] [security2:error] [pid 955873:tid 956084] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/IXR/"] [unique_id "aqxWFRFTPRVSLOsRVhrxuwAAAVs"]
[Thu Sep 17 15:05:25.880450 2026] [security2:error] [pid 955873:tid 956016] [client 34.154.219.249:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxxAAAARc"]
[Thu Sep 17 15:05:25.970610 2026] [security2:error] [pid 955873:tid 956117] [client 168.119.53.160:48122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "i.am.tengushee.com"] [uri "/index.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxywAAAXw"], referer: http://i.am.tengushee.com
[Thu Sep 17 15:05:26.022602 2026] [security2:error] [pid 955873:tid 956006] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cache/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrxzwAAAQ0"]
[Thu Sep 17 15:05:26.036357 2026] [autoindex:error] [pid 955873:tid 956109] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:26.037007 2026] [security2:error] [pid 955873:tid 956109] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFhFTPRVSLOsRVhrxzgAAAXQ"]
[Thu Sep 17 15:05:26.038127 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxwwAAAWY"]
[Thu Sep 17 15:05:26.038145 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxwwAAAWY"]
[Thu Sep 17 15:05:26.038669 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/Requests/"] [unique_id "aqxWFRFTPRVSLOsRVhrxxwAAAVg"]
[Thu Sep 17 15:05:26.187640 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/"] [unique_id "aqxWFhFTPRVSLOsRVhrx0QAAAYg"]
[Thu Sep 17 15:05:26.253506 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx2QAAASY"]
[Thu Sep 17 15:05:26.261377 2026] [autoindex:error] [pid 955873:tid 956077] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:26.261843 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFhFTPRVSLOsRVhrx2AAAAVQ"]
[Thu Sep 17 15:05:26.284862 2026] [security2:error] [pid 955873:tid 956085] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxWFhFTPRVSLOsRVhrx0wAAAVw"]
[Thu Sep 17 15:05:26.352555 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/"] [unique_id "aqxWFhFTPRVSLOsRVhrx3QAAARA"]
[Thu Sep 17 15:05:26.377625 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx3gAAAUw"]
[Thu Sep 17 15:05:26.481585 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx4wAAARo"]
[Thu Sep 17 15:05:26.516249 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFhFTPRVSLOsRVhrx5gAAAXc"]
[Thu Sep 17 15:05:26.528863 2026] [autoindex:error] [pid 955873:tid 956049] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:26.529319 2026] [security2:error] [pid 955873:tid 956049] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFhFTPRVSLOsRVhrx5QAAATg"]
[Thu Sep 17 15:05:26.547315 2026] [security2:error] [pid 955873:tid 956003] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/Text/"] [unique_id "aqxWFhFTPRVSLOsRVhrx3wAAAQo"]
[Thu Sep 17 15:05:26.695858 2026] [security2:error] [pid 955873:tid 955886] [remote 216.73.217.142:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWFhFTPRVSLOsRVhrx6wABXQw"]
[Thu Sep 17 15:05:26.720672 2026] [security2:error] [pid 955873:tid 956072] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/email/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx7gAAAU8"]
[Thu Sep 17 15:05:26.791277 2026] [security2:error] [pid 955873:tid 956124] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWFhFTPRVSLOsRVhrx9QAAAYM"]
[Thu Sep 17 15:05:26.857943 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.219.249:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx-AAAAYE"]
[Thu Sep 17 15:05:26.869577 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx6gAAAUg"]
[Thu Sep 17 15:05:26.869604 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx6gAAAUg"]
[Thu Sep 17 15:05:26.953405 2026] [security2:error] [pid 955873:tid 956046] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/smtp/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx-QAAATU"]
[Thu Sep 17 15:05:27.024441 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:45678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/ModelInterface.php"] [unique_id "aqxWFxFTPRVSLOsRVhrx_gAAAUQ"]
[Thu Sep 17 15:05:27.024525 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/ModelInterface.php"] [unique_id "aqxWFxFTPRVSLOsRVhrx_gAAAUQ"]
[Thu Sep 17 15:05:27.060970 2026] [security2:error] [pid 955873:tid 956101] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWFxFTPRVSLOsRVhrx_wAAAWw"]
[Thu Sep 17 15:05:27.183904 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailing/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryAQAAAXI"]
[Thu Sep 17 15:05:27.187007 2026] [autoindex:error] [pid 955873:tid 956104] [client 194.163.134.215:38820] AH01276: Cannot serve directory /home1/pqcmzsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:27.318103 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/"] [unique_id "aqxWFxFTPRVSLOsRVhryDQAAARc"]
[Thu Sep 17 15:05:27.342297 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.219.249:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWFxFTPRVSLOsRVhryDgAAAWk"]
[Thu Sep 17 15:05:27.414837 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/notifications/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryEQAAAUE"]
[Thu Sep 17 15:05:27.446983 2026] [security2:error] [pid 955873:tid 956117] [client 20.244.34.24:65042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxWFxFTPRVSLOsRVhryEwAAAXw"], referer: binance.com
[Thu Sep 17 15:05:27.481062 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/"] [unique_id "aqxWFxFTPRVSLOsRVhryFAAAAV4"]
[Thu Sep 17 15:05:27.580478 2026] [security2:error] [pid 955873:tid 956052] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWFxFTPRVSLOsRVhryFwAAATs"]
[Thu Sep 17 15:05:27.624532 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFxFTPRVSLOsRVhryGgAAAWE"]
[Thu Sep 17 15:05:27.652044 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/notify/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryGwAAAYg"]
[Thu Sep 17 15:05:27.791074 2026] [security2:error] [pid 955873:tid 956029] [client 88.99.80.227:62228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.endless-chronicles.com"] [uri "/index.php"] [unique_id "aqxWFxFTPRVSLOsRVhryJwAAASQ"], referer: http://www.endless-chronicles.com
[Thu Sep 17 15:05:27.810836 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:56450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWFxFTPRVSLOsRVhryKAAAASY"]
[Thu Sep 17 15:05:27.833702 2026] [autoindex:error] [pid 955873:tid 956039] [client 34.35.44.204:45802] AH01276: Cannot serve directory /home1/omqzshmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:27.883821 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sender/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryLAAAAVM"]
[Thu Sep 17 15:05:27.961791 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFxFTPRVSLOsRVhryJQAAAWc"]
[Thu Sep 17 15:05:27.961816 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFxFTPRVSLOsRVhryJQAAAWc"]
[Thu Sep 17 15:05:28.008909 2026] [security2:error] [pid 955873:tid 956095] [client 45.146.54.112:35661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWGBFTPRVSLOsRVhryMAAAAWY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:28.117914 2026] [security2:error] [pid 955873:tid 956008] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/campaign/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryNQAAAQ8"]
[Thu Sep 17 15:05:28.143967 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:45682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelConfig.php"] [unique_id "aqxWGBFTPRVSLOsRVhryOAAAATY"]
[Thu Sep 17 15:05:28.144052 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelConfig.php"] [unique_id "aqxWGBFTPRVSLOsRVhryOAAAATY"]
[Thu Sep 17 15:05:28.245725 2026] [security2:error] [pid 955873:tid 956121] [client 4.240.114.86:60401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-admin/includes/dvskadniwoc.php"] [unique_id "aqxWGBFTPRVSLOsRVhryPQAAAYA"], referer: binance.com
[Thu Sep 17 15:05:28.350274 2026] [security2:error] [pid 955873:tid 956011] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/newsletter/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryRQAAARI"]
[Thu Sep 17 15:05:28.422415 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:45696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelMetadata.php"] [unique_id "aqxWGBFTPRVSLOsRVhrySAAAAWo"]
[Thu Sep 17 15:05:28.422499 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:45696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelMetadata.php"] [unique_id "aqxWGBFTPRVSLOsRVhrySAAAAWo"]
[Thu Sep 17 15:05:28.584538 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/ses/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryUQAAAXg"]
[Thu Sep 17 15:05:28.589818 2026] [security2:error] [pid 955873:tid 956063] [client 47.79.207.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWGBFTPRVSLOsRVhryOgAAAUY"], referer: https://www.google.com/
[Thu Sep 17 15:05:28.629435 2026] [security2:error] [pid 955873:tid 956062] [client 216.73.163.42:54893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWGBFTPRVSLOsRVhryUgAAAUU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:28.713819 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:45706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelRequirements.php"] [unique_id "aqxWGBFTPRVSLOsRVhryVgAAASw"]
[Thu Sep 17 15:05:28.713926 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:45706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelRequirements.php"] [unique_id "aqxWGBFTPRVSLOsRVhryVgAAASw"]
[Thu Sep 17 15:05:28.816001 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sendgrid/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryYAAAAVo"]
[Thu Sep 17 15:05:29.007045 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/RequiredOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryaQAAAVM"]
[Thu Sep 17 15:05:29.007162 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:45708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/RequiredOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryaQAAAVM"]
[Thu Sep 17 15:05:29.033728 2026] [security2:error] [pid 955873:tid 956123] [client 168.232.161.19:4669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWGBFTPRVSLOsRVhryZQABghc"]
[Thu Sep 17 15:05:29.051858 2026] [security2:error] [pid 955873:tid 956069] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sparkpost/.env"] [unique_id "aqxWGRFTPRVSLOsRVhrybwAAAUw"]
[Thu Sep 17 15:05:29.073566 2026] [security2:error] [pid 955873:tid 956052] [client 37.19.210.94:48767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.210.19.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lasvegaslife.info"] [uri "/xmlrpc.php"] [unique_id "aqxWGRFTPRVSLOsRVhryawAAATs"]
[Thu Sep 17 15:05:29.073723 2026] [security2:error] [pid 955873:tid 956052] [client 37.19.210.94:48767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lasvegaslife.info"] [uri "/xmlrpc.php"] [unique_id "aqxWGRFTPRVSLOsRVhryawAAATs"]
[Thu Sep 17 15:05:29.285592 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/SupportedOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryewAAASU"]
[Thu Sep 17 15:05:29.285694 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/SupportedOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryewAAASU"]
[Thu Sep 17 15:05:29.290915 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/postmark/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryfAAAATM"]
[Thu Sep 17 15:05:29.520492 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailgun/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryhQAAAV8"]
[Thu Sep 17 15:05:29.530972 2026] [security2:error] [pid 955873:tid 956082] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryiAAAAVk"]
[Thu Sep 17 15:05:29.578031 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:45728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/"] [unique_id "aqxWGRFTPRVSLOsRVhryiQAAAUs"]
[Thu Sep 17 15:05:29.737279 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/"] [unique_id "aqxWGRFTPRVSLOsRVhrykAAAAXI"]
[Thu Sep 17 15:05:29.749454 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mandrill/.env"] [unique_id "aqxWGRFTPRVSLOsRVhrylAAAARU"]
[Thu Sep 17 15:05:29.892998 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:45728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWGRFTPRVSLOsRVhrynAAAAWk"]
[Thu Sep 17 15:05:29.980008 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailjet/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryoAAAAXs"]
[Thu Sep 17 15:05:29.994079 2026] [security2:error] [pid 955873:tid 956077] [client 192.178.6.4:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWGRFTPRVSLOsRVhryoQAAAVQ"]
[Thu Sep 17 15:05:30.208927 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWGhFTPRVSLOsRVhryqwAAARs"]
[Thu Sep 17 15:05:30.212026 2026] [security2:error] [pid 955873:tid 956048] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/brevo/.env"] [unique_id "aqxWGhFTPRVSLOsRVhryrQAAATc"]
[Thu Sep 17 15:05:30.241944 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhrypgAAAYg"]
[Thu Sep 17 15:05:30.241975 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhrypgAAAYg"]
[Thu Sep 17 15:05:30.245509 2026] [security2:error] [pid 955873:tid 956028] [client 154.190.208.131:41714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhrysgAAASM"]
[Thu Sep 17 15:05:30.246034 2026] [security2:error] [pid 955873:tid 956028] [client 154.190.208.131:41714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhrysgAAASM"]
[Thu Sep 17 15:05:30.382602 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:45728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/CapabilityEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryuQAAAUw"]
[Thu Sep 17 15:05:30.382759 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:45728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/CapabilityEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryuQAAAUw"]
[Thu Sep 17 15:05:30.421090 2026] [security2:error] [pid 955873:tid 956025] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWGhFTPRVSLOsRVhryvAAAASA"]
[Thu Sep 17 15:05:30.436060 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx8wAAATo"]
[Thu Sep 17 15:05:30.436086 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx8wAAATo"]
[Thu Sep 17 15:05:30.438747 2026] [security2:error] [pid 955873:tid 956115] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxWFhFTPRVSLOsRVhrx7AAAAXo"]
[Thu Sep 17 15:05:30.443022 2026] [security2:error] [pid 955873:tid 956096] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/transactional/.env"] [unique_id "aqxWGhFTPRVSLOsRVhrywAAAAWc"]
[Thu Sep 17 15:05:30.606781 2026] [security2:error] [pid 955873:tid 956023] [client 45.169.98.18:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhryxgAAAR4"]
[Thu Sep 17 15:05:30.606852 2026] [security2:error] [pid 955873:tid 956023] [client 45.169.98.18:52126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhryxgAAAR4"]
[Thu Sep 17 15:05:30.670066 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/OptionEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryzgAAAYE"]
[Thu Sep 17 15:05:30.670146 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:58374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/OptionEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryzgAAAYE"]
[Thu Sep 17 15:05:30.676460 2026] [security2:error] [pid 955873:tid 956012] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/bulk/.env"] [unique_id "aqxWGhFTPRVSLOsRVhryzwAAARM"]
[Thu Sep 17 15:05:30.738468 2026] [security2:error] [pid 955873:tid 956046] [client 216.73.163.48:39879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWGhFTPRVSLOsRVhry0AAAATU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:30.803512 2026] [security2:error] [pid 955873:tid 956052] [client 186.105.232.15:64488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhry1wAAATs"]
[Thu Sep 17 15:05:30.803614 2026] [security2:error] [pid 955873:tid 956052] [client 186.105.232.15:64488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhry1wAAATs"]
[Thu Sep 17 15:05:30.911630 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/aws/.env"] [unique_id "aqxWGhFTPRVSLOsRVhry3wAAAXI"]
[Thu Sep 17 15:05:30.972779 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/"] [unique_id "aqxWGhFTPRVSLOsRVhry5AAAATk"]
[Thu Sep 17 15:05:31.013366 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhry2wAAAWo"]
[Thu Sep 17 15:05:31.013389 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhry2wAAAWo"]
[Thu Sep 17 15:05:31.042131 2026] [security2:error] [pid 955873:tid 956072] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxWGhFTPRVSLOsRVhry2QAAAU8"]
[Thu Sep 17 15:05:31.145747 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/azure/.env"] [unique_id "aqxWGxFTPRVSLOsRVhry6gAAAXs"]
[Thu Sep 17 15:05:31.151015 2026] [security2:error] [pid 955873:tid 956077] [client 4.240.114.86:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-admin/includes/medias.php"] [unique_id "aqxWGxFTPRVSLOsRVhry6wAAAVQ"], referer: binance.com
[Thu Sep 17 15:05:31.340925 2026] [security2:error] [pid 955873:tid 956021] [client 115.244.164.14:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGxFTPRVSLOsRVhry9QAAARw"]
[Thu Sep 17 15:05:31.341024 2026] [security2:error] [pid 955873:tid 956021] [client 115.244.164.14:61288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGxFTPRVSLOsRVhry9QAAARw"]
[Thu Sep 17 15:05:31.373138 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/gcp/.env"] [unique_id "aqxWGxFTPRVSLOsRVhry9wAAAS4"]
[Thu Sep 17 15:05:31.395064 2026] [security2:error] [pid 955873:tid 956067] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhry8wAAAUo"]
[Thu Sep 17 15:05:31.395084 2026] [security2:error] [pid 955873:tid 956067] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhry8wAAAUo"]
[Thu Sep 17 15:05:31.447449 2026] [security2:error] [pid 955873:tid 956071] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxWGxFTPRVSLOsRVhry8QAAAU4"]
[Thu Sep 17 15:05:31.457797 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/"] [unique_id "aqxWGxFTPRVSLOsRVhry-AAAARs"]
[Thu Sep 17 15:05:31.476011 2026] [security2:error] [pid 955873:tid 956069] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWGxFTPRVSLOsRVhry_AAAAUw"]
[Thu Sep 17 15:05:31.605894 2026] [security2:error] [pid 955873:tid 956109] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cloud/.env"] [unique_id "aqxWGxFTPRVSLOsRVhry_wAAAXQ"]
[Thu Sep 17 15:05:31.619289 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWGxFTPRVSLOsRVhrzAAAAAWg"]
[Thu Sep 17 15:05:31.739849 2026] [autoindex:error] [pid 955873:tid 956106] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:31.740300 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWGxFTPRVSLOsRVhrzBwAAAXE"]
[Thu Sep 17 15:05:31.744424 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxWGxFTPRVSLOsRVhrzAgAAASc"]
[Thu Sep 17 15:05:31.753799 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWGxFTPRVSLOsRVhrzCgAAAR4"]
[Thu Sep 17 15:05:31.833595 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/infrastructure/.env"] [unique_id "aqxWGxFTPRVSLOsRVhrzDwAAAWM"]
[Thu Sep 17 15:05:31.958008 2026] [autoindex:error] [pid 955873:tid 956046] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:31.958497 2026] [security2:error] [pid 955873:tid 956046] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWGxFTPRVSLOsRVhrzFQAAATU"]
[Thu Sep 17 15:05:31.975995 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhrzDgAAARM"]
[Thu Sep 17 15:05:31.976015 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhrzDgAAARM"]
[Thu Sep 17 15:05:32.007771 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxWGxFTPRVSLOsRVhrzEwAAAX4"]
[Thu Sep 17 15:05:32.063363 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzGAAAATs"]
[Thu Sep 17 15:05:32.068344 2026] [security2:error] [pid 955873:tid 956061] [client 194.163.128.162:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzGQAAAUQ"], referer: binance.com
[Thu Sep 17 15:05:32.193945 2026] [security2:error] [pid 955873:tid 956065] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzHAAAAUg"]
[Thu Sep 17 15:05:32.208367 2026] [security2:error] [pid 955873:tid 956114] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/blocks/"] [unique_id "aqxWHBFTPRVSLOsRVhrzGgAAAXk"]
[Thu Sep 17 15:05:32.213912 2026] [security2:error] [pid 955873:tid 956089] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzHQAAAWA"]
[Thu Sep 17 15:05:32.249847 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/"] [unique_id "aqxWHBFTPRVSLOsRVhrzHwAAAWs"]
[Thu Sep 17 15:05:32.298084 2026] [security2:error] [pid 955873:tid 956013] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/k8s/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzIgAAARQ"]
[Thu Sep 17 15:05:32.311132 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWHBFTPRVSLOsRVhrzIwAAAUI"]
[Thu Sep 17 15:05:32.392778 2026] [autoindex:error] [pid 955873:tid 956104] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:32.393246 2026] [security2:error] [pid 955873:tid 956104] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHBFTPRVSLOsRVhrzKQAAAW8"]
[Thu Sep 17 15:05:32.400167 2026] [security2:error] [pid 955873:tid 956113] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/certificates/"] [unique_id "aqxWHBFTPRVSLOsRVhrzJwAAAXg"]
[Thu Sep 17 15:05:32.405330 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/"] [unique_id "aqxWHBFTPRVSLOsRVhrzKgAAATE"]
[Thu Sep 17 15:05:32.412710 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzKwAAAUU"]
[Thu Sep 17 15:05:32.531423 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/kubernetes/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzLAAAASs"]
[Thu Sep 17 15:05:32.542665 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/"] [unique_id "aqxWHBFTPRVSLOsRVhrzLQAAAXw"]
[Thu Sep 17 15:05:32.566748 2026] [security2:error] [pid 955873:tid 956125] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzMAAAAYQ"]
[Thu Sep 17 15:05:32.602356 2026] [autoindex:error] [pid 955873:tid 956083] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:32.603033 2026] [security2:error] [pid 955873:tid 956083] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHBFTPRVSLOsRVhrzMgAAAVo"]
[Thu Sep 17 15:05:32.656287 2026] [security2:error] [pid 955873:tid 956037] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/customize/"] [unique_id "aqxWHBFTPRVSLOsRVhrzLgAAASw"]
[Thu Sep 17 15:05:32.656301 2026] [security2:error] [pid 955873:tid 956098] [client 47.79.200.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzJgAAAWk"], referer: https://www.google.com/
[Thu Sep 17 15:05:32.738217 2026] [security2:error] [pid 955873:tid 956020] [client 20.244.34.24:51330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzNgAAARs"], referer: binance.com
[Thu Sep 17 15:05:32.747123 2026] [security2:error] [pid 955873:tid 956043] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzNwAAATI"]
[Thu Sep 17 15:05:32.764385 2026] [security2:error] [pid 955873:tid 956041] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/terraform/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzOQAAATA"]
[Thu Sep 17 15:05:32.855890 2026] [autoindex:error] [pid 955873:tid 956018] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:32.856364 2026] [security2:error] [pid 955873:tid 956018] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHBFTPRVSLOsRVhrzPAAAARk"]
[Thu Sep 17 15:05:32.870454 2026] [security2:error] [pid 955873:tid 956069] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/fonts/"] [unique_id "aqxWHBFTPRVSLOsRVhrzOgAAAUw"]
[Thu Sep 17 15:05:32.878258 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzMwAAAWE"]
[Thu Sep 17 15:05:32.878276 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzMwAAAWE"]
[Thu Sep 17 15:05:32.912470 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzPgAAAWQ"]
[Thu Sep 17 15:05:32.995024 2026] [security2:error] [pid 955873:tid 956025] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/ansible/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzQgAAASA"]
[Thu Sep 17 15:05:33.015459 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzQwAAASQ"]
[Thu Sep 17 15:05:33.015562 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzQwAAASQ"]
[Thu Sep 17 15:05:33.087075 2026] [security2:error] [pid 955873:tid 956051] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzRwAAATo"]
[Thu Sep 17 15:05:33.099794 2026] [autoindex:error] [pid 955873:tid 956084] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:33.100433 2026] [security2:error] [pid 955873:tid 956084] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHRFTPRVSLOsRVhrzRgAAAVs"]
[Thu Sep 17 15:05:33.104860 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/images/"] [unique_id "aqxWHRFTPRVSLOsRVhrzRAAAAR8"]
[Thu Sep 17 15:05:33.163406 2026] [security2:error] [pid 955873:tid 956006] [client 104.28.198.244:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzSQAAAQ0"]
[Thu Sep 17 15:05:33.163535 2026] [security2:error] [pid 955873:tid 956006] [client 104.28.198.244:22548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzSQAAAQ0"]
[Thu Sep 17 15:05:33.224827 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.git/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzSwAAAS8"]
[Thu Sep 17 15:05:33.287298 2026] [security2:error] [pid 955873:tid 955906] [remote 40.77.167.51:28882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzSgABZyA"]
[Thu Sep 17 15:05:33.289637 2026] [autoindex:error] [pid 955873:tid 956054] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:33.290108 2026] [security2:error] [pid 955873:tid 956054] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHRFTPRVSLOsRVhrzUAAAAT0"]
[Thu Sep 17 15:05:33.296617 2026] [security2:error] [pid 955873:tid 956110] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/.well-known/"] [unique_id "aqxWHRFTPRVSLOsRVhrzTQAAAXU"]
[Thu Sep 17 15:05:33.348713 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationOperationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzVQAAAVU"]
[Thu Sep 17 15:05:33.348804 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:58390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationOperationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzVQAAAVU"]
[Thu Sep 17 15:05:33.456525 2026] [security2:error] [pid 955873:tid 956060] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/ci/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzWAAAAUM"]
[Thu Sep 17 15:05:33.496322 2026] [security2:error] [pid 955873:tid 956012] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzWwAAARM"]
[Thu Sep 17 15:05:33.633106 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/"] [unique_id "aqxWHRFTPRVSLOsRVhrzXgAAAQs"]
[Thu Sep 17 15:05:33.634723 2026] [security2:error] [pid 955873:tid 956126] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzXAAAAYU"]
[Thu Sep 17 15:05:33.634742 2026] [security2:error] [pid 955873:tid 956126] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzXAAAAYU"]
[Thu Sep 17 15:05:33.668078 2026] [security2:error] [pid 955873:tid 956082] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzXwAAAVk"]
[Thu Sep 17 15:05:33.672984 2026] [security2:error] [pid 955873:tid 956038] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/ALFA_DATA/"] [unique_id "aqxWHRFTPRVSLOsRVhrzWQAAAS0"]
[Thu Sep 17 15:05:33.689461 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cd/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzYQAAAUQ"]
[Thu Sep 17 15:05:33.798343 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/"] [unique_id "aqxWHRFTPRVSLOsRVhrzZQAAAXI"]
[Thu Sep 17 15:05:33.887658 2026] [security2:error] [pid 955873:tid 956114] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzaQAAAXk"]
[Thu Sep 17 15:05:33.924919 2026] [security2:error] [pid 955873:tid 956089] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/jenkins/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzbAAAAWA"]
[Thu Sep 17 15:05:33.936905 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWHRFTPRVSLOsRVhrzbQAAAUY"]
[Thu Sep 17 15:05:34.015983 2026] [security2:error] [pid 955873:tid 956092] [client 216.73.163.66:26029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzbgAAAWM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:34.026815 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzagAAAUA"]
[Thu Sep 17 15:05:34.026835 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzagAAAUA"]
[Thu Sep 17 15:05:34.042051 2026] [security2:error] [pid 955873:tid 956072] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzcAAAAU8"]
[Thu Sep 17 15:05:34.042063 2026] [security2:error] [pid 955873:tid 956065] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/.well-knownold/"] [unique_id "aqxWHRFTPRVSLOsRVhrzZwAAAUg"]
[Thu Sep 17 15:05:34.156575 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/gitlab/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzcgAAATE"]
[Thu Sep 17 15:05:34.206550 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzcwAAAUU"]
[Thu Sep 17 15:05:34.262330 2026] [autoindex:error] [pid 955873:tid 956077] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:34.262839 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHhFTPRVSLOsRVhrzdwAAAVQ"]
[Thu Sep 17 15:05:34.269178 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzcQAAAWo"]
[Thu Sep 17 15:05:34.269197 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzcQAAAWo"]
[Thu Sep 17 15:05:34.274098 2026] [security2:error] [pid 955873:tid 956050] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxWHhFTPRVSLOsRVhrzdAAAATk"]
[Thu Sep 17 15:05:34.393332 2026] [security2:error] [pid 955873:tid 956098] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/github/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzewAAAWk"]
[Thu Sep 17 15:05:34.413938 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/"] [unique_id "aqxWHhFTPRVSLOsRVhrzfQAAASI"]
[Thu Sep 17 15:05:34.471190 2026] [cgid:error] [pid 955873:tid 956067] [client 139.28.219.68:0] AH01265: stderr from /home3/ncfwbqmy/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:05:34.471634 2026] [security2:error] [pid 955873:tid 956067] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHhFTPRVSLOsRVhrzgAAAAUo"]
[Thu Sep 17 15:05:34.497724 2026] [security2:error] [pid 955873:tid 956048] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzgQAAATc"]
[Thu Sep 17 15:05:34.497908 2026] [security2:error] [pid 955873:tid 956127] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-bin/"] [unique_id "aqxWHhFTPRVSLOsRVhrzfgAAAYY"]
[Thu Sep 17 15:05:34.581570 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/"] [unique_id "aqxWHhFTPRVSLOsRVhrzgwAAATA"]
[Thu Sep 17 15:05:34.625894 2026] [security2:error] [pid 955873:tid 956018] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/actions/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzhAAAARk"]
[Thu Sep 17 15:05:34.720346 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/"] [unique_id "aqxWHhFTPRVSLOsRVhrziAAAAUw"]
[Thu Sep 17 15:05:34.724109 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrziQAAAWE"]
[Thu Sep 17 15:05:34.829114 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzhwAAAXA"]
[Thu Sep 17 15:05:34.829138 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzhwAAAXA"]
[Thu Sep 17 15:05:34.858783 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/circleci/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzjQAAAU4"]
[Thu Sep 17 15:05:34.905605 2026] [security2:error] [pid 955873:tid 956123] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index/"] [unique_id "aqxWHhFTPRVSLOsRVhrzhQAAAYI"]
[Thu Sep 17 15:05:34.997969 2026] [authz_core:error] [pid 955873:tid 956081] [client 4.240.114.86:64733] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/maint/error_log, referer: binance.com
[Thu Sep 17 15:05:35.085730 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzkAAAAWQ"]
[Thu Sep 17 15:05:35.085751 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzkAAAAWQ"]
[Thu Sep 17 15:05:35.095904 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/travis/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzlQAAARA"]
[Thu Sep 17 15:05:35.150920 2026] [security2:error] [pid 955873:tid 956115] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzlwAAAXo"]
[Thu Sep 17 15:05:35.225683 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzmAAAAUc"]
[Thu Sep 17 15:05:35.225798 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzmAAAAUc"]
[Thu Sep 17 15:05:35.266464 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzlgAAAR8"]
[Thu Sep 17 15:05:35.266497 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzlgAAAR8"]
[Thu Sep 17 15:05:35.302761 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/id/"] [unique_id "aqxWHxFTPRVSLOsRVhrzkgAAATo"]
[Thu Sep 17 15:05:35.318059 2026] [security2:error] [pid 955873:tid 956106] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzngAAAXE"]
[Thu Sep 17 15:05:35.329989 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/buildkite/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrznwAAAVI"]
[Thu Sep 17 15:05:35.510061 2026] [security2:error] [pid 955873:tid 956118] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzqAAAAX0"]
[Thu Sep 17 15:05:35.532785 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationOperationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzqQAAATM"]
[Thu Sep 17 15:05:35.532885 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:58412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationOperationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzqQAAATM"]
[Thu Sep 17 15:05:35.562856 2026] [security2:error] [pid 955873:tid 956030] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mysql/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzqgAAASU"]
[Thu Sep 17 15:05:35.623546 2026] [security2:error] [pid 955873:tid 956121] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzpwAAAYA"]
[Thu Sep 17 15:05:35.623572 2026] [security2:error] [pid 955873:tid 956121] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzpwAAAYA"]
[Thu Sep 17 15:05:35.642719 2026] [security2:error] [pid 955873:tid 956119] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWHxFTPRVSLOsRVhrzqwAAAX4"]
[Thu Sep 17 15:05:35.698769 2026] [security2:error] [pid 955873:tid 956008] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/www/"] [unique_id "aqxWHxFTPRVSLOsRVhrzpQAAAQ8"]
[Thu Sep 17 15:05:35.715135 2026] [security2:error] [pid 955873:tid 956056] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzrAAAAT8"]
[Thu Sep 17 15:05:35.798220 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/postgres/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzsAAAAW4"]
[Thu Sep 17 15:05:35.821682 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/"] [unique_id "aqxWHxFTPRVSLOsRVhrzsQAAAVk"]
[Thu Sep 17 15:05:35.925622 2026] [security2:error] [pid 955873:tid 956052] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWHxFTPRVSLOsRVhrztQAAATs"]
[Thu Sep 17 15:05:36.016049 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrztAAAAXY"]
[Thu Sep 17 15:05:36.016073 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrztAAAAXY"]
[Thu Sep 17 15:05:36.028285 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/"] [unique_id "aqxWIBFTPRVSLOsRVhrztgAAARg"]
[Thu Sep 17 15:05:36.029255 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mongodb/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzuAAAAXI"]
[Thu Sep 17 15:05:36.037120 2026] [security2:error] [pid 955873:tid 956046] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/web/"] [unique_id "aqxWHxFTPRVSLOsRVhrzsgAAATU"]
[Thu Sep 17 15:05:36.068726 2026] [security2:error] [pid 955873:tid 956066] [client 45.131.194.118:48889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrztwAAAUk"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:36.130422 2026] [security2:error] [pid 955873:tid 956035] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzuQAAASo"]
[Thu Sep 17 15:05:36.175924 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWIBFTPRVSLOsRVhrzuwAAARc"]
[Thu Sep 17 15:05:36.182359 2026] [security2:error] [pid 955873:tid 956061] [client 185.55.149.49:57497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzugAAAUQ"]
[Thu Sep 17 15:05:36.182448 2026] [security2:error] [pid 955873:tid 956061] [client 185.55.149.49:57497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzugAAAUQ"]
[Thu Sep 17 15:05:36.264910 2026] [security2:error] [pid 955873:tid 956013] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/redis/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzwgAAARQ"]
[Thu Sep 17 15:05:36.364820 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzvwAAAVc"]
[Thu Sep 17 15:05:36.364845 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzvwAAAVc"]
[Thu Sep 17 15:05:36.417454 2026] [security2:error] [pid 955873:tid 956070] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/uploads/"] [unique_id "aqxWIBFTPRVSLOsRVhrzvAAAAU0"]
[Thu Sep 17 15:05:36.496572 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/elasticsearch/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzxQAAAXg"]
[Thu Sep 17 15:05:36.543978 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzxwAAAUU"]
[Thu Sep 17 15:05:36.700011 2026] [security2:error] [pid 955873:tid 956058] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzywAAAUE"]
[Thu Sep 17 15:05:36.704037 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzxgAAATE"]
[Thu Sep 17 15:05:36.704073 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzxgAAATE"]
[Thu Sep 17 15:05:36.726796 2026] [security2:error] [pid 955873:tid 956122] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/rabbitmq/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrz0AAAAYE"]
[Thu Sep 17 15:05:36.733557 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzygAAAYQ"]
[Thu Sep 17 15:05:36.733581 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzygAAAYQ"]
[Thu Sep 17 15:05:36.761646 2026] [security2:error] [pid 955873:tid 956022] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/upload/"] [unique_id "aqxWIBFTPRVSLOsRVhrzyAAAAR0"]
[Thu Sep 17 15:05:36.849274 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/"] [unique_id "aqxWIBFTPRVSLOsRVhrz1wAAAUo"]
[Thu Sep 17 15:05:36.890932 2026] [security2:error] [pid 955873:tid 956039] [client 47.79.200.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrz1gAAAS4"], referer: https://www.google.com/
[Thu Sep 17 15:05:36.900543 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrz2gAAARs"]
[Thu Sep 17 15:05:36.957546 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/kafka/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrz3wAAAWE"]
[Thu Sep 17 15:05:37.018046 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/"] [unique_id "aqxWIBFTPRVSLOsRVhrz4AAAAXA"]
[Thu Sep 17 15:05:37.122163 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz4wAAAQ4"]
[Thu Sep 17 15:05:37.164839 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/"] [unique_id "aqxWIRFTPRVSLOsRVhrz5AAAASA"]
[Thu Sep 17 15:05:37.190275 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/queue/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz5QAAATQ"]
[Thu Sep 17 15:05:37.217838 2026] [security2:error] [pid 955873:tid 956018] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrz3gAAARk"]
[Thu Sep 17 15:05:37.217866 2026] [security2:error] [pid 955873:tid 956018] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrz3gAAARk"]
[Thu Sep 17 15:05:37.236838 2026] [security2:error] [pid 955873:tid 956043] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/uploads/"] [unique_id "aqxWIBFTPRVSLOsRVhrz2wAAATI"]
[Thu Sep 17 15:05:37.333049 2026] [security2:error] [pid 955873:tid 956109] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz7AAAAXQ"]
[Thu Sep 17 15:05:37.421171 2026] [security2:error] [pid 955873:tid 956110] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/worker/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz8AAAAXU"]
[Thu Sep 17 15:05:37.517322 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz6wAAAUc"]
[Thu Sep 17 15:05:37.517347 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz6wAAAUc"]
[Thu Sep 17 15:05:37.552549 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz7wAAATo"]
[Thu Sep 17 15:05:37.552576 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz7wAAATo"]
[Thu Sep 17 15:05:37.561100 2026] [security2:error] [pid 955873:tid 956040] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz8gAAAS8"]
[Thu Sep 17 15:05:37.573010 2026] [security2:error] [pid 955873:tid 956054] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Admin/uploads/"] [unique_id "aqxWIRFTPRVSLOsRVhrz7QAAAT0"]
[Thu Sep 17 15:05:37.585152 2026] [security2:error] [pid 955873:tid 956055] [client 66.249.77.225:60040] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "gallery.littlethingspr.com"] [uri "/robots.txt"] [unique_id "aqxWIRFTPRVSLOsRVhrz8wAAAT4"]
[Thu Sep 17 15:05:37.667310 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/job/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz9wAAATM"]
[Thu Sep 17 15:05:37.667765 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz-AAAASU"]
[Thu Sep 17 15:05:37.667851 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz-AAAASU"]
[Thu Sep 17 15:05:37.726143 2026] [security2:error] [pid 955873:tid 956005] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz-wAAAQw"]
[Thu Sep 17 15:05:37.899155 2026] [security2:error] [pid 955873:tid 956126] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "aqxWIRFTPRVSLOsRVhr0BAAAAYU"]
[Thu Sep 17 15:05:37.916352 2026] [security2:error] [pid 955873:tid 956068] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWIRFTPRVSLOsRVhr0BQAAAUs"]
[Thu Sep 17 15:05:37.963038 2026] [security2:error] [pid 955873:tid 956052] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0AQAAATs"]
[Thu Sep 17 15:05:37.963066 2026] [security2:error] [pid 955873:tid 956052] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0AQAAATs"]
[Thu Sep 17 15:05:37.978422 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationOperationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0BgAAAQs"]
[Thu Sep 17 15:05:37.978549 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationOperationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0BgAAAQs"]
[Thu Sep 17 15:05:38.003319 2026] [security2:error] [pid 955873:tid 956008] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/"] [unique_id "aqxWIRFTPRVSLOsRVhrz_gAAAQ8"]
[Thu Sep 17 15:05:38.093143 2026] [security2:error] [pid 955873:tid 956107] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0BwAAAXI"]
[Thu Sep 17 15:05:38.135321 2026] [security2:error] [pid 955873:tid 956038] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/qa/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0CAAAAS0"]
[Thu Sep 17 15:05:38.139121 2026] [security2:error] [pid 955873:tid 956046] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0CQAAATU"]
[Thu Sep 17 15:05:38.310200 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/"] [unique_id "aqxWIhFTPRVSLOsRVhr0DAAAAUA"]
[Thu Sep 17 15:05:38.313321 2026] [security2:error] [pid 955873:tid 956063] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0DQAAAUY"]
[Thu Sep 17 15:05:38.364840 2026] [security2:error] [pid 955873:tid 956124] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/preview/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0DwAAAYM"]
[Thu Sep 17 15:05:38.413679 2026] [security2:error] [pid 955873:tid 956091] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0EAAAAWI"]
[Thu Sep 17 15:05:38.478731 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/"] [unique_id "aqxWIhFTPRVSLOsRVhr0EQAAAV0"]
[Thu Sep 17 15:05:38.526548 2026] [security2:error] [pid 955873:tid 956100] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0EgAAAWs"]
[Thu Sep 17 15:05:38.599437 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/beta/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0FgAAATE"]
[Thu Sep 17 15:05:38.621569 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWIhFTPRVSLOsRVhr0FwAAAYQ"]
[Thu Sep 17 15:05:38.692967 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0GAAAASs"]
[Thu Sep 17 15:05:38.697218 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0FQAAAUE"]
[Thu Sep 17 15:05:38.697237 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0FQAAAUE"]
[Thu Sep 17 15:05:38.712700 2026] [security2:error] [pid 955873:tid 956014] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0GQAAARU"]
[Thu Sep 17 15:05:38.756723 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/images/"] [unique_id "aqxWIhFTPRVSLOsRVhr0EwAAAWo"]
[Thu Sep 17 15:05:38.833470 2026] [security2:error] [pid 955873:tid 956079] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/uat/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0HgAAAVY"]
[Thu Sep 17 15:05:38.957410 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0HAAAAUo"]
[Thu Sep 17 15:05:38.957435 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0HAAAAUo"]
[Thu Sep 17 15:05:38.968791 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0IQAAARs"]
[Thu Sep 17 15:05:38.992888 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0IwAAAWE"]
[Thu Sep 17 15:05:39.070861 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/stage/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0JQAAAQo"]
[Thu Sep 17 15:05:39.122172 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/"] [unique_id "aqxWIxFTPRVSLOsRVhr0KAAAARw"]
[Thu Sep 17 15:05:39.160490 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0JAAAAXA"]
[Thu Sep 17 15:05:39.160511 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0JAAAAXA"]
[Thu Sep 17 15:05:39.187655 2026] [security2:error] [pid 955873:tid 956123] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0KgAAAYI"]
[Thu Sep 17 15:05:39.223789 2026] [security2:error] [pid 955873:tid 956127] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/assets/"] [unique_id "aqxWIhFTPRVSLOsRVhr0HwAAAYY"]
[Thu Sep 17 15:05:39.243063 2026] [security2:error] [pid 955873:tid 956006] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0LAAAAQ0"]
[Thu Sep 17 15:05:39.282703 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/"] [unique_id "aqxWIxFTPRVSLOsRVhr0LwAAATQ"]
[Thu Sep 17 15:05:39.304901 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0MQAAARo"]
[Thu Sep 17 15:05:39.345414 2026] [security2:error] [pid 955873:tid 956109] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0MgAAAXQ"]
[Thu Sep 17 15:05:39.439009 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/"] [unique_id "aqxWIxFTPRVSLOsRVhr0MwAAAXM"]
[Thu Sep 17 15:05:39.516677 2026] [security2:error] [pid 955873:tid 956084] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0NQAAAVs"]
[Thu Sep 17 15:05:39.518515 2026] [security2:error] [pid 955873:tid 956110] [client 20.244.34.24:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0NgAAAXU"], referer: binance.com
[Thu Sep 17 15:05:39.537399 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0NwAAATg"]
[Thu Sep 17 15:05:39.779007 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/config/app/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0QgAAAX0"]
[Thu Sep 17 15:05:39.809450 2026] [security2:error] [pid 955873:tid 956005] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0RQAAAQw"]
[Thu Sep 17 15:05:39.822632 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0OAAAAR4"]
[Thu Sep 17 15:05:39.822675 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0OAAAAR4"]
[Thu Sep 17 15:05:39.929414 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0QAAAAXc"]
[Thu Sep 17 15:05:39.929447 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0QAAAAXc"]
[Thu Sep 17 15:05:39.963471 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionModelInterface.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0RwAAAUs"]
[Thu Sep 17 15:05:39.963603 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionModelInterface.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0RwAAAUs"]
[Thu Sep 17 15:05:39.965198 2026] [security2:error] [pid 955873:tid 956052] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0SAAAATs"]
[Thu Sep 17 15:05:39.992909 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxWIxFTPRVSLOsRVhr0PAAAATo"]
[Thu Sep 17 15:05:40.012956 2026] [security2:error] [pid 955873:tid 956008] [client 34.166.129.237:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0SQAAAQ8"]
[Thu Sep 17 15:05:40.072381 2026] [security2:error] [pid 955873:tid 956012] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0SgAAARM"]
[Thu Sep 17 15:05:40.121403 2026] [security2:error] [pid 955873:tid 956088] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0SwAAAV8"]
[Thu Sep 17 15:05:40.279774 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionOperationModelInterface.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0UgAAAWA"]
[Thu Sep 17 15:05:40.279884 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionOperationModelInterface.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0UgAAAWA"]
[Thu Sep 17 15:05:40.317316 2026] [security2:error] [pid 955873:tid 956080] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0VgAAAVc"]
[Thu Sep 17 15:05:40.321694 2026] [security2:error] [pid 955873:tid 956035] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0TgAAASo"]
[Thu Sep 17 15:05:40.321725 2026] [security2:error] [pid 955873:tid 956035] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0TgAAASo"]
[Thu Sep 17 15:05:40.355895 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0VwAAAUY"]
[Thu Sep 17 15:05:40.365708 2026] [security2:error] [pid 955873:tid 956046] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/upload/image/"] [unique_id "aqxWJBFTPRVSLOsRVhr0TAAAATU"]
[Thu Sep 17 15:05:40.478771 2026] [security2:error] [pid 955873:tid 956120] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0WQAAAX8"]
[Thu Sep 17 15:05:40.575204 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/"] [unique_id "aqxWJBFTPRVSLOsRVhr0XQAAATE"]
[Thu Sep 17 15:05:40.638626 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0XwAAARU"]
[Thu Sep 17 15:05:40.695732 2026] [security2:error] [pid 955873:tid 956094] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0XAAAAWU"]
[Thu Sep 17 15:05:40.695751 2026] [security2:error] [pid 955873:tid 956094] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0XAAAAWU"]
[Thu Sep 17 15:05:40.706185 2026] [security2:error] [pid 955873:tid 956086] [client 34.166.129.237:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/info.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0YAAAAV0"]
[Thu Sep 17 15:05:40.733289 2026] [security2:error] [pid 955873:tid 956059] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/assets/images/"] [unique_id "aqxWJBFTPRVSLOsRVhr0WgAAAUI"]
[Thu Sep 17 15:05:40.763698 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/"] [unique_id "aqxWJBFTPRVSLOsRVhr0YQAAAVY"]
[Thu Sep 17 15:05:40.767912 2026] [security2:error] [pid 955873:tid 956124] [client 154.190.208.131:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0ZAAAAYM"]
[Thu Sep 17 15:05:40.775728 2026] [security2:error] [pid 955873:tid 956124] [client 154.190.208.131:42290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0ZAAAAYM"]
[Thu Sep 17 15:05:40.913439 2026] [security2:error] [pid 955873:tid 956021] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0bgAAARw"]
[Thu Sep 17 15:05:40.929954 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWJBFTPRVSLOsRVhr0cQAAAXk"]
[Thu Sep 17 15:05:40.996980 2026] [authz_core:error] [pid 955873:tid 956006] [client 4.240.114.86:51574] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/maint/error_log, referer: binance.com
[Thu Sep 17 15:05:41.051365 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0cAAAAVg"]
[Thu Sep 17 15:05:41.051387 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0cAAAAVg"]
[Thu Sep 17 15:05:41.059085 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0cwAAAYI"]
[Thu Sep 17 15:05:41.059164 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:52691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0cwAAAYI"]
[Thu Sep 17 15:05:41.073530 2026] [security2:error] [pid 955873:tid 956003] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Public/"] [unique_id "aqxWJBFTPRVSLOsRVhr0bAAAAQo"]
[Thu Sep 17 15:05:41.094264 2026] [security2:error] [pid 955873:tid 956022] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0dQAAAR0"]
[Thu Sep 17 15:05:41.189844 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0dwAAAU4"]
[Thu Sep 17 15:05:41.261060 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0dAAAATA"]
[Thu Sep 17 15:05:41.261082 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0dAAAATA"]
[Thu Sep 17 15:05:41.390057 2026] [security2:error] [pid 955873:tid 956049] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0fwAAATg"]
[Thu Sep 17 15:05:41.391210 2026] [security2:error] [pid 955873:tid 956110] [client 74.7.228.3:41556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.cqf.sfu.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWJRFTPRVSLOsRVhr0fgAAAXU"]
[Thu Sep 17 15:05:41.396808 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/php.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0gAAAARo"]
[Thu Sep 17 15:05:41.409930 2026] [security2:error] [pid 955873:tid 956075] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0fAAAAVI"]
[Thu Sep 17 15:05:41.409948 2026] [security2:error] [pid 955873:tid 956075] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0fAAAAVI"]
[Thu Sep 17 15:05:41.420272 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/"] [unique_id "aqxWJRFTPRVSLOsRVhr0gQAAAYc"]
[Thu Sep 17 15:05:41.458745 2026] [security2:error] [pid 955873:tid 956009] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/vendor/"] [unique_id "aqxWJRFTPRVSLOsRVhr0egAAARA"]
[Thu Sep 17 15:05:41.464530 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0gwAAAQw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:05:41.469695 2026] [security2:error] [pid 955873:tid 956118] [client 74.7.228.3:41556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cqf.sfu.mybluehost.me"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxWJRFTPRVSLOsRVhr0ggAAAX0"], referer: https://mail.cqf.sfu.mybluehost.me/robots.txt
[Thu Sep 17 15:05:41.576287 2026] [security2:error] [pid 955873:tid 956064] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0hQAAAUc"]
[Thu Sep 17 15:05:41.584860 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/"] [unique_id "aqxWJRFTPRVSLOsRVhr0hAAAAT4"]
[Thu Sep 17 15:05:41.734440 2026] [security2:error] [pid 955873:tid 956007] [client 186.105.232.15:65073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iwAAAQ4"]
[Thu Sep 17 15:05:41.734538 2026] [security2:error] [pid 955873:tid 956007] [client 186.105.232.15:65073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iwAAAQ4"]
[Thu Sep 17 15:05:41.741710 2026] [security2:error] [pid 955873:tid 956052] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0jAAAATs"]
[Thu Sep 17 15:05:41.742489 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/"] [unique_id "aqxWJRFTPRVSLOsRVhr0jQAAAQs"]
[Thu Sep 17 15:05:41.775747 2026] [security2:error] [pid 955873:tid 956073] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0kQAAAVA"]
[Thu Sep 17 15:05:41.779049 2026] [security2:error] [pid 955873:tid 956044] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iAAAATM"]
[Thu Sep 17 15:05:41.779067 2026] [security2:error] [pid 955873:tid 956044] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iAAAATM"]
[Thu Sep 17 15:05:41.807051 2026] [security2:error] [pid 955873:tid 956082] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/local/"] [unique_id "aqxWJRFTPRVSLOsRVhr0hgAAAVk"]
[Thu Sep 17 15:05:41.926160 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lAAAARI"]
[Thu Sep 17 15:05:41.926241 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:61952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lAAAARI"]
[Thu Sep 17 15:05:42.020569 2026] [security2:error] [pid 955873:tid 956048] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0mAAAATc"]
[Thu Sep 17 15:05:42.022373 2026] [security2:error] [pid 955873:tid 956080] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0mQAAAVc"]
[Thu Sep 17 15:05:42.098773 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.129.237:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/i.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0mgAAASY"]
[Thu Sep 17 15:05:42.116556 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0kwAAARM"]
[Thu Sep 17 15:05:42.116575 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0kwAAARM"]
[Thu Sep 17 15:05:42.123891 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lwAAAXI"]
[Thu Sep 17 15:05:42.123924 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lwAAAXI"]
[Thu Sep 17 15:05:42.151390 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/modules/"] [unique_id "aqxWJRFTPRVSLOsRVhr0lQAAAX4"]
[Thu Sep 17 15:05:42.257892 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0oQAAASg"]
[Thu Sep 17 15:05:42.257988 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0oQAAASg"]
[Thu Sep 17 15:05:42.276432 2026] [security2:error] [pid 955873:tid 956120] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0owAAAX8"]
[Thu Sep 17 15:05:42.295682 2026] [security2:error] [pid 955873:tid 956050] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0pgAAATk"]
[Thu Sep 17 15:05:42.378489 2026] [security2:error] [pid 955873:tid 956057] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.essencestudiosdance.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "aqxWJhFTPRVSLOsRVhr0qgAAAUA"]
[Thu Sep 17 15:05:42.406003 2026] [security2:error] [pid 955873:tid 956072] [client 74.7.228.63:47760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.essencestudiosdance.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxWJhFTPRVSLOsRVhr0pAABTz8"]
[Thu Sep 17 15:05:42.430245 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0rAAAAXs"]
[Thu Sep 17 15:05:42.552022 2026] [security2:error] [pid 955873:tid 956014] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0qwAAARU"]
[Thu Sep 17 15:05:42.552045 2026] [security2:error] [pid 955873:tid 956014] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0qwAAARU"]
[Thu Sep 17 15:05:42.566789 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:56610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationOperationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0rQAAAWo"]
[Thu Sep 17 15:05:42.566905 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:56610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationOperationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0rQAAAWo"]
[Thu Sep 17 15:05:42.570985 2026] [security2:error] [pid 955873:tid 956113] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0rgAAAXg"]
[Thu Sep 17 15:05:42.573470 2026] [security2:error] [pid 955873:tid 956092] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Site/"] [unique_id "aqxWJhFTPRVSLOsRVhr0qAAAAWM"]
[Thu Sep 17 15:05:42.594017 2026] [security2:error] [pid 955873:tid 956079] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0rwAAAVY"]
[Thu Sep 17 15:05:42.762739 2026] [security2:error] [pid 955873:tid 956085] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0tQAAAVw"]
[Thu Sep 17 15:05:42.782506 2026] [security2:error] [pid 955873:tid 956086] [client 34.166.129.237:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/pi.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0twAAAV0"]
[Thu Sep 17 15:05:42.848008 2026] [security2:error] [pid 955873:tid 956053] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0xAAAATw"]
[Thu Sep 17 15:05:42.855290 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:56618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/"] [unique_id "aqxWJhFTPRVSLOsRVhr0xQAAAVg"]
[Thu Sep 17 15:05:42.891169 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0tAAAASc"]
[Thu Sep 17 15:05:42.891193 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0tAAAASc"]
[Thu Sep 17 15:05:42.898599 2026] [security2:error] [pid 955873:tid 956028] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/system/"] [unique_id "aqxWJhFTPRVSLOsRVhr0sgAAASM"]
[Thu Sep 17 15:05:43.049568 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr0xwAAAWg"]
[Thu Sep 17 15:05:43.053106 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/"] [unique_id "aqxWJxFTPRVSLOsRVhr0xgAAAR0"]
[Thu Sep 17 15:05:43.124961 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr0ygAAAXQ"]
[Thu Sep 17 15:05:43.191098 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWJxFTPRVSLOsRVhr0ywAAAXo"]
[Thu Sep 17 15:05:43.227018 2026] [security2:error] [pid 955873:tid 956108] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr0zAAAAXM"]
[Thu Sep 17 15:05:43.265001 2026] [security2:error] [pid 955873:tid 956110] [client 45.146.54.111:40125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00AAAAXU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:43.367953 2026] [security2:error] [pid 955873:tid 955948] [remote 45.239.10.81:37646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr0zwABW0o"]
[Thu Sep 17 15:05:43.405686 2026] [security2:error] [pid 955873:tid 956087] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr01AAAAV4"]
[Thu Sep 17 15:05:43.466341 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr01gAAAWQ"]
[Thu Sep 17 15:05:43.498162 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.129.237:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/pinfo.php"] [unique_id "aqxWJxFTPRVSLOsRVhr01wAAATg"]
[Thu Sep 17 15:05:43.530954 2026] [security2:error] [pid 955873:tid 956025] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr01QAAASA"]
[Thu Sep 17 15:05:43.530976 2026] [security2:error] [pid 955873:tid 956025] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr01QAAASA"]
[Thu Sep 17 15:05:43.591384 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00wAAAUM"]
[Thu Sep 17 15:05:43.591405 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00wAAAUM"]
[Thu Sep 17 15:05:43.683316 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr02gAAAXc"]
[Thu Sep 17 15:05:43.720504 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/template/"] [unique_id "aqxWJxFTPRVSLOsRVhr0yAAAAXA"]
[Thu Sep 17 15:05:43.731220 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr02wAAAQ4"]
[Thu Sep 17 15:05:43.737751 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleImageGenerationModel.php"] [unique_id "aqxWJxFTPRVSLOsRVhr03AAAAQs"]
[Thu Sep 17 15:05:43.737822 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleImageGenerationModel.php"] [unique_id "aqxWJxFTPRVSLOsRVhr03AAAAQs"]
[Thu Sep 17 15:05:43.870930 2026] [security2:error] [pid 955873:tid 956020] [client 194.163.128.162:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxWJxFTPRVSLOsRVhr04AAAARs"], referer: binance.com
[Thu Sep 17 15:05:43.957584 2026] [security2:error] [pid 955873:tid 956088] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr05QAAAV8"]
[Thu Sep 17 15:05:43.984082 2026] [security2:error] [pid 955873:tid 956103] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr05gAAAW4"]
[Thu Sep 17 15:05:44.022604 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleModelMetadataDirectory.php"] [unique_id "aqxWKBFTPRVSLOsRVhr05wAAARM"]
[Thu Sep 17 15:05:44.022693 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:56632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleModelMetadataDirectory.php"] [unique_id "aqxWKBFTPRVSLOsRVhr05wAAARM"]
[Thu Sep 17 15:05:44.052420 2026] [security2:error] [pid 955873:tid 956056] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr05AAAAT8"]
[Thu Sep 17 15:05:44.052437 2026] [security2:error] [pid 955873:tid 956056] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr05AAAAT8"]
[Thu Sep 17 15:05:44.188306 2026] [security2:error] [pid 955873:tid 956119] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr06AAAAX4"]
[Thu Sep 17 15:05:44.202804 2026] [security2:error] [pid 955873:tid 956111] [client 34.166.129.237:44582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/test.php"] [unique_id "aqxWKBFTPRVSLOsRVhr06QAAAXY"]
[Thu Sep 17 15:05:44.232934 2026] [security2:error] [pid 955873:tid 956066] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr06gAAAUk"]
[Thu Sep 17 15:05:44.255616 2026] [security2:error] [pid 955873:tid 956011] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/shop/"] [unique_id "aqxWJxFTPRVSLOsRVhr04gAAARI"]
[Thu Sep 17 15:05:44.312828 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleTextGenerationModel.php"] [unique_id "aqxWKBFTPRVSLOsRVhr07QAAATk"]
[Thu Sep 17 15:05:44.312896 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleTextGenerationModel.php"] [unique_id "aqxWKBFTPRVSLOsRVhr07QAAATk"]
[Thu Sep 17 15:05:44.495561 2026] [security2:error] [pid 955873:tid 956036] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr09AAAASs"]
[Thu Sep 17 15:05:44.507749 2026] [security2:error] [pid 955873:tid 956117] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr09QAAAXw"]
[Thu Sep 17 15:05:44.577097 2026] [security2:error] [pid 955873:tid 956122] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr08wAAAYE"]
[Thu Sep 17 15:05:44.577126 2026] [security2:error] [pid 955873:tid 956122] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr08wAAAYE"]
[Thu Sep 17 15:05:44.623764 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ProviderRegistry.php"] [unique_id "aqxWKBFTPRVSLOsRVhr09gAAARY"]
[Thu Sep 17 15:05:44.623853 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:56658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ProviderRegistry.php"] [unique_id "aqxWKBFTPRVSLOsRVhr09gAAARY"]
[Thu Sep 17 15:05:44.675437 2026] [security2:error] [pid 955873:tid 956062] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/files/"] [unique_id "aqxWKBFTPRVSLOsRVhr07wAAAUU"]
[Thu Sep 17 15:05:44.697869 2026] [security2:error] [pid 955873:tid 956099] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr09wAAAWo"]
[Thu Sep 17 15:05:44.773435 2026] [security2:error] [pid 955873:tid 956092] [client 20.244.34.24:58117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxWKBFTPRVSLOsRVhr0-AAAAWM"], referer: binance.com
[Thu Sep 17 15:05:44.783286 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr0-QAAAUI"]
[Thu Sep 17 15:05:44.856398 2026] [security2:error] [pid 955873:tid 956067] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr0_AAAAUo"]
[Thu Sep 17 15:05:44.916094 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKBFTPRVSLOsRVhr1BwAAATQ"]
[Thu Sep 17 15:05:45.031976 2026] [security2:error] [pid 955873:tid 956096] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1CwAAAWc"]
[Thu Sep 17 15:05:45.059921 2026] [security2:error] [pid 955873:tid 956043] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1DQAAATI"]
[Thu Sep 17 15:05:45.091192 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKRFTPRVSLOsRVhr1DAAAASI"]
[Thu Sep 17 15:05:45.106752 2026] [security2:error] [pid 955873:tid 956085] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr1AgAAAVw"]
[Thu Sep 17 15:05:45.106775 2026] [security2:error] [pid 955873:tid 956085] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr1AgAAAVw"]
[Thu Sep 17 15:05:45.107957 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/editor/"] [unique_id "aqxWKBFTPRVSLOsRVhr0_QAAAUY"]
[Thu Sep 17 15:05:45.217610 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.129.237:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/p.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1FAAAAVI"]
[Thu Sep 17 15:05:45.221263 2026] [security2:error] [pid 955873:tid 956087] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1FQAAAV4"]
[Thu Sep 17 15:05:45.235704 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/wp-includes/php-ai-client/src/"] [unique_id "aqxWKRFTPRVSLOsRVhr1FgAAASU"]
[Thu Sep 17 15:05:45.335374 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1GwAAAQw"]
[Thu Sep 17 15:05:45.385581 2026] [security2:error] [pid 955873:tid 956052] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1IgAAATs"]
[Thu Sep 17 15:05:45.416695 2026] [security2:error] [pid 955873:tid 956098] [client 4.240.114.86:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-login.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1HgAAAWk"], referer: binance.com
[Thu Sep 17 15:05:45.446970 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1GgAAAXE"]
[Thu Sep 17 15:05:45.446991 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1GgAAAXE"]
[Thu Sep 17 15:05:45.549502 2026] [security2:error] [pid 955873:tid 956049] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/include/"] [unique_id "aqxWKRFTPRVSLOsRVhr1FwAAATg"]
[Thu Sep 17 15:05:45.554914 2026] [security2:error] [pid 955873:tid 956088] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1IwAAAV8"]
[Thu Sep 17 15:05:45.610920 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1JQAAAW4"]
[Thu Sep 17 15:05:45.653531 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1IQAAAQ4"]
[Thu Sep 17 15:05:45.653553 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1IQAAAQ4"]
[Thu Sep 17 15:05:45.794008 2026] [security2:error] [pid 955873:tid 956066] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1KwAAAUk"]
[Thu Sep 17 15:05:45.825381 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/"] [unique_id "aqxWKRFTPRVSLOsRVhr1LwAAAUs"]
[Thu Sep 17 15:05:45.878948 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1KgAAAX4"]
[Thu Sep 17 15:05:45.878972 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1KgAAAX4"]
[Thu Sep 17 15:05:45.884811 2026] [security2:error] [pid 955873:tid 956042] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1MwAAATE"]
[Thu Sep 17 15:05:45.909324 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:44596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/debug.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1NAAAAXI"]
[Thu Sep 17 15:05:45.909604 2026] [security2:error] [pid 955873:tid 956037] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Assets/"] [unique_id "aqxWKRFTPRVSLOsRVhr1JwAAASw"]
[Thu Sep 17 15:05:45.972756 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1NgAAAWE"]
[Thu Sep 17 15:05:45.989301 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/"] [unique_id "aqxWKRFTPRVSLOsRVhr1NwAAAVM"]
[Thu Sep 17 15:05:46.136049 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKhFTPRVSLOsRVhr1OwAAAVo"]
[Thu Sep 17 15:05:46.160801 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1PAAAASk"]
[Thu Sep 17 15:05:46.184529 2026] [security2:error] [pid 955873:tid 956099] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1PQAAAWo"]
[Thu Sep 17 15:05:46.215955 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1OgAAAVQ"]
[Thu Sep 17 15:05:46.215973 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1OgAAAVQ"]
[Thu Sep 17 15:05:46.355043 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/images/stories/"] [unique_id "aqxWKhFTPRVSLOsRVhr1OAAAAUE"]
[Thu Sep 17 15:05:46.397738 2026] [security2:error] [pid 955873:tid 956067] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1QgAAAUo"]
[Thu Sep 17 15:05:46.438798 2026] [security2:error] [pid 955873:tid 956086] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1QwAAAV0"]
[Thu Sep 17 15:05:46.491019 2026] [security2:error] [pid 955873:tid 956120] [client 216.73.163.58:27915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1RAAAAX8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:46.498097 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1PgAAAWI"]
[Thu Sep 17 15:05:46.498117 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1PgAAAWI"]
[Thu Sep 17 15:05:46.561949 2026] [security2:error] [pid 955873:tid 956121] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1SAAAAYA"]
[Thu Sep 17 15:05:46.622225 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.129.237:44600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1SgAAAUI"]
[Thu Sep 17 15:05:46.645581 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/ResultInterface.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1SwAAARE"]
[Thu Sep 17 15:05:46.645722 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/ResultInterface.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1SwAAARE"]
[Thu Sep 17 15:05:46.681894 2026] [security2:error] [pid 955873:tid 956069] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1RwAAAUw"]
[Thu Sep 17 15:05:46.681917 2026] [security2:error] [pid 955873:tid 956069] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1RwAAAUw"]
[Thu Sep 17 15:05:46.714804 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1TAAAAWU"]
[Thu Sep 17 15:05:46.761206 2026] [security2:error] [pid 955873:tid 956045] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/plugins/"] [unique_id "aqxWKhFTPRVSLOsRVhr1RQAAATQ"]
[Thu Sep 17 15:05:46.823876 2026] [security2:error] [pid 955873:tid 956053] [client 66.249.66.45:42489] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "memorytrackspodcast.com"] [uri "/robots.txt"] [unique_id "aqxWKhFTPRVSLOsRVhr1UAAAATw"]
[Thu Sep 17 15:05:46.834548 2026] [security2:error] [pid 955873:tid 956027] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1UwAAASI"]
[Thu Sep 17 15:05:46.943898 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1VgAAAWc"]
[Thu Sep 17 15:05:46.944848 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1VgAAAWc"]
[Thu Sep 17 15:05:46.981363 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/"] [unique_id "aqxWKhFTPRVSLOsRVhr1WQAAAWA"]
[Thu Sep 17 15:05:46.990210 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1WwAAAU4"]
[Thu Sep 17 15:05:47.067931 2026] [security2:error] [pid 955873:tid 956104] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1XAAAAW8"]
[Thu Sep 17 15:05:47.117532 2026] [security2:error] [pid 955873:tid 956097] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1WgAAAWg"]
[Thu Sep 17 15:05:47.117554 2026] [security2:error] [pid 955873:tid 956097] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1WgAAAWg"]
[Thu Sep 17 15:05:47.150994 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/"] [unique_id "aqxWKxFTPRVSLOsRVhr1XgAAAXU"]
[Thu Sep 17 15:05:47.151253 2026] [security2:error] [pid 955873:tid 956128] [client 74.7.230.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rallyspin.com"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00gABhz0"]
[Thu Sep 17 15:05:47.204182 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/php/"] [unique_id "aqxWKhFTPRVSLOsRVhr1VwAAAYQ"]
[Thu Sep 17 15:05:47.221869 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1XwAAAR4"]
[Thu Sep 17 15:05:47.264791 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1YwAAAXc"]
[Thu Sep 17 15:05:47.320401 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:56676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKxFTPRVSLOsRVhr1ZAAAAVs"]
[Thu Sep 17 15:05:47.354028 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.129.237:44608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1aAAAAXk"]
[Thu Sep 17 15:05:47.412983 2026] [autoindex:error] [pid 955873:tid 956004] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:47.413697 2026] [security2:error] [pid 955873:tid 956004] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/css/"] [unique_id "aqxWKxFTPRVSLOsRVhr1aQAAAQs"]
[Thu Sep 17 15:05:47.422923 2026] [security2:error] [pid 955873:tid 956118] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1bQAAAX0"]
[Thu Sep 17 15:05:47.540732 2026] [security2:error] [pid 955873:tid 956044] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1cgAAATM"]
[Thu Sep 17 15:05:47.586736 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1dgAAAQ4"]
[Thu Sep 17 15:05:47.653224 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1cQAAAW4"]
[Thu Sep 17 15:05:47.653249 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1cQAAAW4"]
[Thu Sep 17 15:05:47.806725 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1eAAAARg"]
[Thu Sep 17 15:05:47.806751 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1eAAAARg"]
[Thu Sep 17 15:05:47.817740 2026] [security2:error] [pid 955873:tid 956033] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1fQAAASg"]
[Thu Sep 17 15:05:47.824321 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/Candidate.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1fgAAATE"]
[Thu Sep 17 15:05:47.824402 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/Candidate.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1fgAAATE"]
[Thu Sep 17 15:05:47.827007 2026] [security2:error] [pid 955873:tid 956048] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxWKxFTPRVSLOsRVhr1cwAAATc"]
[Thu Sep 17 15:05:47.873587 2026] [security2:error] [pid 955873:tid 956072] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1gQAAAU8"]
[Thu Sep 17 15:05:48.017305 2026] [autoindex:error] [pid 955873:tid 956117] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:48.017743 2026] [security2:error] [pid 955873:tid 956117] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLBFTPRVSLOsRVhr1hgAAAXw"]
[Thu Sep 17 15:05:48.023626 2026] [security2:error] [pid 955873:tid 956036] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/cache/"] [unique_id "aqxWKxFTPRVSLOsRVhr1hAAAASs"]
[Thu Sep 17 15:05:48.053920 2026] [security2:error] [pid 955873:tid 956068] [client 34.166.129.237:44612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1hwAAAUs"]
[Thu Sep 17 15:05:48.091497 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1jgAAASk"]
[Thu Sep 17 15:05:48.107670 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/GenerativeAiResult.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1jwAAAUU"]
[Thu Sep 17 15:05:48.107750 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:56688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/GenerativeAiResult.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1jwAAAUU"]
[Thu Sep 17 15:05:48.150981 2026] [security2:error] [pid 955873:tid 956077] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1kgAAAVQ"]
[Thu Sep 17 15:05:48.170735 2026] [security2:error] [pid 955873:tid 956012] [client 216.73.163.59:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1kAAAARM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:48.226812 2026] [autoindex:error] [pid 955873:tid 956130] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:48.227260 2026] [security2:error] [pid 955873:tid 956130] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/maint/"] [unique_id "aqxWLBFTPRVSLOsRVhr1kwAAAYk"]
[Thu Sep 17 15:05:48.368772 2026] [security2:error] [pid 955873:tid 956079] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1mAAAAVY"]
[Thu Sep 17 15:05:48.392755 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/TokenUsage.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1mwAAAYA"]
[Thu Sep 17 15:05:48.392831 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:56702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/TokenUsage.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1mwAAAYA"]
[Thu Sep 17 15:05:48.468428 2026] [security2:error] [pid 955873:tid 956010] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1nQAAARE"]
[Thu Sep 17 15:05:48.470582 2026] [security2:error] [pid 955873:tid 956069] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1ngAAAUw"]
[Thu Sep 17 15:05:48.522067 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1nAAAASc"]
[Thu Sep 17 15:05:48.522086 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1nAAAASc"]
[Thu Sep 17 15:05:48.551738 2026] [security2:error] [pid 955873:tid 956092] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxWLBFTPRVSLOsRVhr1mQAAAWM"]
[Thu Sep 17 15:05:48.623928 2026] [security2:error] [pid 955873:tid 956053] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1ogAAATw"]
[Thu Sep 17 15:05:48.689694 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/"] [unique_id "aqxWLBFTPRVSLOsRVhr1pwAAAWA"]
[Thu Sep 17 15:05:48.717515 2026] [security2:error] [pid 955873:tid 956115] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1qAAAAXo"]
[Thu Sep 17 15:05:48.744975 2026] [security2:error] [pid 955873:tid 956123] [client 34.166.129.237:44624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1qQAAAYI"]
[Thu Sep 17 15:05:48.786698 2026] [autoindex:error] [pid 955873:tid 956029] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:48.787140 2026] [security2:error] [pid 955873:tid 956029] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLBFTPRVSLOsRVhr1rAAAASQ"]
[Thu Sep 17 15:05:48.788148 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1rQAAAWg"]
[Thu Sep 17 15:05:48.794848 2026] [security2:error] [pid 955873:tid 956071] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/assets/"] [unique_id "aqxWLBFTPRVSLOsRVhr1qgAAAU4"]
[Thu Sep 17 15:05:48.842488 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/"] [unique_id "aqxWLBFTPRVSLOsRVhr1sAAAAYc"]
[Thu Sep 17 15:05:48.943049 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1tgAAAR4"]
[Thu Sep 17 15:05:49.006652 2026] [autoindex:error] [pid 955873:tid 956047] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.007144 2026] [security2:error] [pid 955873:tid 956047] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLBFTPRVSLOsRVhr1uQAAATY"]
[Thu Sep 17 15:05:49.009110 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxWLBFTPRVSLOsRVhr1twAAAXc"]
[Thu Sep 17 15:05:49.013821 2026] [security2:error] [pid 955873:tid 956028] [client 4.240.114.86:55860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-login.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1ugAAASM"], referer: binance.com
[Thu Sep 17 15:05:49.081628 2026] [security2:error] [pid 955873:tid 956085] [client 45.146.54.112:40837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1vgAAAVw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:49.103579 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWLRFTPRVSLOsRVhr1wAAAAQs"]
[Thu Sep 17 15:05:49.122506 2026] [security2:error] [pid 955873:tid 956061] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr1wgAAAUQ"]
[Thu Sep 17 15:05:49.303431 2026] [autoindex:error] [pid 955873:tid 956040] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.303911 2026] [security2:error] [pid 955873:tid 956040] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLRFTPRVSLOsRVhr1ygAAAS8"]
[Thu Sep 17 15:05:49.353149 2026] [security2:error] [pid 955873:tid 956103] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr1ywAAAW4"]
[Thu Sep 17 15:05:49.392088 2026] [security2:error] [pid 955873:tid 956025] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/block-supports/"] [unique_id "aqxWLRFTPRVSLOsRVhr1xAAAASA"]
[Thu Sep 17 15:05:49.442774 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1yQAAASE"]
[Thu Sep 17 15:05:49.442794 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1yQAAASE"]
[Thu Sep 17 15:05:49.449751 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWLRFTPRVSLOsRVhr10gAAAW0"]
[Thu Sep 17 15:05:49.553182 2026] [security2:error] [pid 955873:tid 956017] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr11AAAARg"]
[Thu Sep 17 15:05:49.556515 2026] [security2:error] [pid 955873:tid 956082] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr11QAAAVk"]
[Thu Sep 17 15:05:49.586454 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/FinishReasonEnum.php"] [unique_id "aqxWLRFTPRVSLOsRVhr12AAAATE"]
[Thu Sep 17 15:05:49.586565 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/FinishReasonEnum.php"] [unique_id "aqxWLRFTPRVSLOsRVhr12AAAATE"]
[Thu Sep 17 15:05:49.617316 2026] [autoindex:error] [pid 955873:tid 956080] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.618065 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLRFTPRVSLOsRVhr12QAAAVc"]
[Thu Sep 17 15:05:49.634905 2026] [security2:error] [pid 955873:tid 956033] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/html-api/"] [unique_id "aqxWLRFTPRVSLOsRVhr11gAAASg"]
[Thu Sep 17 15:05:49.696413 2026] [security2:error] [pid 955873:tid 956117] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr14AAAAXw"]
[Thu Sep 17 15:05:49.809230 2026] [autoindex:error] [pid 955873:tid 956068] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.809744 2026] [security2:error] [pid 955873:tid 956068] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLRFTPRVSLOsRVhr14wAAAUs"]
[Thu Sep 17 15:05:49.811682 2026] [security2:error] [pid 955873:tid 956070] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/js/"] [unique_id "aqxWLRFTPRVSLOsRVhr14QAAAU0"]
[Thu Sep 17 15:05:49.835750 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr15AAAAWs"]
[Thu Sep 17 15:05:49.844253 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWLRFTPRVSLOsRVhr15QAAATk"]
[Thu Sep 17 15:05:49.871423 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/"] [unique_id "aqxWLRFTPRVSLOsRVhr15gAAARM"]
[Thu Sep 17 15:05:49.935205 2026] [security2:error] [pid 955873:tid 956058] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr16QAAAUE"]
[Thu Sep 17 15:05:50.001999 2026] [security2:error] [pid 955873:tid 956086] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWLhFTPRVSLOsRVhr17gAAAV0"]
[Thu Sep 17 15:05:50.018675 2026] [autoindex:error] [pid 955873:tid 956116] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:50.019155 2026] [security2:error] [pid 955873:tid 956116] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLhFTPRVSLOsRVhr17wAAAXs"]
[Thu Sep 17 15:05:50.039282 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/"] [unique_id "aqxWLhFTPRVSLOsRVhr18AAAAVY"]
[Thu Sep 17 15:05:50.107184 2026] [security2:error] [pid 955873:tid 956091] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/php-compat/"] [unique_id "aqxWLRFTPRVSLOsRVhr17AAAAWI"]
[Thu Sep 17 15:05:50.114107 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr18wAAAWU"]
[Thu Sep 17 15:05:50.147334 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.129.237:44640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWLhFTPRVSLOsRVhr19gAAAVo"]
[Thu Sep 17 15:05:50.171269 2026] [security2:error] [pid 955873:tid 956027] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr1-gAAASI"]
[Thu Sep 17 15:05:50.198460 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/wp-includes/php-ai-client/src/"] [unique_id "aqxWLhFTPRVSLOsRVhr1_AAAAWA"]
[Thu Sep 17 15:05:50.349346 2026] [autoindex:error] [pid 955873:tid 956029] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:50.349842 2026] [security2:error] [pid 955873:tid 956029] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLhFTPRVSLOsRVhr2AQAAASQ"]
[Thu Sep 17 15:05:50.351997 2026] [security2:error] [pid 955873:tid 956096] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxWLhFTPRVSLOsRVhr1_wAAAWc"]
[Thu Sep 17 15:05:50.356947 2026] [security2:error] [pid 955873:tid 956104] [client 20.244.34.24:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2AwAAAW8"], referer: binance.com
[Thu Sep 17 15:05:50.361796 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWLhFTPRVSLOsRVhr2BAAAAU4"]
[Thu Sep 17 15:05:50.390130 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2BQAAAQw"]
[Thu Sep 17 15:05:50.395316 2026] [security2:error] [pid 955873:tid 956021] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2BgAAARw"]
[Thu Sep 17 15:05:50.532225 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2AgAAAWg"]
[Thu Sep 17 15:05:50.532250 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2AgAAAWg"]
[Thu Sep 17 15:05:50.606408 2026] [security2:error] [pid 955873:tid 956108] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2DAAAAXM"]
[Thu Sep 17 15:05:50.660315 2026] [security2:error] [pid 955873:tid 956055] [client 162.241.226.11:17456] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2DwAAAT4"]
[Thu Sep 17 15:05:50.665390 2026] [autoindex:error] [pid 955873:tid 956084] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:50.666090 2026] [security2:error] [pid 955873:tid 956084] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLhFTPRVSLOsRVhr2EgAAAVs"]
[Thu Sep 17 15:05:50.670555 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2EwAAAXQ"]
[Thu Sep 17 15:05:50.676513 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/"] [unique_id "aqxWLhFTPRVSLOsRVhr2FAAAAWk"]
[Thu Sep 17 15:05:50.710007 2026] [security2:error] [pid 955873:tid 956124] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/pomo/"] [unique_id "aqxWLhFTPRVSLOsRVhr2DQAAAYM"]
[Thu Sep 17 15:05:50.846087 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/"] [unique_id "aqxWLhFTPRVSLOsRVhr2GgAAAV8"]
[Thu Sep 17 15:05:50.861732 2026] [security2:error] [pid 955873:tid 956106] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2HQAAAXE"]
[Thu Sep 17 15:05:50.947391 2026] [security2:error] [pid 955873:tid 956026] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2JQAAASE"]
[Thu Sep 17 15:05:50.989202 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/wp-includes/php-ai-client/src/Tools/"] [unique_id "aqxWLhFTPRVSLOsRVhr2JgAAARk"]
[Thu Sep 17 15:05:51.056711 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2KAAAAYY"]
[Thu Sep 17 15:05:51.142292 2026] [security2:error] [pid 955873:tid 956066] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2JwAAAUk"]
[Thu Sep 17 15:05:51.142314 2026] [security2:error] [pid 955873:tid 956066] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2JwAAAUk"]
[Thu Sep 17 15:05:51.179368 2026] [security2:error] [pid 955873:tid 956016] [client 34.166.129.237:44656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/php-info.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2LQAAARc"]
[Thu Sep 17 15:05:51.226628 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2MAAAAWw"]
[Thu Sep 17 15:05:51.240092 2026] [security2:error] [pid 955873:tid 956076] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2MQAAAVM"]
[Thu Sep 17 15:05:51.291712 2026] [security2:error] [pid 955873:tid 956044] [client 154.190.208.131:41595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2NAAAATM"]
[Thu Sep 17 15:05:51.291856 2026] [security2:error] [pid 955873:tid 956044] [client 154.190.208.131:41595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2NAAAATM"]
[Thu Sep 17 15:05:51.300568 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/random_compat/"] [unique_id "aqxWLhFTPRVSLOsRVhr2IQAAATo"]
[Thu Sep 17 15:05:51.330775 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2LAAAAX4"]
[Thu Sep 17 15:05:51.330794 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2LAAAAX4"]
[Thu Sep 17 15:05:51.472208 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionCall.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2PAAAAUE"]
[Thu Sep 17 15:05:51.472292 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionCall.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2PAAAAUE"]
[Thu Sep 17 15:05:51.494980 2026] [security2:error] [pid 955873:tid 956074] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2PwAAAVE"]
[Thu Sep 17 15:05:51.503443 2026] [security2:error] [pid 955873:tid 956121] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2QQAAAYA"]
[Thu Sep 17 15:05:51.510846 2026] [autoindex:error] [pid 955873:tid 956081] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:51.511294 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLxFTPRVSLOsRVhr2QAAAAVg"]
[Thu Sep 17 15:05:51.512914 2026] [security2:error] [pid 955873:tid 956113] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/rest-api/"] [unique_id "aqxWLxFTPRVSLOsRVhr2PQAAAXg"]
[Thu Sep 17 15:05:51.546527 2026] [security2:error] [pid 955873:tid 956107] [client 45.169.98.18:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2RQAAAXI"]
[Thu Sep 17 15:05:51.546608 2026] [security2:error] [pid 955873:tid 956107] [client 45.169.98.18:53256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2RQAAAXI"]
[Thu Sep 17 15:05:51.766540 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionDeclaration.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2UwAAAYc"]
[Thu Sep 17 15:05:51.766651 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionDeclaration.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2UwAAAYc"]
[Thu Sep 17 15:05:51.782068 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2VAAAAQw"]
[Thu Sep 17 15:05:51.794860 2026] [security2:error] [pid 955873:tid 956019] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2VQAAARo"]
[Thu Sep 17 15:05:51.796543 2026] [security2:error] [pid 955873:tid 956087] [client 216.73.163.75:43469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2SwAAAV4"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:51.876979 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.129.237:44662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpversion.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2VgAAAXo"]
[Thu Sep 17 15:05:51.989442 2026] [security2:error] [pid 955873:tid 956108] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2WgAAAXM"]
[Thu Sep 17 15:05:52.059689 2026] [security2:error] [pid 955873:tid 956055] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2WwAAAT4"]
[Thu Sep 17 15:05:52.076869 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:49560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionResponse.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2XgAAAVs"]
[Thu Sep 17 15:05:52.076959 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:49560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionResponse.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2XgAAAVs"]
[Thu Sep 17 15:05:52.104777 2026] [autoindex:error] [pid 955873:tid 956043] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.105270 2026] [security2:error] [pid 955873:tid 956043] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2XwAAATI"]
[Thu Sep 17 15:05:52.106548 2026] [security2:error] [pid 955873:tid 956028] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxWMBFTPRVSLOsRVhr2XAAAASM"]
[Thu Sep 17 15:05:52.195198 2026] [security2:error] [pid 955873:tid 956046] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2YwAAATU"]
[Thu Sep 17 15:05:52.336870 2026] [security2:error] [pid 955873:tid 956106] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2ZgAAAXE"]
[Thu Sep 17 15:05:52.379939 2026] [security2:error] [pid 955873:tid 956118] [client 194.163.128.162:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2bAAAAX0"], referer: binance.com
[Thu Sep 17 15:05:52.380065 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/WebSearch.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2bQAAAW4"]
[Thu Sep 17 15:05:52.380128 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:49566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/WebSearch.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2bQAAAW4"]
[Thu Sep 17 15:05:52.403089 2026] [autoindex:error] [pid 955873:tid 956031] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.403528 2026] [security2:error] [pid 955873:tid 956031] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2bwAAASY"]
[Thu Sep 17 15:05:52.436585 2026] [security2:error] [pid 955873:tid 956085] [client 115.244.164.14:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2cAAAAVw"]
[Thu Sep 17 15:05:52.436645 2026] [security2:error] [pid 955873:tid 956085] [client 115.244.164.14:62616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2cAAAAVw"]
[Thu Sep 17 15:05:52.451629 2026] [security2:error] [pid 955873:tid 956026] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxWMBFTPRVSLOsRVhr2ZwAAASE"]
[Thu Sep 17 15:05:52.458680 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2cQAAAQ4"]
[Thu Sep 17 15:05:52.581124 2026] [security2:error] [pid 955873:tid 956025] [client 34.166.129.237:35462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/_phpinfo.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2dwAAASA"]
[Thu Sep 17 15:05:52.613730 2026] [security2:error] [pid 955873:tid 956082] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2eAAAAVk"]
[Thu Sep 17 15:05:52.664706 2026] [security2:error] [pid 955873:tid 956016] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2ewAAARc"]
[Thu Sep 17 15:05:52.664911 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWMBFTPRVSLOsRVhr2fAAAAT0"]
[Thu Sep 17 15:05:52.665277 2026] [fcgid:warn] [pid 955873:tid 956099] (70014)End of file found: [client 66.132.186.206:1892] mod_fcgid: can't get data from http client
[Thu Sep 17 15:05:52.667876 2026] [security2:error] [pid 955873:tid 956088] [client 186.105.232.15:49261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2fgAAAV8"]
[Thu Sep 17 15:05:52.669829 2026] [security2:error] [pid 955873:tid 956088] [client 186.105.232.15:49261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2fgAAAV8"]
[Thu Sep 17 15:05:52.704467 2026] [autoindex:error] [pid 955873:tid 956076] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.704922 2026] [security2:error] [pid 955873:tid 956076] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2gwAAAVM"]
[Thu Sep 17 15:05:52.734260 2026] [security2:error] [pid 955873:tid 956066] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/style-engine/"] [unique_id "aqxWMBFTPRVSLOsRVhr2eQAAAUk"]
[Thu Sep 17 15:05:52.741861 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWMBFTPRVSLOsRVhr2hQAAAXY"]
[Thu Sep 17 15:05:52.860612 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWMBFTPRVSLOsRVhr2igAAAQs"]
[Thu Sep 17 15:05:52.890788 2026] [security2:error] [pid 955873:tid 956105] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2iwAAAXA"]
[Thu Sep 17 15:05:52.900207 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWMBFTPRVSLOsRVhr2jgAAARI"]
[Thu Sep 17 15:05:52.923151 2026] [autoindex:error] [pid 955873:tid 956100] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.923645 2026] [security2:error] [pid 955873:tid 956100] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2jwAAAWs"]
[Thu Sep 17 15:05:52.934280 2026] [security2:error] [pid 955873:tid 956122] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2kAAAAYE"]
[Thu Sep 17 15:05:52.982258 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxWMBFTPRVSLOsRVhr2jAAAAXc"]
[Thu Sep 17 15:05:53.028616 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/wp-includes/php-ai-client/"] [unique_id "aqxWMRFTPRVSLOsRVhr2kQAAARM"]
[Thu Sep 17 15:05:53.158792 2026] [security2:error] [pid 955873:tid 956121] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2lwAAAYA"]
[Thu Sep 17 15:05:53.167795 2026] [security2:error] [pid 955873:tid 956081] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2mAAAAVg"]
[Thu Sep 17 15:05:53.247440 2026] [autoindex:error] [pid 955873:tid 956107] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:53.248132 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMRFTPRVSLOsRVhr2nAAAAXI"]
[Thu Sep 17 15:05:53.263184 2026] [security2:error] [pid 955873:tid 956120] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/widgets/"] [unique_id "aqxWMRFTPRVSLOsRVhr2mgAAAX8"]
[Thu Sep 17 15:05:53.268519 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.129.237:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2ogAAATk"]
[Thu Sep 17 15:05:53.336416 2026] [security2:error] [pid 955873:tid 956053] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2pQAAATw"]
[Thu Sep 17 15:05:53.360508 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2mQAAAV0"]
[Thu Sep 17 15:05:53.360528 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2mQAAAV0"]
[Thu Sep 17 15:05:53.469214 2026] [security2:error] [pid 955873:tid 956013] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2qAAAARQ"]
[Thu Sep 17 15:05:53.473677 2026] [autoindex:error] [pid 955873:tid 956030] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:53.474128 2026] [security2:error] [pid 955873:tid 956030] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxWMRFTPRVSLOsRVhr2pwAAASU"]
[Thu Sep 17 15:05:53.506119 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/"] [unique_id "aqxWMRFTPRVSLOsRVhr2rAAAAWg"]
[Thu Sep 17 15:05:53.509568 2026] [security2:error] [pid 955873:tid 956096] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2rQAAAWc"]
[Thu Sep 17 15:05:53.669275 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/"] [unique_id "aqxWMRFTPRVSLOsRVhr2rgAAAUg"]
[Thu Sep 17 15:05:53.702810 2026] [autoindex:error] [pid 955873:tid 956063] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:53.703286 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/css/colors/"] [unique_id "aqxWMRFTPRVSLOsRVhr2rwAAAUY"]
[Thu Sep 17 15:05:53.704309 2026] [security2:error] [pid 955873:tid 956055] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2swAAAT4"]
[Thu Sep 17 15:05:53.746983 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2tAAAAXQ"]
[Thu Sep 17 15:05:53.823959 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWMRFTPRVSLOsRVhr2twAAARE"]
[Thu Sep 17 15:05:53.924111 2026] [security2:error] [pid 955873:tid 956056] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2vwAAAT8"]
[Thu Sep 17 15:05:53.974112 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.129.237:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/server-info.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2wQAAATI"]
[Thu Sep 17 15:05:54.024382 2026] [security2:error] [pid 955873:tid 956102] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr2xAAAAW0"]
[Thu Sep 17 15:05:54.079227 2026] [security2:error] [pid 955873:tid 956103] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2vgAAAW4"]
[Thu Sep 17 15:05:54.079248 2026] [security2:error] [pid 955873:tid 956103] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2vgAAAW4"]
[Thu Sep 17 15:05:54.100179 2026] [security2:error] [pid 955873:tid 956114] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/images/slider/"] [unique_id "aqxWMRFTPRVSLOsRVhr2vAAAAXk"]
[Thu Sep 17 15:05:54.113267 2026] [security2:error] [pid 955873:tid 956118] [client 216.73.163.58:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWMhFTPRVSLOsRVhr2yQAAAX0"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:54.182376 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2wAAAASY"]
[Thu Sep 17 15:05:54.182402 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2wAAAASY"]
[Thu Sep 17 15:05:54.223803 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr2ygAAAYY"]
[Thu Sep 17 15:05:54.301335 2026] [security2:error] [pid 955873:tid 956061] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr20gAAAUQ"]
[Thu Sep 17 15:05:54.324902 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWMhFTPRVSLOsRVhr21AAAAVM"]
[Thu Sep 17 15:05:54.418885 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr21gAAAWE"]
[Thu Sep 17 15:05:54.467564 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr22QAAARI"]
[Thu Sep 17 15:05:54.495471 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWMhFTPRVSLOsRVhr22AAAAXA"]
[Thu Sep 17 15:05:54.548307 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr21QAAAXY"]
[Thu Sep 17 15:05:54.548330 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr21QAAAXY"]
[Thu Sep 17 15:05:54.572099 2026] [security2:error] [pid 955873:tid 956100] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr22wAAAWs"]
[Thu Sep 17 15:05:54.604865 2026] [security2:error] [pid 955873:tid 956119] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr23gAAAX4"]
[Thu Sep 17 15:05:54.624991 2026] [security2:error] [pid 955873:tid 956016] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxWMhFTPRVSLOsRVhr2zgAAARc"]
[Thu Sep 17 15:05:54.631271 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr23wAAAVQ"]
[Thu Sep 17 15:05:54.635379 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/wp-includes/php-ai-client/third-party/Http/"] [unique_id "aqxWMhFTPRVSLOsRVhr24AAAAU8"]
[Thu Sep 17 15:05:54.663514 2026] [security2:error] [pid 955873:tid 956068] [client 34.166.129.237:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/server-status.php"] [unique_id "aqxWMhFTPRVSLOsRVhr24wAAAUs"]
[Thu Sep 17 15:05:54.726113 2026] [security2:error] [pid 955873:tid 956004] [client 216.73.163.67:22165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr25QAAAQs"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:54.789850 2026] [security2:error] [pid 955873:tid 956116] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr26QAAAXs"]
[Thu Sep 17 15:05:54.829439 2026] [security2:error] [pid 955873:tid 956081] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr26gAAAVg"]
[Thu Sep 17 15:05:54.880739 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr27AAAASk"]
[Thu Sep 17 15:05:54.956514 2026] [security2:error] [pid 955873:tid 956117] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr27wAAAXw"]
[Thu Sep 17 15:05:54.980734 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr26AAAARM"]
[Thu Sep 17 15:05:54.980758 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr26AAAARM"]
[Thu Sep 17 15:05:55.060686 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr28QAAATk"]
[Thu Sep 17 15:05:55.092488 2026] [security2:error] [pid 955873:tid 956089] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr28AAAAWA"]
[Thu Sep 17 15:05:55.092507 2026] [security2:error] [pid 955873:tid 956089] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr28AAAAWA"]
[Thu Sep 17 15:05:55.134707 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/ClassDiscovery.php"] [unique_id "aqxWMxFTPRVSLOsRVhr29AAAASQ"]
[Thu Sep 17 15:05:55.134798 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/ClassDiscovery.php"] [unique_id "aqxWMxFTPRVSLOsRVhr29AAAASQ"]
[Thu Sep 17 15:05:55.135303 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr28gAAAVI"]
[Thu Sep 17 15:05:55.160763 2026] [security2:error] [pid 955873:tid 956086] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr29gAAAV0"]
[Thu Sep 17 15:05:55.259834 2026] [security2:error] [pid 955873:tid 956083] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr2-gAAAVo"]
[Thu Sep 17 15:05:55.288903 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr2_AAAASI"]
[Thu Sep 17 15:05:55.374405 2026] [security2:error] [pid 955873:tid 956096] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/sites/default/files/"] [unique_id "aqxWMhFTPRVSLOsRVhr27QAAAWU"]
[Thu Sep 17 15:05:55.421528 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3AAAAATA"]
[Thu Sep 17 15:05:55.421629 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:49572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3AAAAATA"]
[Thu Sep 17 15:05:55.438642 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3AwAAAUY"]
[Thu Sep 17 15:05:55.457558 2026] [security2:error] [pid 955873:tid 956028] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3BwAAASM"]
[Thu Sep 17 15:05:55.642070 2026] [security2:error] [pid 955873:tid 956060] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3CgAAAUM"]
[Thu Sep 17 15:05:55.655503 2026] [security2:error] [pid 955873:tid 956102] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3CwAAAW0"]
[Thu Sep 17 15:05:55.710102 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:49582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/"] [unique_id "aqxWMxFTPRVSLOsRVhr3EwAAAS8"]
[Thu Sep 17 15:05:55.714860 2026] [security2:error] [pid 955873:tid 956015] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3FQAAARY"]
[Thu Sep 17 15:05:55.811907 2026] [security2:error] [pid 955873:tid 956088] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3GgAAAV8"]
[Thu Sep 17 15:05:55.825604 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3EgAAARg"]
[Thu Sep 17 15:05:55.825627 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3EgAAARg"]
[Thu Sep 17 15:05:55.842368 2026] [security2:error] [pid 955873:tid 956007] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxWMxFTPRVSLOsRVhr3DgAAAQ4"]
[Thu Sep 17 15:05:55.875157 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/"] [unique_id "aqxWMxFTPRVSLOsRVhr3GwAAASg"]
[Thu Sep 17 15:05:55.926645 2026] [security2:error] [pid 955873:tid 956076] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3HAAAAVM"]
[Thu Sep 17 15:05:55.950707 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWMxFTPRVSLOsRVhr3HQAAATM"]
[Thu Sep 17 15:05:55.965768 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3HgAAASE"]
[Thu Sep 17 15:05:55.990490 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3HwAAARs"]
[Thu Sep 17 15:05:56.019900 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:49582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWNBFTPRVSLOsRVhr3IQAAARk"]
[Thu Sep 17 15:05:56.122211 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3JQAAARI"]
[Thu Sep 17 15:05:56.170909 2026] [security2:error] [pid 955873:tid 956111] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3JwAAAXY"]
[Thu Sep 17 15:05:56.184813 2026] [security2:error] [pid 955873:tid 956090] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JAAAAWE"]
[Thu Sep 17 15:05:56.184836 2026] [security2:error] [pid 955873:tid 956090] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JAAAAWE"]
[Thu Sep 17 15:05:56.230642 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxWNBFTPRVSLOsRVhr3IAAAAVc"]
[Thu Sep 17 15:05:56.269805 2026] [security2:error] [pid 955873:tid 956119] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3KgAAAX4"]
[Thu Sep 17 15:05:56.279899 2026] [security2:error] [pid 955873:tid 956130] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3KwAAAYk"]
[Thu Sep 17 15:05:56.354614 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JgAAAXA"]
[Thu Sep 17 15:05:56.354638 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JgAAAXA"]
[Thu Sep 17 15:05:56.417248 2026] [security2:error] [pid 955873:tid 956006] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3MAAAAQ0"]
[Thu Sep 17 15:05:56.433123 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3MgAAATc"]
[Thu Sep 17 15:05:56.520225 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:49582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/ClassInstantiationFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3NAAAAUU"]
[Thu Sep 17 15:05:56.520354 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:49582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/ClassInstantiationFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3NAAAAUU"]
[Thu Sep 17 15:05:56.542573 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3MQAAAXc"]
[Thu Sep 17 15:05:56.542593 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3MQAAAXc"]
[Thu Sep 17 15:05:56.547680 2026] [security2:error] [pid 955873:tid 956074] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3NQAAAVE"]
[Thu Sep 17 15:05:56.584733 2026] [security2:error] [pid 955873:tid 956116] [client 47.39.232.109:59653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3MwABe30"], referer: https://www.endless-chronicles.com/cdbbec328e5cc574586e0b446e67b334.ogg
[Thu Sep 17 15:05:56.590892 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3NgAAAYA"]
[Thu Sep 17 15:05:56.599751 2026] [security2:error] [pid 955873:tid 956072] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/components/"] [unique_id "aqxWNBFTPRVSLOsRVhr3LgAAAU8"]
[Thu Sep 17 15:05:56.652876 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.129.237:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3NwAAATQ"]
[Thu Sep 17 15:05:56.744523 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3OgAAAWI"]
[Thu Sep 17 15:05:56.788216 2026] [security2:error] [pid 955873:tid 956092] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3QQAAAWM"]
[Thu Sep 17 15:05:56.808729 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/DiscoveryFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3QgAAAWA"]
[Thu Sep 17 15:05:56.808858 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:49592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/DiscoveryFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3QgAAAWA"]
[Thu Sep 17 15:05:56.824055 2026] [security2:error] [pid 955873:tid 956029] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3RAAAASQ"]
[Thu Sep 17 15:05:56.903127 2026] [security2:error] [pid 955873:tid 956086] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3RQAAAV0"]
[Thu Sep 17 15:05:56.906299 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3PgAAAYQ"]
[Thu Sep 17 15:05:56.906328 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3PgAAAYQ"]
[Thu Sep 17 15:05:56.939944 2026] [security2:error] [pid 955873:tid 956012] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/uploads/images/"] [unique_id "aqxWNBFTPRVSLOsRVhr3PAAAARM"]
[Thu Sep 17 15:05:57.056618 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3RwAAASI"]
[Thu Sep 17 15:05:57.098457 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NoCandidateFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3SQAAAV4"]
[Thu Sep 17 15:05:57.098545 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:49608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NoCandidateFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3SQAAAV4"]
[Thu Sep 17 15:05:57.102683 2026] [security2:error] [pid 955873:tid 956019] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3SwAAARo"]
[Thu Sep 17 15:05:57.216583 2026] [security2:error] [pid 955873:tid 956101] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3TQAAAWw"]
[Thu Sep 17 15:05:57.240042 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3TAAAAUA"]
[Thu Sep 17 15:05:57.240066 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3TAAAAUA"]
[Thu Sep 17 15:05:57.253258 2026] [security2:error] [pid 955873:tid 956096] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxWNRFTPRVSLOsRVhr3SAAAAWc"]
[Thu Sep 17 15:05:57.358759 2026] [security2:error] [pid 955873:tid 956021] [client 34.166.129.237:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3UgAAARw"]
[Thu Sep 17 15:05:57.371554 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3UwAAASM"]
[Thu Sep 17 15:05:57.376060 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NotFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3VAAAAYc"]
[Thu Sep 17 15:05:57.376142 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NotFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3VAAAAYc"]
[Thu Sep 17 15:05:57.379137 2026] [security2:error] [pid 955873:tid 956032] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3VQAAASc"]
[Thu Sep 17 15:05:57.446799 2026] [autoindex:error] [pid 955873:tid 956108] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:57.447256 2026] [security2:error] [pid 955873:tid 956108] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWNRFTPRVSLOsRVhr3WAAAAXM"]
[Thu Sep 17 15:05:57.487281 2026] [security2:error] [pid 955873:tid 956005] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/fonts/"] [unique_id "aqxWNRFTPRVSLOsRVhr3VgAAAQw"]
[Thu Sep 17 15:05:57.526580 2026] [security2:error] [pid 955873:tid 956053] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3WQAAATw"]
[Thu Sep 17 15:05:57.569900 2026] [security2:error] [pid 955873:tid 956047] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3WgAAATY"]
[Thu Sep 17 15:05:57.658240 2026] [security2:error] [pid 955873:tid 956120] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3XAAAAX8"]
[Thu Sep 17 15:05:57.664524 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:49628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/PuliUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3XwAAAUM"]
[Thu Sep 17 15:05:57.664596 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:49628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/PuliUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3XwAAAUM"]
[Thu Sep 17 15:05:57.685999 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3YQAAATU"]
[Thu Sep 17 15:05:57.733402 2026] [security2:error] [pid 955873:tid 956106] [client 185.55.149.49:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YgAAAXE"]
[Thu Sep 17 15:05:57.733486 2026] [security2:error] [pid 955873:tid 956106] [client 185.55.149.49:53358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YgAAAXE"]
[Thu Sep 17 15:05:57.810865 2026] [security2:error] [pid 955873:tid 956124] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YAAAAYM"]
[Thu Sep 17 15:05:57.810886 2026] [security2:error] [pid 955873:tid 956124] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YAAAAYM"]
[Thu Sep 17 15:05:57.836357 2026] [security2:error] [pid 955873:tid 956059] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxWNRFTPRVSLOsRVhr3XQAAAUI"]
[Thu Sep 17 15:05:57.839600 2026] [security2:error] [pid 955873:tid 956061] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3ZgAAAUQ"]
[Thu Sep 17 15:05:57.936643 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3aAAAAWk"]
[Thu Sep 17 15:05:57.959757 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/StrategyUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3aQAAAQ4"]
[Thu Sep 17 15:05:57.959862 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:49638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/StrategyUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3aQAAAQ4"]
[Thu Sep 17 15:05:57.993102 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3agAAAVk"]
[Thu Sep 17 15:05:58.065969 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.129.237:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3bgAAASY"]
[Thu Sep 17 15:05:58.148544 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3bwAAATM"]
[Thu Sep 17 15:05:58.149372 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3bQAAAR8"]
[Thu Sep 17 15:05:58.149388 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3bQAAAR8"]
[Thu Sep 17 15:05:58.214003 2026] [security2:error] [pid 955873:tid 956018] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3cQAAARk"]
[Thu Sep 17 15:05:58.215896 2026] [security2:error] [pid 955873:tid 956127] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxWNhFTPRVSLOsRVhr3awAAAYY"]
[Thu Sep 17 15:05:58.239829 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr17FactoryDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3cwAAARI"]
[Thu Sep 17 15:05:58.239931 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:49640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr17FactoryDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3cwAAARI"]
[Thu Sep 17 15:05:58.304095 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3eQAAASo"]
[Thu Sep 17 15:05:58.461632 2026] [security2:error] [pid 955873:tid 956066] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3fwAAAUk"]
[Thu Sep 17 15:05:58.462019 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3gAAAATc"]
[Thu Sep 17 15:05:58.493783 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3gQAAAU4"]
[Thu Sep 17 15:05:58.530442 2026] [security2:error] [pid 955873:tid 956006] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3fgAAAQ0"]
[Thu Sep 17 15:05:58.530461 2026] [security2:error] [pid 955873:tid 956006] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3fgAAAQ0"]
[Thu Sep 17 15:05:58.532182 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:49646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr18ClientDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3ggAAAQs"]
[Thu Sep 17 15:05:58.532260 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:49646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr18ClientDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3ggAAAQs"]
[Thu Sep 17 15:05:58.571733 2026] [security2:error] [pid 955873:tid 956062] [client 216.73.163.52:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3gwAAAUU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:58.572316 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wordpress/"] [unique_id "aqxWNhFTPRVSLOsRVhr3fAAAAXA"]
[Thu Sep 17 15:05:58.619489 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3hAAAAUE"]
[Thu Sep 17 15:05:58.712763 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3hgAAAXs"]
[Thu Sep 17 15:05:58.752849 2026] [security2:error] [pid 955873:tid 956073] [client 34.166.129.237:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3iQAAAVA"]
[Thu Sep 17 15:05:58.766551 2026] [security2:error] [pid 955873:tid 956072] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3igAAAU8"]
[Thu Sep 17 15:05:58.778314 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3iwAAATQ"]
[Thu Sep 17 15:05:58.824190 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/"] [unique_id "aqxWNhFTPRVSLOsRVhr3jAAAAWI"]
[Thu Sep 17 15:05:58.920474 2026] [security2:error] [pid 955873:tid 956126] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3jwAAAYU"]
[Thu Sep 17 15:05:58.934858 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3kAAAAWM"]
[Thu Sep 17 15:05:58.983757 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/"] [unique_id "aqxWNhFTPRVSLOsRVhr3kQAAAWA"]
[Thu Sep 17 15:05:59.044871 2026] [security2:error] [pid 955873:tid 956075] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3kgAAAVI"]
[Thu Sep 17 15:05:59.055563 2026] [security2:error] [pid 955873:tid 956074] [client 210.222.43.21:49199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3jgAAAVE"], referer: http://talent-in-borders.com/TEST
[Thu Sep 17 15:05:59.088279 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3lAAAAXI"]
[Thu Sep 17 15:05:59.111410 2026] [autoindex:error] [pid 955873:tid 956125] [client 139.28.219.68:41578] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:59.111922 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/images/"] [unique_id "aqxWNxFTPRVSLOsRVhr3kwAAAYQ"]
[Thu Sep 17 15:05:59.127016 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWNxFTPRVSLOsRVhr3lQAAAUo"]
[Thu Sep 17 15:05:59.224106 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3lgAAATk"]
[Thu Sep 17 15:05:59.241442 2026] [security2:error] [pid 955873:tid 956013] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3lwAAARQ"]
[Thu Sep 17 15:05:59.243623 2026] [security2:error] [pid 955873:tid 956025] [client 194.163.128.162:59809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3mAAAASA"], referer: binance.com
[Thu Sep 17 15:05:59.311906 2026] [autoindex:error] [pid 955873:tid 956030] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:59.312615 2026] [security2:error] [pid 955873:tid 956030] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWNxFTPRVSLOsRVhr3oAAAASU"]
[Thu Sep 17 15:05:59.314170 2026] [security2:error] [pid 955873:tid 956087] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxWNxFTPRVSLOsRVhr3nQAAAV4"]
[Thu Sep 17 15:05:59.328101 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3oQAAAUY"]
[Thu Sep 17 15:05:59.401163 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3owAAATI"]
[Thu Sep 17 15:05:59.438137 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3pQAAAWU"]
[Thu Sep 17 15:05:59.460670 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3nAAAASI"]
[Thu Sep 17 15:05:59.460694 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3nAAAASI"]
[Thu Sep 17 15:05:59.478605 2026] [security2:error] [pid 955873:tid 956021] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3qAAAARw"]
[Thu Sep 17 15:05:59.495821 2026] [security2:error] [pid 955873:tid 956028] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3qQAAASM"]
[Thu Sep 17 15:05:59.497644 2026] [security2:error] [pid 955873:tid 956052] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxWNxFTPRVSLOsRVhr3pgAAATs"]
[Thu Sep 17 15:05:59.556264 2026] [security2:error] [pid 955873:tid 956055] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3qgAAAT4"]
[Thu Sep 17 15:05:59.604754 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rAAAAUw"]
[Thu Sep 17 15:05:59.604823 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rAAAAUw"]
[Thu Sep 17 15:05:59.605286 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3qwAAAVU"]
[Thu Sep 17 15:05:59.682058 2026] [security2:error] [pid 955873:tid 956047] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3sAAAATY"]
[Thu Sep 17 15:05:59.709385 2026] [security2:error] [pid 955873:tid 956056] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3sQAAAT8"]
[Thu Sep 17 15:05:59.803583 2026] [security2:error] [pid 955873:tid 956053] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rwAAATw"]
[Thu Sep 17 15:05:59.803604 2026] [security2:error] [pid 955873:tid 956053] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rwAAATw"]
[Thu Sep 17 15:05:59.885439 2026] [security2:error] [pid 955873:tid 956104] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3twAAAW8"]
[Thu Sep 17 15:05:59.885466 2026] [security2:error] [pid 955873:tid 956061] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3uQAAAUQ"]
[Thu Sep 17 15:05:59.885465 2026] [security2:error] [pid 955873:tid 956088] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3uAAAAV8"]
[Thu Sep 17 15:05:59.885495 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonPsr17ClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3ugAAAUI"]
[Thu Sep 17 15:05:59.885558 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:57610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonPsr17ClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3ugAAAUI"]
[Thu Sep 17 15:05:59.948757 2026] [security2:error] [pid 955873:tid 956005] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/js/"] [unique_id "aqxWNxFTPRVSLOsRVhr3rQAAAQw"]
[Thu Sep 17 15:05:59.957606 2026] [security2:error] [pid 955873:tid 956032] [client 181.137.97.243:35936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "greenbrickbuilders.com"] [uri "/robots.txt"] [unique_id "aqxWNxFTPRVSLOsRVhr3uwAAASc"]
[Thu Sep 17 15:06:00.040250 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3vQAAAQ4"]
[Thu Sep 17 15:06:00.112631 2026] [security2:error] [pid 955873:tid 956102] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3wAAAAW0"]
[Thu Sep 17 15:06:00.137535 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.129.237:35524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWOBFTPRVSLOsRVhr3wgAAARg"]
[Thu Sep 17 15:06:00.160294 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/DiscoveryStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3xAAAASY"]
[Thu Sep 17 15:06:00.160399 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/DiscoveryStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3xAAAASY"]
[Thu Sep 17 15:06:00.162538 2026] [security2:error] [pid 955873:tid 956010] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3xQAAARE"]
[Thu Sep 17 15:06:00.194400 2026] [security2:error] [pid 955873:tid 956024] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3xgAAAR8"]
[Thu Sep 17 15:06:00.208525 2026] [security2:error] [pid 955873:tid 956008] [client 47.39.232.109:51255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3wwABDxI"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726025143&hideliu=1&hideminor=1&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:06:00.269894 2026] [security2:error] [pid 955873:tid 956082] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3wQAAAVk"]
[Thu Sep 17 15:06:00.269917 2026] [security2:error] [pid 955873:tid 956082] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3wQAAAVk"]
[Thu Sep 17 15:06:00.299802 2026] [security2:error] [pid 955873:tid 956011] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3yAAAARI"]
[Thu Sep 17 15:06:00.324980 2026] [security2:error] [pid 955873:tid 956076] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxWOBFTPRVSLOsRVhr3vgAAAVM"]
[Thu Sep 17 15:06:00.351505 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3ygAAASo"]
[Thu Sep 17 15:06:00.438219 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:57624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/PuliBetaStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr30QAAAXY"]
[Thu Sep 17 15:06:00.438321 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:57624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/PuliBetaStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr30QAAAXY"]
[Thu Sep 17 15:06:00.438955 2026] [security2:error] [pid 955873:tid 956070] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr30AAAAU0"]
[Thu Sep 17 15:06:00.460887 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr30wAAARs"]
[Thu Sep 17 15:06:00.487812 2026] [autoindex:error] [pid 955873:tid 955896] [remote 93.152.209.11:36278] AH01276: Cannot serve directory /home1/ykkcnqmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:00.508046 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr32gAAAU8"]
[Thu Sep 17 15:06:00.582421 2026] [security2:error] [pid 955873:tid 956071] [client 47.79.201.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr30gAAAU4"], referer: https://www.google.com/
[Thu Sep 17 15:06:00.635432 2026] [security2:error] [pid 955873:tid 956073] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr32QAAAVA"]
[Thu Sep 17 15:06:00.635459 2026] [security2:error] [pid 955873:tid 956073] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr32QAAAVA"]
[Thu Sep 17 15:06:00.642031 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxWOBFTPRVSLOsRVhr31wAAAUE"]
[Thu Sep 17 15:06:00.676634 2026] [security2:error] [pid 955873:tid 956067] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr33AAAAUo"]
[Thu Sep 17 15:06:00.716014 2026] [security2:error] [pid 955873:tid 956025] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr33QAAASA"]
[Thu Sep 17 15:06:00.725423 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/"] [unique_id "aqxWOBFTPRVSLOsRVhr33gAAASU"]
[Thu Sep 17 15:06:00.798309 2026] [authz_core:error] [pid 955873:tid 956026] [client 4.240.114.86:61816] AH01630: client denied by server configuration: /home2/loseyov0/public_html/staging-paltals/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:06:00.828340 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.129.237:35526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWOBFTPRVSLOsRVhr35gAAASQ"]
[Thu Sep 17 15:06:00.828644 2026] [security2:error] [pid 955873:tid 956043] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr35QAAATI"]
[Thu Sep 17 15:06:00.884279 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/"] [unique_id "aqxWOBFTPRVSLOsRVhr36AAAASI"]
[Thu Sep 17 15:06:00.934262 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:41578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr34wAAAUY"]
[Thu Sep 17 15:06:00.934288 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr34wAAAUY"]
[Thu Sep 17 15:06:00.977016 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr37AAAAR4"]
[Thu Sep 17 15:06:00.992637 2026] [security2:error] [pid 955873:tid 956069] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr37gAAAUw"]
[Thu Sep 17 15:06:01.025610 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWORFTPRVSLOsRVhr38AAAAVU"]
[Thu Sep 17 15:06:01.090883 2026] [security2:error] [pid 955873:tid 956084] [client 31.37.3.225:48884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr37QABWxo"]
[Thu Sep 17 15:06:01.132712 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWORFTPRVSLOsRVhr38wAAAX8"]
[Thu Sep 17 15:06:01.149703 2026] [security2:error] [pid 955873:tid 956060] [client 85.208.98.202:42871] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/js/email-subscribers-public.js"] [unique_id "aqxWORFTPRVSLOsRVhr39AAAAUM"]
[Thu Sep 17 15:06:01.160010 2026] [security2:error] [pid 955873:tid 956083] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWORFTPRVSLOsRVhr39QAAAVo"]
[Thu Sep 17 15:06:01.269915 2026] [security2:error] [pid 955873:tid 956081] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWORFTPRVSLOsRVhr39wAAAVg"]
[Thu Sep 17 15:06:01.286824 2026] [security2:error] [pid 955873:tid 956106] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWORFTPRVSLOsRVhr3-AAAAXE"]
[Thu Sep 17 15:06:01.301811 2026] [security2:error] [pid 955873:tid 956110] [client 20.244.34.24:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxWORFTPRVSLOsRVhr3-QAAAXU"], referer: binance.com
[Thu Sep 17 15:06:01.358518 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr39gAAATU"]
[Thu Sep 17 15:06:01.358543 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr39gAAATU"]
[Thu Sep 17 15:06:01.362935 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWORFTPRVSLOsRVhr3_gAAAS4"]
[Thu Sep 17 15:06:01.441523 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4AQAAAQ4"]
[Thu Sep 17 15:06:01.512639 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php~"] [unique_id "aqxWORFTPRVSLOsRVhr4BQAAAX0"]
[Thu Sep 17 15:06:01.517006 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/"] [unique_id "aqxWORFTPRVSLOsRVhr4BgAAAS8"]
[Thu Sep 17 15:06:01.546321 2026] [security2:error] [pid 955873:tid 956017] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4CAAAARg"]
[Thu Sep 17 15:06:01.594941 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4CQAAATM"]
[Thu Sep 17 15:06:01.660524 2026] [security2:error] [pid 955873:tid 956019] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/network/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr38gAAARo"]
[Thu Sep 17 15:06:01.667112 2026] [security2:error] [pid 955873:tid 956008] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4CwAAAQ8"]
[Thu Sep 17 15:06:01.685406 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/"] [unique_id "aqxWORFTPRVSLOsRVhr4CgAAAR8"]
[Thu Sep 17 15:06:01.740812 2026] [security2:error] [pid 955873:tid 955889] [remote 216.73.217.142:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWORFTPRVSLOsRVhr4DgABRw8"]
[Thu Sep 17 15:06:01.751610 2026] [security2:error] [pid 955873:tid 956009] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4DwAAARA"]
[Thu Sep 17 15:06:01.820548 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:42319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWORFTPRVSLOsRVhr4EAAAAWk"]
[Thu Sep 17 15:06:01.824536 2026] [security2:error] [pid 955873:tid 956015] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4EQAAARY"]
[Thu Sep 17 15:06:01.824966 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:42319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWORFTPRVSLOsRVhr4EAAAAWk"]
[Thu Sep 17 15:06:01.829430 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/wp-includes/php-ai-client/third-party/Nyholm/"] [unique_id "aqxWORFTPRVSLOsRVhr4EwAAASo"]
[Thu Sep 17 15:06:01.858641 2026] [security2:error] [pid 955873:tid 956042] [client 47.79.201.157:21202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4DQAAATE"], referer: https://www.google.com/
[Thu Sep 17 15:06:01.916571 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4FwAAAVc"]
[Thu Sep 17 15:06:01.944180 2026] [security2:error] [pid 955873:tid 956111] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4GQAAAXY"]
[Thu Sep 17 15:06:02.035987 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:53820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4GwAAAUk"]
[Thu Sep 17 15:06:02.036931 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:53820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4GwAAAUk"]
[Thu Sep 17 15:06:02.070739 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4HAAAAUU"]
[Thu Sep 17 15:06:02.103606 2026] [security2:error] [pid 955873:tid 956077] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4HQAAAVQ"]
[Thu Sep 17 15:06:02.201469 2026] [security2:error] [pid 955873:tid 956020] [client 34.166.129.237:35214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/info.php.bak"] [unique_id "aqxWOhFTPRVSLOsRVhr4HwAAARs"]
[Thu Sep 17 15:06:02.214006 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4GgAAATc"]
[Thu Sep 17 15:06:02.214036 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4GgAAATc"]
[Thu Sep 17 15:06:02.214778 2026] [security2:error] [pid 955873:tid 956096] [client 2a01:7e03::2000:e4ff:fed3:3768:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entrustcounseling.com"] [uri "/wp-login.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3pAABZwM"], referer: https://www.google.com/
[Thu Sep 17 15:06:02.226077 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4IAAAAYE"]
[Thu Sep 17 15:06:02.281186 2026] [security2:error] [pid 955873:tid 956045] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4IQAAATQ"]
[Thu Sep 17 15:06:02.358657 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/"] [unique_id "aqxWOhFTPRVSLOsRVhr4JQAAAU4"]
[Thu Sep 17 15:06:02.378676 2026] [security2:error] [pid 955873:tid 956079] [client 139.28.219.68:55978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/network/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4HgAAAVY"]
[Thu Sep 17 15:06:02.379288 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4JwAAARk"]
[Thu Sep 17 15:06:02.382266 2026] [security2:error] [pid 955873:tid 956089] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4KAAAAWA"]
[Thu Sep 17 15:06:02.505866 2026] [security2:error] [pid 955873:tid 956068] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4KgAAAUs"]
[Thu Sep 17 15:06:02.520979 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/"] [unique_id "aqxWOhFTPRVSLOsRVhr4KQAAAVA"]
[Thu Sep 17 15:06:02.531567 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4LAAAAUE"]
[Thu Sep 17 15:06:02.660874 2026] [security2:error] [pid 955873:tid 956013] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4MQAAARQ"]
[Thu Sep 17 15:06:02.663202 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/wp-includes/php-ai-client/third-party/Nyholm/Psr7/"] [unique_id "aqxWOhFTPRVSLOsRVhr4MgAAASU"]
[Thu Sep 17 15:06:02.684549 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4MwAAAWo"]
[Thu Sep 17 15:06:02.792255 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/user/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4MAAAAXI"]
[Thu Sep 17 15:06:02.792457 2026] [security2:error] [pid 955873:tid 956094] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4NQAAAWU"]
[Thu Sep 17 15:06:02.836799 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4OAAAAUY"]
[Thu Sep 17 15:06:02.892390 2026] [security2:error] [pid 955873:tid 956025] [client 34.166.129.237:35220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWOhFTPRVSLOsRVhr4OgAAASA"]
[Thu Sep 17 15:06:02.942652 2026] [security2:error] [pid 955873:tid 956065] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4OwAAAUg"]
[Thu Sep 17 15:06:02.974658 2026] [security2:error] [pid 955873:tid 956026] [client 115.244.164.14:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4PQAAASE"]
[Thu Sep 17 15:06:02.974814 2026] [security2:error] [pid 955873:tid 956026] [client 115.244.164.14:63481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4PQAAASE"]
[Thu Sep 17 15:06:02.989376 2026] [security2:error] [pid 955873:tid 956087] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4PgAAAV4"]
[Thu Sep 17 15:06:03.000965 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4NwAAASI"]
[Thu Sep 17 15:06:03.000987 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4NwAAASI"]
[Thu Sep 17 15:06:03.048272 2026] [security2:error] [pid 955873:tid 956086] [client 2a01:7e03::2000:e4ff:fed3:3768:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entrustcounseling.com"] [uri "/wp-login.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4KwABXR4"]
[Thu Sep 17 15:06:03.056838 2026] [security2:error] [pid 955873:tid 956128] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4PwAAAYc"]
[Thu Sep 17 15:06:03.143540 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4QQAAATY"]
[Thu Sep 17 15:06:03.144343 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/HttplugFactory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4QgAAATg"]
[Thu Sep 17 15:06:03.144430 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/HttplugFactory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4QgAAATg"]
[Thu Sep 17 15:06:03.149520 2026] [security2:error] [pid 955873:tid 956055] [client 139.28.219.68:55978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/user/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4PAAAAT4"]
[Thu Sep 17 15:06:03.211641 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4RAAAAYg"]
[Thu Sep 17 15:06:03.221069 2026] [security2:error] [pid 955873:tid 956056] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4RQAAAT8"]
[Thu Sep 17 15:06:03.297590 2026] [security2:error] [pid 955873:tid 956106] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4SgAAAXE"]
[Thu Sep 17 15:06:03.423353 2026] [security2:error] [pid 955873:tid 956039] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4TgAAAS4"]
[Thu Sep 17 15:06:03.429808 2026] [security2:error] [pid 955873:tid 956124] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4TwAAAYM"]
[Thu Sep 17 15:06:03.430399 2026] [security2:error] [pid 955873:tid 956061] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/"] [unique_id "aqxWOxFTPRVSLOsRVhr4SwAAAUQ"]
[Thu Sep 17 15:06:03.430985 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/Psr17Factory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4UAAAAQ4"]
[Thu Sep 17 15:06:03.431082 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/Psr17Factory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4UAAAAQ4"]
[Thu Sep 17 15:06:03.457006 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4UQAAAS8"]
[Thu Sep 17 15:06:03.508071 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4UgAAASk"]
[Thu Sep 17 15:06:03.586108 2026] [security2:error] [pid 955873:tid 956104] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4VQAAAW8"]
[Thu Sep 17 15:06:03.596446 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.129.237:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WAAAAUI"]
[Thu Sep 17 15:06:03.597546 2026] [security2:error] [pid 955873:tid 956115] [client 178.20.43.173:60708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4SAAAAXo"], referer: https://berenice-vaucher.com/thank-you-for-your-comment/
[Thu Sep 17 15:06:03.618848 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4WgAAARo"]
[Thu Sep 17 15:06:03.619993 2026] [security2:error] [pid 955873:tid 956117] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WQAAAXw"]
[Thu Sep 17 15:06:03.630211 2026] [security2:error] [pid 955873:tid 956102] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/"] [unique_id "aqxWOxFTPRVSLOsRVhr4VgAAAW0"]
[Thu Sep 17 15:06:03.666010 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WwAAAVo"]
[Thu Sep 17 15:06:03.666126 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:49838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WwAAAVo"]
[Thu Sep 17 15:06:03.734075 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/MessageTrait.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4XgAAAUc"]
[Thu Sep 17 15:06:03.734171 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/MessageTrait.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4XgAAAUc"]
[Thu Sep 17 15:06:03.738770 2026] [security2:error] [pid 955873:tid 956005] [client 36.50.43.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4AAAAAQw"]
[Thu Sep 17 15:06:03.780827 2026] [security2:error] [pid 955873:tid 956036] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4XwAAASs"]
[Thu Sep 17 15:06:03.784439 2026] [security2:error] [pid 955873:tid 956082] [client 181.94.90.36:44650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4XAABWSk"]
[Thu Sep 17 15:06:03.786520 2026] [security2:error] [pid 955873:tid 956080] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4YAAAAVc"]
[Thu Sep 17 15:06:03.816992 2026] [security2:error] [pid 955873:tid 956004] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4ZAAAAQs"]
[Thu Sep 17 15:06:03.817030 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4ZgAAAUU"]
[Thu Sep 17 15:06:03.819544 2026] [security2:error] [pid 955873:tid 956090] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/"] [unique_id "aqxWOxFTPRVSLOsRVhr4YQAAAWE"]
[Thu Sep 17 15:06:03.944113 2026] [security2:error] [pid 955873:tid 956020] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4aQAAARs"]
[Thu Sep 17 15:06:04.015836 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Request.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4awAAAWc"]
[Thu Sep 17 15:06:04.015924 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:57666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Request.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4awAAAWc"]
[Thu Sep 17 15:06:04.023493 2026] [autoindex:error] [pid 955873:tid 956048] [client 139.28.219.68:41578] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:04.024000 2026] [security2:error] [pid 955873:tid 956048] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/includes/"] [unique_id "aqxWOxFTPRVSLOsRVhr4agAAATc"]
[Thu Sep 17 15:06:04.052350 2026] [security2:error] [pid 955873:tid 956088] [client 2a01:7e03::2000:e4ff:fed3:3768:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entrustcounseling.com"] [uri "/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4VAABXyg"], referer: https://duckduckgo.com/
[Thu Sep 17 15:06:04.069656 2026] [security2:error] [pid 955873:tid 956127] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4bAAAAYY"]
[Thu Sep 17 15:06:04.108274 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4bQAAAWA"]
[Thu Sep 17 15:06:04.124628 2026] [security2:error] [pid 955873:tid 956016] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4bgAAARc"]
[Thu Sep 17 15:06:04.269063 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4cgAAAVI"]
[Thu Sep 17 15:06:04.280354 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.129.237:35240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4cwAAATQ"]
[Thu Sep 17 15:06:04.292691 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/RequestTrait.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4dAAAAWM"]
[Thu Sep 17 15:06:04.292774 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:57676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/RequestTrait.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4dAAAAWM"]
[Thu Sep 17 15:06:04.319114 2026] [security2:error] [pid 955873:tid 956022] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4eAAAAR0"]
[Thu Sep 17 15:06:04.341580 2026] [security2:error] [pid 955873:tid 956079] [client 16.216.88.236:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4bwABVi0"]
[Thu Sep 17 15:06:04.350229 2026] [security2:error] [pid 955873:tid 956073] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/index.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4cAAAAVA"]
[Thu Sep 17 15:06:04.352187 2026] [security2:error] [pid 955873:tid 956125] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4eQAAAYQ"]
[Thu Sep 17 15:06:04.428029 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4ewAAASw"]
[Thu Sep 17 15:06:04.569354 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:57690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Response.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4gAAAAYA"]
[Thu Sep 17 15:06:04.569453 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:57690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Response.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4gAAAAYA"]
[Thu Sep 17 15:06:04.584381 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4gQAAATI"]
[Thu Sep 17 15:06:04.637283 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4ggAAAR4"]
[Thu Sep 17 15:06:04.654191 2026] [security2:error] [pid 955873:tid 956025] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4gwAAASA"]
[Thu Sep 17 15:06:04.715825 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:55978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/index.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4fwAAAWo"]
[Thu Sep 17 15:06:04.736941 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4hAAAASE"]
[Thu Sep 17 15:06:04.850217 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/ServerRequest.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4hwAAAV0"]
[Thu Sep 17 15:06:04.850314 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/ServerRequest.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4hwAAAV0"]
[Thu Sep 17 15:06:04.890061 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4igAAAWQ"]
[Thu Sep 17 15:06:04.891226 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4iwAAATY"]
[Thu Sep 17 15:06:04.914897 2026] [security2:error] [pid 955873:tid 956049] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4jAAAATg"]
[Thu Sep 17 15:06:04.984348 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.129.237:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4kAAAASI"]
[Thu Sep 17 15:06:05.010040 2026] [autoindex:error] [pid 955873:tid 956120] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:05.010561 2026] [security2:error] [pid 955873:tid 956120] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWPBFTPRVSLOsRVhr4kQAAAX8"]
[Thu Sep 17 15:06:05.020933 2026] [security2:error] [pid 955873:tid 956055] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/upgrade/"] [unique_id "aqxWPBFTPRVSLOsRVhr4jQAAAT4"]
[Thu Sep 17 15:06:05.051133 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4lAAAATU"]
[Thu Sep 17 15:06:05.085856 2026] [security2:error] [pid 955873:tid 956028] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4lQAAASM"]
[Thu Sep 17 15:06:05.144560 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Stream.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4lwAAAQ4"]
[Thu Sep 17 15:06:05.144666 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Stream.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4lwAAAQ4"]
[Thu Sep 17 15:06:05.199927 2026] [security2:error] [pid 955873:tid 956033] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4mAAAASg"]
[Thu Sep 17 15:06:05.217434 2026] [security2:error] [pid 955873:tid 956034] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4mgAAASk"]
[Thu Sep 17 15:06:05.318920 2026] [security2:error] [pid 955873:tid 956059] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4nQAAAUI"]
[Thu Sep 17 15:06:05.372126 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4oAAAAYI"]
[Thu Sep 17 15:06:05.423450 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/StreamTrait.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4owAAAT0"]
[Thu Sep 17 15:06:05.423548 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:57712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/StreamTrait.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4owAAAT0"]
[Thu Sep 17 15:06:05.479173 2026] [security2:error] [pid 955873:tid 956024] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4pAAAAR8"]
[Thu Sep 17 15:06:05.514200 2026] [security2:error] [pid 955873:tid 956083] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4pQAAAVo"]
[Thu Sep 17 15:06:05.527304 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4pgAAARI"]
[Thu Sep 17 15:06:05.670011 2026] [security2:error] [pid 955873:tid 956008] [client 34.166.129.237:35254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4qAAAAQ8"]
[Thu Sep 17 15:06:05.685320 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4qQAAATE"]
[Thu Sep 17 15:06:05.705958 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/UploadedFile.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4qgAAASs"]
[Thu Sep 17 15:06:05.706047 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:57724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/UploadedFile.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4qgAAASs"]
[Thu Sep 17 15:06:05.754897 2026] [security2:error] [pid 955873:tid 956062] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4rQAAAUU"]
[Thu Sep 17 15:06:05.754897 2026] [security2:error] [pid 955873:tid 956004] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4rAAAAQs"]
[Thu Sep 17 15:06:05.839310 2026] [security2:error] [pid 955873:tid 956100] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4sQAAAWs"]
[Thu Sep 17 15:06:05.983891 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Uri.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4uQAAAYY"]
[Thu Sep 17 15:06:05.983988 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Uri.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4uQAAAYY"]
[Thu Sep 17 15:06:05.992297 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4ugAAAWA"]
[Thu Sep 17 15:06:06.028596 2026] [security2:error] [pid 955873:tid 956068] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4uwAAAUs"]
[Thu Sep 17 15:06:06.149098 2026] [security2:error] [pid 955873:tid 956079] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4wAAAAVY"]
[Thu Sep 17 15:06:06.168908 2026] [security2:error] [pid 955873:tid 956006] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4wgAAAQ0"]
[Thu Sep 17 15:06:06.271798 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWPhFTPRVSLOsRVhr4wwAAATI"]
[Thu Sep 17 15:06:06.302776 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4xAAAAXI"]
[Thu Sep 17 15:06:06.306425 2026] [security2:error] [pid 955873:tid 956091] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4xQAAAWI"]
[Thu Sep 17 15:06:06.363976 2026] [security2:error] [pid 955873:tid 956074] [client 34.166.129.237:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWPhFTPRVSLOsRVhr4yQAAAVE"]
[Thu Sep 17 15:06:06.419791 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4ywAAAR4"]
[Thu Sep 17 15:06:06.455211 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWPhFTPRVSLOsRVhr4zAAAAUg"]
[Thu Sep 17 15:06:06.461768 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4zQAAAWo"]
[Thu Sep 17 15:06:06.585033 2026] [security2:error] [pid 955873:tid 956128] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4zgAAAYc"]
[Thu Sep 17 15:06:06.598494 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWPhFTPRVSLOsRVhr4zwAAAWQ"]
[Thu Sep 17 15:06:06.621202 2026] [security2:error] [pid 955873:tid 956057] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr40AAAAUA"]
[Thu Sep 17 15:06:06.622071 2026] [security2:error] [pid 955873:tid 956067] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr40QAAAUo"]
[Thu Sep 17 15:06:06.700291 2026] [security2:error] [pid 955873:tid 956026] [client 104.28.198.244:22661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWPhFTPRVSLOsRVhr40wAAASE"]
[Thu Sep 17 15:06:06.702632 2026] [authz_core:error] [pid 955873:tid 956037] [client 4.240.114.86:64631] AH01630: client denied by server configuration: /home2/loseyov0/public_html/staging-paltals/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:06:06.731056 2026] [security2:error] [pid 955873:tid 955929] [remote 216.73.217.142:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWPhFTPRVSLOsRVhr41AABdDc"]
[Thu Sep 17 15:06:06.779035 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr41wAAAUM"]
[Thu Sep 17 15:06:06.828584 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr42gAAAS4"]
[Thu Sep 17 15:06:06.864125 2026] [security2:error] [pid 955873:tid 956061] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr42wAAAUQ"]
[Thu Sep 17 15:06:06.883511 2026] [security2:error] [pid 955873:tid 956026] [client 104.28.198.244:22661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWPhFTPRVSLOsRVhr40wAAASE"]
[Thu Sep 17 15:06:06.928001 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPhFTPRVSLOsRVhr41gAAAXg"]
[Thu Sep 17 15:06:06.928021 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPhFTPRVSLOsRVhr41gAAAXg"]
[Thu Sep 17 15:06:06.935973 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr43gAAASQ"]
[Thu Sep 17 15:06:07.040270 2026] [security2:error] [pid 955873:tid 956010] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr44QAAARE"]
[Thu Sep 17 15:06:07.068370 2026] [security2:error] [pid 955873:tid 956124] [client 34.166.129.237:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWPxFTPRVSLOsRVhr44gAAAYM"]
[Thu Sep 17 15:06:07.089075 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr44wAAARo"]
[Thu Sep 17 15:06:07.109340 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/"] [unique_id "aqxWPxFTPRVSLOsRVhr45QAAAW0"]
[Thu Sep 17 15:06:07.128454 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.221.252:45188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWPxFTPRVSLOsRVhr45gAAAVo"]
[Thu Sep 17 15:06:07.144992 2026] [security2:error] [pid 955873:tid 956011] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr45wAAARI"]
[Thu Sep 17 15:06:07.242400 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr46QAAASY"]
[Thu Sep 17 15:06:07.268222 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/"] [unique_id "aqxWPxFTPRVSLOsRVhr46gAAARY"]
[Thu Sep 17 15:06:07.358703 2026] [security2:error] [pid 955873:tid 956008] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr48gAAAQ8"]
[Thu Sep 17 15:06:07.399099 2026] [security2:error] [pid 955873:tid 956119] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr49AAAAX4"]
[Thu Sep 17 15:06:07.423538 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr49QAAASs"]
[Thu Sep 17 15:06:07.458800 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWPxFTPRVSLOsRVhr49wAAAVc"]
[Thu Sep 17 15:06:07.521414 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr4-gAAAXs"]
[Thu Sep 17 15:06:07.561550 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr4_AAAAU8"]
[Thu Sep 17 15:06:07.702282 2026] [security2:error] [pid 955873:tid 956096] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr4_wAAAWc"]
[Thu Sep 17 15:06:07.717802 2026] [security2:error] [pid 955873:tid 956068] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5AAAAAUs"]
[Thu Sep 17 15:06:07.777456 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.129.237:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWPxFTPRVSLOsRVhr5AwAAAVM"]
[Thu Sep 17 15:06:07.787199 2026] [security2:error] [pid 955873:tid 956075] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5BQAAAVI"]
[Thu Sep 17 15:06:07.800259 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPxFTPRVSLOsRVhr4_QAAAYY"]
[Thu Sep 17 15:06:07.800275 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPxFTPRVSLOsRVhr4_QAAAYY"]
[Thu Sep 17 15:06:07.836392 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.221.252:45200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWPxFTPRVSLOsRVhr5CAAAAWE"]
[Thu Sep 17 15:06:07.877138 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5CgAAAUE"]
[Thu Sep 17 15:06:07.979853 2026] [security2:error] [pid 955873:tid 956070] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5DgAAAU0"]
[Thu Sep 17 15:06:08.035708 2026] [security2:error] [pid 955873:tid 956013] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5EAAAARQ"]
[Thu Sep 17 15:06:08.052193 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/EventDispatcherInterface.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5EQAAATI"]
[Thu Sep 17 15:06:08.052294 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/EventDispatcherInterface.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5EQAAATI"]
[Thu Sep 17 15:06:08.178192 2026] [security2:error] [pid 955873:tid 956074] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5EwAAAVE"]
[Thu Sep 17 15:06:08.190951 2026] [security2:error] [pid 955873:tid 956025] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5FAAAASA"]
[Thu Sep 17 15:06:08.256442 2026] [security2:error] [pid 955873:tid 956099] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5FQAAAWo"]
[Thu Sep 17 15:06:08.338954 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQBFTPRVSLOsRVhr5GQAAARk"]
[Thu Sep 17 15:06:08.346800 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5GgAAAVU"]
[Thu Sep 17 15:06:08.422398 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5HQAAAWQ"]
[Thu Sep 17 15:06:08.429872 2026] [security2:error] [pid 955873:tid 956023] [client 185.55.149.49:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5HgAAAR4"]
[Thu Sep 17 15:06:08.429959 2026] [security2:error] [pid 955873:tid 956023] [client 185.55.149.49:53979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5HgAAAR4"]
[Thu Sep 17 15:06:08.461123 2026] [security2:error] [pid 955873:tid 956091] [client 216.73.163.69:39637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5GwAAAWI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:08.505551 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5IAAAATg"]
[Thu Sep 17 15:06:08.512994 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQBFTPRVSLOsRVhr5HwAAAR0"]
[Thu Sep 17 15:06:08.530803 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.221.252:45206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWQBFTPRVSLOsRVhr5IQAAATs"]
[Thu Sep 17 15:06:08.532439 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5IgAAAWU"]
[Thu Sep 17 15:06:08.659645 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWQBFTPRVSLOsRVhr5IwAAAX8"]
[Thu Sep 17 15:06:08.661072 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5JAAAASw"]
[Thu Sep 17 15:06:08.778967 2026] [security2:error] [pid 955873:tid 956060] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5JgAAAUM"]
[Thu Sep 17 15:06:08.813032 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5KAAAAXg"]
[Thu Sep 17 15:06:08.871968 2026] [security2:error] [pid 955873:tid 956056] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5JwAAAT8"]
[Thu Sep 17 15:06:08.964785 2026] [security2:error] [pid 955873:tid 956003] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5LQAAAQo"]
[Thu Sep 17 15:06:08.978211 2026] [security2:error] [pid 955873:tid 956110] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5LgAAAXU"]
[Thu Sep 17 15:06:08.990877 2026] [security2:error] [pid 955873:tid 956126] [client 20.244.34.24:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5LwAAAYU"], referer: binance.com
[Thu Sep 17 15:06:09.002701 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5KQAAAX0"]
[Thu Sep 17 15:06:09.002727 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5KQAAAX0"]
[Thu Sep 17 15:06:09.131734 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5MAAAAYg"]
[Thu Sep 17 15:06:09.141566 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5MQAAAQ4"]
[Thu Sep 17 15:06:09.149457 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/"] [unique_id "aqxWQRFTPRVSLOsRVhr5MgAAAX4"]
[Thu Sep 17 15:06:09.155066 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5MwAAASs"]
[Thu Sep 17 15:06:09.285922 2026] [security2:error] [pid 955873:tid 956062] [client 4.240.114.86:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5NgAAAUU"], referer: binance.com
[Thu Sep 17 15:06:09.303165 2026] [security2:error] [pid 955873:tid 956004] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5OAAAAQs"]
[Thu Sep 17 15:06:09.321394 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/"] [unique_id "aqxWQRFTPRVSLOsRVhr5NwAAAWk"]
[Thu Sep 17 15:06:09.347321 2026] [security2:error] [pid 955873:tid 956081] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5OwAAAVg"]
[Thu Sep 17 15:06:09.433728 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5PQAAARs"]
[Thu Sep 17 15:06:09.460638 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5PgAAAU8"]
[Thu Sep 17 15:06:09.463159 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQRFTPRVSLOsRVhr5PwAAAYI"]
[Thu Sep 17 15:06:09.465513 2026] [security2:error] [pid 955873:tid 956041] [client 34.166.221.252:45216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWQRFTPRVSLOsRVhr5QAAAATA"]
[Thu Sep 17 15:06:09.549010 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.129.237:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5QQAAAW8"]
[Thu Sep 17 15:06:09.585338 2026] [security2:error] [pid 955873:tid 956042] [client 220.181.108.159:64550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nlfephrata.org"] [uri "/index.php"] [unique_id "aqxWPxFTPRVSLOsRVhr49gABMT8"]
[Thu Sep 17 15:06:09.590591 2026] [security2:error] [pid 955873:tid 956017] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5RgAAARg"]
[Thu Sep 17 15:06:09.613420 2026] [security2:error] [pid 955873:tid 956090] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5SgAAAWE"]
[Thu Sep 17 15:06:09.709658 2026] [security2:error] [pid 955873:tid 956125] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5TQAAAYQ"]
[Thu Sep 17 15:06:09.770434 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5TgAAATc"]
[Thu Sep 17 15:06:09.792020 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5SQAAAYY"]
[Thu Sep 17 15:06:09.792045 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5SQAAAYY"]
[Thu Sep 17 15:06:09.804865 2026] [security2:error] [pid 955873:tid 956016] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5TwAAARc"]
[Thu Sep 17 15:06:09.932267 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:57760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientExceptionInterface.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5VAAAAXI"]
[Thu Sep 17 15:06:09.932346 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientExceptionInterface.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5VAAAAXI"]
[Thu Sep 17 15:06:09.941149 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5VQAAAVE"]
[Thu Sep 17 15:06:10.013325 2026] [security2:error] [pid 955873:tid 956077] [client 216.73.163.39:24317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5VgAAAVQ"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:10.028989 2026] [security2:error] [pid 955873:tid 956086] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5WQAAAV0"]
[Thu Sep 17 15:06:10.094702 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5WgAAAR4"]
[Thu Sep 17 15:06:10.213573 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:34860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5XAAAAWI"]
[Thu Sep 17 15:06:10.213654 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:34860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5XAAAAWI"]
[Thu Sep 17 15:06:10.229102 2026] [security2:error] [pid 955873:tid 956099] [client 34.166.129.237:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5XQAAAWo"]
[Thu Sep 17 15:06:10.231376 2026] [security2:error] [pid 955873:tid 956128] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5XgAAAYc"]
[Thu Sep 17 15:06:10.247120 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5XwAAATg"]
[Thu Sep 17 15:06:10.401432 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5agAAAX8"]
[Thu Sep 17 15:06:10.478302 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5bAAAAS4"]
[Thu Sep 17 15:06:10.540117 2026] [security2:error] [pid 955873:tid 956028] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5bQAAASM"]
[Thu Sep 17 15:06:10.560915 2026] [security2:error] [pid 955873:tid 956021] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5bgAAARw"]
[Thu Sep 17 15:06:10.715244 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5cwAAARI"]
[Thu Sep 17 15:06:10.761823 2026] [security2:error] [pid 955873:tid 956031] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5dAAAASY"]
[Thu Sep 17 15:06:10.810552 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/NetworkExceptionInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5dQAAAQo"]
[Thu Sep 17 15:06:10.810633 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/NetworkExceptionInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5dQAAAQo"]
[Thu Sep 17 15:06:10.872165 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5eQAAASc"]
[Thu Sep 17 15:06:10.936692 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:35318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5ewAAAR8"]
[Thu Sep 17 15:06:10.945499 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5fAAAAYg"]
[Thu Sep 17 15:06:11.024897 2026] [security2:error] [pid 955873:tid 956009] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5fQAAARA"]
[Thu Sep 17 15:06:11.101543 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/RequestExceptionInterface.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5fwAAAVc"]
[Thu Sep 17 15:06:11.101635 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/RequestExceptionInterface.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5fwAAAVc"]
[Thu Sep 17 15:06:11.180087 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5gQAAAU4"]
[Thu Sep 17 15:06:11.336416 2026] [security2:error] [pid 955873:tid 956066] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5gwAAAUk"]
[Thu Sep 17 15:06:11.352780 2026] [security2:error] [pid 955873:tid 956111] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5hAAAAXY"]
[Thu Sep 17 15:06:11.367970 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5hQAAASs"]
[Thu Sep 17 15:06:11.386616 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/"] [unique_id "aqxWQxFTPRVSLOsRVhr5iAAAAYk"]
[Thu Sep 17 15:06:11.490510 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5jQAAARg"]
[Thu Sep 17 15:06:11.562230 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/"] [unique_id "aqxWQxFTPRVSLOsRVhr5jgAAAWE"]
[Thu Sep 17 15:06:11.620349 2026] [security2:error] [pid 955873:tid 956084] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5kQAAAVs"]
[Thu Sep 17 15:06:11.620972 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5kgAAATE"]
[Thu Sep 17 15:06:11.639294 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5kwAAAXc"]
[Thu Sep 17 15:06:11.644129 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5lAAAAYE"]
[Thu Sep 17 15:06:11.702941 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQxFTPRVSLOsRVhr5lQAAAVI"]
[Thu Sep 17 15:06:11.858991 2026] [security2:error] [pid 955873:tid 956070] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5mgAAAU0"]
[Thu Sep 17 15:06:11.902725 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5oAAAATk"]
[Thu Sep 17 15:06:11.911068 2026] [security2:error] [pid 955873:tid 956043] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5oQAAATI"]
[Thu Sep 17 15:06:12.020925 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5ogAAAVE"]
[Thu Sep 17 15:06:12.026067 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5nwAAAXA"]
[Thu Sep 17 15:06:12.026083 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5nwAAAXA"]
[Thu Sep 17 15:06:12.163549 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:34880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/MessageInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5qAAAAVU"]
[Thu Sep 17 15:06:12.163635 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/MessageInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5qAAAAVU"]
[Thu Sep 17 15:06:12.179730 2026] [security2:error] [pid 955873:tid 956064] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5qwAAAUc"]
[Thu Sep 17 15:06:12.182987 2026] [security2:error] [pid 955873:tid 956108] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5rAAAAXM"]
[Thu Sep 17 15:06:12.186889 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5rQAAAWI"]
[Thu Sep 17 15:06:12.305116 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.129.237:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5sQAAAV4"]
[Thu Sep 17 15:06:12.350628 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5sgAAAXQ"]
[Thu Sep 17 15:06:12.365999 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5tQAAAS4"]
[Thu Sep 17 15:06:12.372472 2026] [security2:error] [pid 955873:tid 956018] [client 156.245.246.112:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xrx.sgh.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5swAAARk"], referer: https://xrx.sgh.mybluehost.me
[Thu Sep 17 15:06:12.452039 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestFactoryInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5tgAAAUA"]
[Thu Sep 17 15:06:12.452121 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:34894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestFactoryInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5tgAAAUA"]
[Thu Sep 17 15:06:12.455053 2026] [security2:error] [pid 955873:tid 956113] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5twAAAXg"]
[Thu Sep 17 15:06:12.534894 2026] [security2:error] [pid 955873:tid 956027] [client 45.169.98.18:54387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5vAAAASI"]
[Thu Sep 17 15:06:12.534959 2026] [security2:error] [pid 955873:tid 956027] [client 45.169.98.18:54387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5vAAAASI"]
[Thu Sep 17 15:06:12.604931 2026] [security2:error] [pid 955873:tid 956019] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5vwAAARo"]
[Thu Sep 17 15:06:12.727973 2026] [security2:error] [pid 955873:tid 956031] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5wgAAASY"]
[Thu Sep 17 15:06:12.738030 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5xAAAASc"]
[Thu Sep 17 15:06:12.738133 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5xAAAASc"]
[Thu Sep 17 15:06:12.934295 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr50QAAAWk"]
[Thu Sep 17 15:06:12.936199 2026] [security2:error] [pid 955873:tid 956081] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr50gAAAVg"]
[Thu Sep 17 15:06:12.971503 2026] [security2:error] [pid 955873:tid 956118] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWRBFTPRVSLOsRVhr50AAAAX0"], referer: http://alrayancont.com/Telerik.Web.UI.WebResource.axd?type=rau
[Thu Sep 17 15:06:12.985384 2026] [security2:error] [pid 955873:tid 956062] [client 216.73.163.46:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5zgAAAUU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:12.988977 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:37142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWRBFTPRVSLOsRVhr50wAAAR8"]
[Thu Sep 17 15:06:13.000844 2026] [security2:error] [pid 955873:tid 956066] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr51AAAAUk"]
[Thu Sep 17 15:06:13.023066 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51gAAAXY"]
[Thu Sep 17 15:06:13.023161 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:34910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51gAAAXY"]
[Thu Sep 17 15:06:13.028364 2026] [security2:error] [pid 955873:tid 956054] [client 154.190.208.131:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51wAAAT0"]
[Thu Sep 17 15:06:13.035373 2026] [security2:error] [pid 955873:tid 956054] [client 154.190.208.131:41597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51wAAAT0"]
[Thu Sep 17 15:06:13.273339 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr52gAAAQw"]
[Thu Sep 17 15:06:13.305438 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr53AAAATM"]
[Thu Sep 17 15:06:13.305516 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr53AAAATM"]
[Thu Sep 17 15:06:13.322023 2026] [security2:error] [pid 955873:tid 956104] [client 34.178.167.214:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWRRFTPRVSLOsRVhr52wAAAW8"]
[Thu Sep 17 15:06:13.399779 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr54QAAARg"]
[Thu Sep 17 15:06:13.552938 2026] [security2:error] [pid 955873:tid 956070] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr54wAAAU0"]
[Thu Sep 17 15:06:13.558852 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr55AAAATk"]
[Thu Sep 17 15:06:13.589332 2026] [security2:error] [pid 955873:tid 956014] [client 115.244.164.14:64227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr55gAAARU"]
[Thu Sep 17 15:06:13.589409 2026] [security2:error] [pid 955873:tid 956014] [client 115.244.164.14:64227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr55gAAARU"]
[Thu Sep 17 15:06:13.606615 2026] [security2:error] [pid 955873:tid 956016] [client 134.185.85.61:51986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "wheresmymap.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxWRRFTPRVSLOsRVhr55wAAARc"]
[Thu Sep 17 15:06:13.609613 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr56AAAAXI"]
[Thu Sep 17 15:06:13.609685 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:34924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr56AAAAXI"]
[Thu Sep 17 15:06:13.684188 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.129.237:37152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWRRFTPRVSLOsRVhr56gAAAVI"]
[Thu Sep 17 15:06:13.713269 2026] [security2:error] [pid 955873:tid 956065] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr56wAAAUg"]
[Thu Sep 17 15:06:13.824560 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr58AAAAR4"]
[Thu Sep 17 15:06:13.866449 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr58QAAAVQ"]
[Thu Sep 17 15:06:13.893768 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:34936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr58gAAAYc"]
[Thu Sep 17 15:06:13.894146 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:34936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr58gAAAYc"]
[Thu Sep 17 15:06:13.986965 2026] [security2:error] [pid 955873:tid 956055] [client 134.185.85.61:57859] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "wheresmymap.com"] [uri "/media/system/js/core.js"] [unique_id "aqxWRRFTPRVSLOsRVhr59wAAAT4"]
[Thu Sep 17 15:06:14.019504 2026] [security2:error] [pid 955873:tid 956076] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr5-AAAAVM"]
[Thu Sep 17 15:06:14.097564 2026] [security2:error] [pid 955873:tid 956018] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr5-gAAARk"]
[Thu Sep 17 15:06:14.175801 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr5-wAAAXk"]
[Thu Sep 17 15:06:14.180202 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:34944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr5_AAAAXg"]
[Thu Sep 17 15:06:14.180286 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:34944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr5_AAAAXg"]
[Thu Sep 17 15:06:14.268558 2026] [security2:error] [pid 955873:tid 956103] [client 34.178.167.214:50264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWRhFTPRVSLOsRVhr5_gAAAW4"]
[Thu Sep 17 15:06:14.338820 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6AgAAATU"]
[Thu Sep 17 15:06:14.369397 2026] [security2:error] [pid 955873:tid 956120] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6AwAAAX8"]
[Thu Sep 17 15:06:14.461235 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:34954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6BgAAAYA"]
[Thu Sep 17 15:06:14.461322 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:34954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6BgAAAYA"]
[Thu Sep 17 15:06:14.492566 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6BwAAAUw"]
[Thu Sep 17 15:06:14.513777 2026] [security2:error] [pid 955873:tid 956061] [client 186.105.232.15:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6CAAAAUQ"]
[Thu Sep 17 15:06:14.513911 2026] [security2:error] [pid 955873:tid 956061] [client 186.105.232.15:50400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6CAAAAUQ"]
[Thu Sep 17 15:06:14.641451 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6CgAAAUI"]
[Thu Sep 17 15:06:14.644466 2026] [security2:error] [pid 955873:tid 956083] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6CwAAAVo"]
[Thu Sep 17 15:06:14.739029 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:34970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6DQAAASQ"]
[Thu Sep 17 15:06:14.739121 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:34970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6DQAAASQ"]
[Thu Sep 17 15:06:14.799513 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6DgAAAS8"]
[Thu Sep 17 15:06:14.913276 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6EwAAAWw"]
[Thu Sep 17 15:06:14.960426 2026] [security2:error] [pid 955873:tid 956004] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6FQAAAQs"]
[Thu Sep 17 15:06:14.988354 2026] [security2:error] [pid 955873:tid 956117] [client 34.178.167.214:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6FwAAAXw"]
[Thu Sep 17 15:06:15.038105 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6GAAAAQo"]
[Thu Sep 17 15:06:15.038202 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6GAAAAQo"]
[Thu Sep 17 15:06:15.101752 2026] [security2:error] [pid 955873:tid 956071] [client 189.141.236.123:57426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6FgABTlg"]
[Thu Sep 17 15:06:15.113678 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6GwAAAYI"]
[Thu Sep 17 15:06:15.185095 2026] [security2:error] [pid 955873:tid 956041] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6HgAAATA"]
[Thu Sep 17 15:06:15.276209 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6HwAAASo"]
[Thu Sep 17 15:06:15.336586 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriFactoryInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6JAAAAUs"]
[Thu Sep 17 15:06:15.336697 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:34986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriFactoryInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6JAAAAUs"]
[Thu Sep 17 15:06:15.429680 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6KAAAAQw"]
[Thu Sep 17 15:06:15.461420 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6KwAAAXc"]
[Thu Sep 17 15:06:15.507627 2026] [security2:error] [pid 955873:tid 956115] [client 216.73.163.60:53887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6KQAAAXo"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:15.585592 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6LQAAAUE"]
[Thu Sep 17 15:06:15.636209 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6LwAAARc"]
[Thu Sep 17 15:06:15.636293 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:34994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6LwAAARc"]
[Thu Sep 17 15:06:15.738583 2026] [security2:error] [pid 955873:tid 956074] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6MAAAAVE"]
[Thu Sep 17 15:06:15.743308 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6MQAAAVI"]
[Thu Sep 17 15:06:15.828107 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6NgAAATk"]
[Thu Sep 17 15:06:15.842908 2026] [security2:error] [pid 955873:tid 956107] [client 216.73.163.57:50717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6MwAAAXI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:15.897331 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6OQAAAVQ"]
[Thu Sep 17 15:06:15.917124 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:35000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/"] [unique_id "aqxWRxFTPRVSLOsRVhr6OgAAAXM"]
[Thu Sep 17 15:06:16.010568 2026] [security2:error] [pid 955873:tid 956067] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6PQAAAUo"]
[Thu Sep 17 15:06:16.055971 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6PgAAAWM"]
[Thu Sep 17 15:06:16.078079 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/"] [unique_id "aqxWSBFTPRVSLOsRVhr6PwAAAXQ"]
[Thu Sep 17 15:06:16.103084 2026] [security2:error] [pid 955873:tid 956076] [client 20.244.34.24:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6QgAAAVM"], referer: binance.com
[Thu Sep 17 15:06:16.172030 2026] [security2:error] [pid 955873:tid 956119] [client 143.14.6.18:17824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6IAAAAX4"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:16.182557 2026] [security2:error] [pid 955873:tid 956098] [client 216.75.132.105:59940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6HQAAAWk"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:16.213503 2026] [security2:error] [pid 955873:tid 956064] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6RQAAAUc"]
[Thu Sep 17 15:06:16.218078 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:35000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWSBFTPRVSLOsRVhr6RgAAAXk"]
[Thu Sep 17 15:06:16.293392 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6SQAAAW4"]
[Thu Sep 17 15:06:16.365930 2026] [security2:error] [pid 955873:tid 956034] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6TwAAASk"]
[Thu Sep 17 15:06:16.520870 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6UwAAATg"]
[Thu Sep 17 15:06:16.555598 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6TgAAARw"]
[Thu Sep 17 15:06:16.555618 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6TgAAARw"]
[Thu Sep 17 15:06:16.570038 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6VQAAAUI"]
[Thu Sep 17 15:06:16.677897 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6WQAAASY"]
[Thu Sep 17 15:06:16.693078 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:35000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/CacheInterface.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6WgAAASc"]
[Thu Sep 17 15:06:16.693152 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:35000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/CacheInterface.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6WgAAASc"]
[Thu Sep 17 15:06:16.723373 2026] [security2:error] [pid 955873:tid 956094] [client 34.178.167.214:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6XAAAAWU"]
[Thu Sep 17 15:06:16.833121 2026] [security2:error] [pid 955873:tid 956106] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6YgAAAXE"]
[Thu Sep 17 15:06:16.847543 2026] [security2:error] [pid 955873:tid 956004] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6YwAAAQs"]
[Thu Sep 17 15:06:16.971819 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxWSBFTPRVSLOsRVhr6agAAAR8"]
[Thu Sep 17 15:06:16.985775 2026] [security2:error] [pid 955873:tid 956066] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6bAAAAUk"]
[Thu Sep 17 15:06:17.128615 2026] [security2:error] [pid 955873:tid 956068] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6cwAAAUs"]
[Thu Sep 17 15:06:17.134420 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxWSRFTPRVSLOsRVhr6cQAAAYk"]
[Thu Sep 17 15:06:17.142696 2026] [security2:error] [pid 955873:tid 956038] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6dAAAAS0"]
[Thu Sep 17 15:06:17.243997 2026] [security2:error] [pid 955873:tid 956117] [client 216.75.132.105:59954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6cgAAAXw"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:17.274271 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/wp-includes/"] [unique_id "aqxWSRFTPRVSLOsRVhr6eAAAAWc"]
[Thu Sep 17 15:06:17.295440 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6egAAAYE"]
[Thu Sep 17 15:06:17.406736 2026] [security2:error] [pid 955873:tid 956085] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6ggAAAVw"]
[Thu Sep 17 15:06:17.410181 2026] [security2:error] [pid 955873:tid 956054] [client 143.14.6.18:17834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6ewAAAT0"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:17.429161 2026] [security2:error] [pid 955873:tid 956115] [client 181.1.121.73:56371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6fgABelw"]
[Thu Sep 17 15:06:17.451292 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6hQAAAQ4"]
[Thu Sep 17 15:06:17.609568 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6hAAAATI"]
[Thu Sep 17 15:06:17.609590 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6hAAAATI"]
[Thu Sep 17 15:06:17.610209 2026] [security2:error] [pid 955873:tid 956067] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6iwAAAUo"]
[Thu Sep 17 15:06:17.659220 2026] [security2:error] [pid 955873:tid 956014] [client 34.178.167.214:50294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6jAAAARU"]
[Thu Sep 17 15:06:17.686887 2026] [security2:error] [pid 955873:tid 956088] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6jgAAAV8"]
[Thu Sep 17 15:06:17.751173 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6jwAAASw"]
[Thu Sep 17 15:06:17.751285 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6jwAAASw"]
[Thu Sep 17 15:06:17.771241 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6kAAAAVU"]
[Thu Sep 17 15:06:17.934530 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6mAAAAWk"]
[Thu Sep 17 15:06:17.967853 2026] [security2:error] [pid 955873:tid 956057] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6mgAAAUA"]
[Thu Sep 17 15:06:18.048689 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:35020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable-deprecated.php"] [unique_id "aqxWShFTPRVSLOsRVhr6nAAAAX8"]
[Thu Sep 17 15:06:18.048782 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:35020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable-deprecated.php"] [unique_id "aqxWShFTPRVSLOsRVhr6nAAAAX8"]
[Thu Sep 17 15:06:18.094809 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6nQAAATU"]
[Thu Sep 17 15:06:18.245782 2026] [security2:error] [pid 955873:tid 956087] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6ogAAAV4"]
[Thu Sep 17 15:06:18.254600 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6owAAARo"]
[Thu Sep 17 15:06:18.300171 2026] [security2:error] [pid 955873:tid 956121] [client 34.178.167.214:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWShFTPRVSLOsRVhr6pgAAAYA"]
[Thu Sep 17 15:06:18.344513 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable.php"] [unique_id "aqxWShFTPRVSLOsRVhr6qQAAARY"]
[Thu Sep 17 15:06:18.344608 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable.php"] [unique_id "aqxWShFTPRVSLOsRVhr6qQAAARY"]
[Thu Sep 17 15:06:18.415045 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6qgAAASY"]
[Thu Sep 17 15:06:18.522792 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6rgAAARs"]
[Thu Sep 17 15:06:18.568606 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6sAAAAVc"]
[Thu Sep 17 15:06:18.636357 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:35038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxWShFTPRVSLOsRVhr6sQAAASs"]
[Thu Sep 17 15:06:18.731190 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6sgAAAX0"]
[Thu Sep 17 15:06:18.792841 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxWShFTPRVSLOsRVhr6tgAAAS0"]
[Thu Sep 17 15:06:18.796216 2026] [security2:error] [pid 955873:tid 956051] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6uAAAATo"]
[Thu Sep 17 15:06:18.862118 2026] [security2:error] [pid 955873:tid 956102] [client 4.240.114.86:54268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxWShFTPRVSLOsRVhr6uQAAAW0"], referer: binance.com
[Thu Sep 17 15:06:18.889092 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6vAAAATM"]
[Thu Sep 17 15:06:18.940648 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/wp-includes/"] [unique_id "aqxWShFTPRVSLOsRVhr6vgAAAYg"]
[Thu Sep 17 15:06:19.047064 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr61AAAASg"]
[Thu Sep 17 15:06:19.067862 2026] [security2:error] [pid 955873:tid 956007] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr61QAAAQ4"]
[Thu Sep 17 15:06:19.102313 2026] [security2:error] [pid 955873:tid 956104] [client 185.55.149.49:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWSxFTPRVSLOsRVhr62QAAAW8"]
[Thu Sep 17 15:06:19.105089 2026] [security2:error] [pid 955873:tid 956104] [client 185.55.149.49:54596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWSxFTPRVSLOsRVhr62QAAAW8"]
[Thu Sep 17 15:06:19.106195 2026] [security2:error] [pid 955873:tid 956065] [client 34.178.167.214:50302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWSxFTPRVSLOsRVhr62wAAAUg"]
[Thu Sep 17 15:06:19.200306 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr63wAAATk"]
[Thu Sep 17 15:06:19.286167 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr61wAAAYY"]
[Thu Sep 17 15:06:19.286199 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr61wAAAYY"]
[Thu Sep 17 15:06:19.339925 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr65QAAAVU"]
[Thu Sep 17 15:06:19.360429 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr65wAAAWM"]
[Thu Sep 17 15:06:19.431555 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:35038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/entry.php"] [unique_id "aqxWSxFTPRVSLOsRVhr66QAAAX4"]
[Thu Sep 17 15:06:19.431629 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:35038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/entry.php"] [unique_id "aqxWSxFTPRVSLOsRVhr66QAAAX4"]
[Thu Sep 17 15:06:19.520129 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr66wAAAXk"]
[Thu Sep 17 15:06:19.612413 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr67QAAAW4"]
[Thu Sep 17 15:06:19.684078 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr67gAAATU"]
[Thu Sep 17 15:06:19.712430 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:35054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/mo.php"] [unique_id "aqxWSxFTPRVSLOsRVhr67wAAASk"]
[Thu Sep 17 15:06:19.712534 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:35054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/mo.php"] [unique_id "aqxWSxFTPRVSLOsRVhr67wAAASk"]
[Thu Sep 17 15:06:19.788858 2026] [security2:error] [pid 955873:tid 956035] [client 45.131.194.119:42199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.194.131.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWShFTPRVSLOsRVhr6swAAASo"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:19.837439 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr69gAAASM"]
[Thu Sep 17 15:06:19.850342 2026] [security2:error] [pid 955873:tid 956120] [client 34.178.167.214:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWSxFTPRVSLOsRVhr6-QAAAX8"]
[Thu Sep 17 15:06:19.890995 2026] [security2:error] [pid 955873:tid 956079] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr6-gAAAVY"]
[Thu Sep 17 15:06:19.963347 2026] [security2:error] [pid 955873:tid 956081] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr69QAAAVg"], referer: http://alrayancont.com/solr/#/
[Thu Sep 17 15:06:19.994710 2026] [security2:error] [pid 955873:tid 956073] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr6_wAAAVA"]
[Thu Sep 17 15:06:20.003777 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/plural-forms.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7AAAAARY"]
[Thu Sep 17 15:06:20.003867 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:51334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/plural-forms.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7AAAAARY"]
[Thu Sep 17 15:06:20.069858 2026] [security2:error] [pid 955873:tid 956054] [client 39.34.162.59:38304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr6_gAAAT0"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:20.149373 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7BQAAASQ"]
[Thu Sep 17 15:06:20.150981 2026] [security2:error] [pid 955873:tid 956012] [client 181.166.70.135:47328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7AQAAARM"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:20.169392 2026] [security2:error] [pid 955873:tid 956061] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7BgAAAUQ"]
[Thu Sep 17 15:06:20.301650 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/po.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7CQAAAYQ"]
[Thu Sep 17 15:06:20.301766 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/po.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7CQAAAYQ"]
[Thu Sep 17 15:06:20.305974 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7CgAAAU8"]
[Thu Sep 17 15:06:20.442829 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7HwAAASs"]
[Thu Sep 17 15:06:20.459969 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7IgAAAYc"]
[Thu Sep 17 15:06:20.511779 2026] [security2:error] [pid 955873:tid 956024] [client 45.146.54.107:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7IQAAAR8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:20.589037 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/streams.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7JgAAAW0"]
[Thu Sep 17 15:06:20.589142 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:51358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/streams.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7JgAAAW0"]
[Thu Sep 17 15:06:20.613217 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7JwAAATM"]
[Thu Sep 17 15:06:20.715763 2026] [security2:error] [pid 955873:tid 956033] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7KwAAASg"]
[Thu Sep 17 15:06:20.771061 2026] [security2:error] [pid 955873:tid 956112] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7LQAAAXc"]
[Thu Sep 17 15:06:20.807446 2026] [security2:error] [pid 955873:tid 956011] [client 34.178.167.214:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7LwAAARI"]
[Thu Sep 17 15:06:20.820725 2026] [security2:error] [pid 955873:tid 956123] [client 216.73.163.59:44293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7LgAAAYI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:20.879812 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/translations.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7MwAAAYE"]
[Thu Sep 17 15:06:20.879922 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:51374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/translations.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7MwAAAYE"]
[Thu Sep 17 15:06:20.928605 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7NwAAAVI"]
[Thu Sep 17 15:06:20.988417 2026] [security2:error] [pid 955873:tid 956077] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7OAAAAVQ"]
[Thu Sep 17 15:06:21.085299 2026] [security2:error] [pid 955873:tid 956014] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7OQAAARU"]
[Thu Sep 17 15:06:21.165151 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:51388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxWTRFTPRVSLOsRVhr7OwAAAWs"]
[Thu Sep 17 15:06:21.239418 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7PgAAATQ"]
[Thu Sep 17 15:06:21.261312 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7PwAAAWk"]
[Thu Sep 17 15:06:21.342155 2026] [authz_core:error] [pid 955873:tid 956088] [client 143.244.57.120:57096] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/error_log
[Thu Sep 17 15:06:21.353029 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxWTRFTPRVSLOsRVhr7QAAAAV8"]
[Thu Sep 17 15:06:21.393921 2026] [security2:error] [pid 955873:tid 956057] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7RgAAAUA"]
[Thu Sep 17 15:06:21.493032 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:51388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/wp-includes/"] [unique_id "aqxWTRFTPRVSLOsRVhr7SgAAATU"]
[Thu Sep 17 15:06:21.534182 2026] [security2:error] [pid 955873:tid 956055] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7TAAAAT4"]
[Thu Sep 17 15:06:21.554750 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7TQAAASI"]
[Thu Sep 17 15:06:21.710645 2026] [security2:error] [pid 955873:tid 956021] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7VAAAARw"]
[Thu Sep 17 15:06:21.717813 2026] [security2:error] [pid 955873:tid 956121] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7UwAAAYA"], referer: http://alrayancont.com/login.do
[Thu Sep 17 15:06:21.746746 2026] [security2:error] [pid 955873:tid 956026] [client 34.178.167.214:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7VQAAASE"]
[Thu Sep 17 15:06:21.807085 2026] [security2:error] [pid 955873:tid 956054] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7VgAAAT0"]
[Thu Sep 17 15:06:21.852205 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7TgAAATw"]
[Thu Sep 17 15:06:21.852235 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7TgAAATw"]
[Thu Sep 17 15:06:21.865746 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7WwAAATE"]
[Thu Sep 17 15:06:21.989244 2026] [security2:error] [pid 955873:tid 956052] [client 213.231.6.109:38854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7XAAAATs"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:21.997453 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-request.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7XwAAAYQ"]
[Thu Sep 17 15:06:21.997560 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-request.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7XwAAAYQ"]
[Thu Sep 17 15:06:22.019580 2026] [security2:error] [pid 955873:tid 956020] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7YAAAARs"]
[Thu Sep 17 15:06:22.085419 2026] [security2:error] [pid 955873:tid 956008] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7YQAAAQ8"]
[Thu Sep 17 15:06:22.174287 2026] [security2:error] [pid 955873:tid 956093] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7YwAAAWQ"]
[Thu Sep 17 15:06:22.285196 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-response.php"] [unique_id "aqxWThFTPRVSLOsRVhr7aQAAAUs"]
[Thu Sep 17 15:06:22.285303 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:51396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-response.php"] [unique_id "aqxWThFTPRVSLOsRVhr7aQAAAUs"]
[Thu Sep 17 15:06:22.331228 2026] [security2:error] [pid 955873:tid 956003] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7awAAAQo"]
[Thu Sep 17 15:06:22.358261 2026] [security2:error] [pid 955873:tid 956102] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7bAAAAW0"]
[Thu Sep 17 15:06:22.491109 2026] [security2:error] [pid 955873:tid 956085] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7cgAAAVw"]
[Thu Sep 17 15:06:22.564812 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-server.php"] [unique_id "aqxWThFTPRVSLOsRVhr7dwAAAWw"]
[Thu Sep 17 15:06:22.564910 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-server.php"] [unique_id "aqxWThFTPRVSLOsRVhr7dwAAAWw"]
[Thu Sep 17 15:06:22.568135 2026] [security2:error] [pid 955873:tid 956040] [client 34.178.167.214:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWThFTPRVSLOsRVhr7eAAAAS8"]
[Thu Sep 17 15:06:22.580283 2026] [security2:error] [pid 955873:tid 956090] [client 20.244.34.24:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxWThFTPRVSLOsRVhr7eQAAAWE"], referer: binance.com
[Thu Sep 17 15:06:22.629984 2026] [security2:error] [pid 955873:tid 956050] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7fQAAATk"]
[Thu Sep 17 15:06:22.645935 2026] [security2:error] [pid 955873:tid 956127] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7fgAAAYY"]
[Thu Sep 17 15:06:22.806421 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWThFTPRVSLOsRVhr7gQAAAWM"]
[Thu Sep 17 15:06:22.842610 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:51416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxWThFTPRVSLOsRVhr7gwAAARg"]
[Thu Sep 17 15:06:22.902855 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7hAAAAWk"]
[Thu Sep 17 15:06:23.016598 2026] [security2:error] [pid 955873:tid 956045] [client 45.169.98.18:54949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWThFTPRVSLOsRVhr7iQAAATQ"]
[Thu Sep 17 15:06:23.016754 2026] [security2:error] [pid 955873:tid 956045] [client 45.169.98.18:54949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWThFTPRVSLOsRVhr7iQAAATQ"]
[Thu Sep 17 15:06:23.043177 2026] [authz_core:error] [pid 955873:tid 956018] [client 143.244.57.120:57096] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/endpoints/error_log
[Thu Sep 17 15:06:23.056442 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxWTxFTPRVSLOsRVhr7igAAARk"]
[Thu Sep 17 15:06:23.176186 2026] [security2:error] [pid 955873:tid 956064] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWTxFTPRVSLOsRVhr7jAAAAUc"]
[Thu Sep 17 15:06:23.196137 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:51416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/wp-includes/rest-api/"] [unique_id "aqxWTxFTPRVSLOsRVhr7jQAAAVg"]
[Thu Sep 17 15:06:23.248219 2026] [security2:error] [pid 955873:tid 956055] [client 34.178.167.214:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7lAAAAT4"]
[Thu Sep 17 15:06:23.314819 2026] [security2:error] [pid 955873:tid 956079] [client 34.154.239.243:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7nAAAAVY"]
[Thu Sep 17 15:06:23.450756 2026] [security2:error] [pid 955873:tid 956072] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWTxFTPRVSLOsRVhr7oQAAAU8"]
[Thu Sep 17 15:06:23.545567 2026] [security2:error] [pid 955873:tid 956013] [client 157.100.203.16:51280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7oAAAARQ"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:23.556110 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7ngAAAYk"]
[Thu Sep 17 15:06:23.556132 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7ngAAAYk"]
[Thu Sep 17 15:06:23.699175 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7qwAAAWc"]
[Thu Sep 17 15:06:23.699324 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:51416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7qwAAAWc"]
[Thu Sep 17 15:06:23.728624 2026] [security2:error] [pid 955873:tid 956126] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWTxFTPRVSLOsRVhr7rAAAAYU"]
[Thu Sep 17 15:06:23.806128 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.239.243:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7rwAAAUU"]
[Thu Sep 17 15:06:23.981684 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7xAAAAVU"]
[Thu Sep 17 15:06:23.981790 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7xAAAAVU"]
[Thu Sep 17 15:06:24.003501 2026] [security2:error] [pid 955873:tid 956108] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr7xwAAAXM"]
[Thu Sep 17 15:06:24.043054 2026] [security2:error] [pid 955873:tid 956005] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7xQAAAQw"], referer: http://alrayancont.com/api/session/properties
[Thu Sep 17 15:06:24.125341 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:64872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr7zwAAARE"]
[Thu Sep 17 15:06:24.125458 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:64872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr7zwAAARE"]
[Thu Sep 17 15:06:24.165146 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWUBFTPRVSLOsRVhr70gAAAXs"]
[Thu Sep 17 15:06:24.260445 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr70wAAAYA"]
[Thu Sep 17 15:06:24.260565 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr70wAAAYA"]
[Thu Sep 17 15:06:24.276475 2026] [security2:error] [pid 955873:tid 956019] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr71QAAARo"]
[Thu Sep 17 15:06:24.290757 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:52074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWUBFTPRVSLOsRVhr71gAAAXk"]
[Thu Sep 17 15:06:24.307379 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:42201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr71wAAAXA"]
[Thu Sep 17 15:06:24.307491 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:42201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr71wAAAXA"]
[Thu Sep 17 15:06:24.538602 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr74QAAAR4"]
[Thu Sep 17 15:06:24.538697 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:51450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr74QAAAR4"]
[Thu Sep 17 15:06:24.548222 2026] [security2:error] [pid 955873:tid 956004] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr74gAAAQs"]
[Thu Sep 17 15:06:24.775273 2026] [security2:error] [pid 955873:tid 956026] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWUBFTPRVSLOsRVhr75QAAASE"], referer: http://alrayancont.com/showLogin.cc
[Thu Sep 17 15:06:24.780108 2026] [security2:error] [pid 955873:tid 956125] [client 34.154.239.243:52082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWUBFTPRVSLOsRVhr76AAAAYQ"]
[Thu Sep 17 15:06:24.815024 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr76QAAAYg"]
[Thu Sep 17 15:06:24.815130 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr76QAAAYg"]
[Thu Sep 17 15:06:24.821540 2026] [security2:error] [pid 955873:tid 956044] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr76gAAATM"]
[Thu Sep 17 15:06:25.004811 2026] [security2:error] [pid 955873:tid 956016] [client 104.28.198.244:22835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr79QAAARc"]
[Thu Sep 17 15:06:25.004923 2026] [security2:error] [pid 955873:tid 956016] [client 104.28.198.244:22835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr79QAAARc"]
[Thu Sep 17 15:06:25.090112 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWURFTPRVSLOsRVhr7-AAAARs"]
[Thu Sep 17 15:06:25.092037 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr7-QAAAVU"]
[Thu Sep 17 15:06:25.092119 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr7-QAAAVU"]
[Thu Sep 17 15:06:25.098997 2026] [security2:error] [pid 955873:tid 956107] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWURFTPRVSLOsRVhr7-gAAAXI"]
[Thu Sep 17 15:06:25.248222 2026] [security2:error] [pid 955873:tid 956014] [client 34.154.239.243:52086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWURFTPRVSLOsRVhr7_gAAARU"]
[Thu Sep 17 15:06:25.315880 2026] [security2:error] [pid 955873:tid 956076] [client 37.39.223.21:53341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWURFTPRVSLOsRVhr7_AABU0E"]
[Thu Sep 17 15:06:25.372890 2026] [security2:error] [pid 955873:tid 956086] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWURFTPRVSLOsRVhr7_wAAAV0"]
[Thu Sep 17 15:06:25.376368 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AAAAAW4"]
[Thu Sep 17 15:06:25.376472 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AAAAAW4"]
[Thu Sep 17 15:06:25.403156 2026] [security2:error] [pid 955873:tid 956050] [client 186.105.232.15:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AgAAATk"]
[Thu Sep 17 15:06:25.403255 2026] [security2:error] [pid 955873:tid 956050] [client 186.105.232.15:50976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AgAAATk"]
[Thu Sep 17 15:06:25.650490 2026] [security2:error] [pid 955873:tid 956115] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWURFTPRVSLOsRVhr8DgAAAXo"]
[Thu Sep 17 15:06:25.677036 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8DwAAAYA"]
[Thu Sep 17 15:06:25.677135 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8DwAAAYA"]
[Thu Sep 17 15:06:25.729467 2026] [security2:error] [pid 955873:tid 956010] [client 34.154.239.243:52094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWURFTPRVSLOsRVhr8EwAAARE"]
[Thu Sep 17 15:06:25.923335 2026] [security2:error] [pid 955873:tid 956124] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWURFTPRVSLOsRVhr8FgAAAYM"]
[Thu Sep 17 15:06:25.950595 2026] [security2:error] [pid 955873:tid 956027] [client 34.178.167.214:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWURFTPRVSLOsRVhr8GQAAASI"]
[Thu Sep 17 15:06:25.965965 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8GgAAAU8"]
[Thu Sep 17 15:06:25.966066 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8GgAAAU8"]
[Thu Sep 17 15:06:26.195895 2026] [security2:error] [pid 955873:tid 956066] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWUhFTPRVSLOsRVhr8IgAAAUk"]
[Thu Sep 17 15:06:26.260448 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KQAAAYg"]
[Thu Sep 17 15:06:26.260520 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KQAAAYg"]
[Thu Sep 17 15:06:26.421772 2026] [security2:error] [pid 955873:tid 956013] [client 34.154.239.243:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KwAAARQ"]
[Thu Sep 17 15:06:26.468404 2026] [security2:error] [pid 955873:tid 956056] [client 94.54.188.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KAAAAT8"]
[Thu Sep 17 15:06:26.471764 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWUhFTPRVSLOsRVhr8LAAAAXQ"]
[Thu Sep 17 15:06:26.546326 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8LwAAAWU"]
[Thu Sep 17 15:06:26.546474 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:51516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8LwAAAWU"]
[Thu Sep 17 15:06:26.744815 2026] [security2:error] [pid 955873:tid 956117] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWUhFTPRVSLOsRVhr8NAAAAXw"]
[Thu Sep 17 15:06:26.766009 2026] [security2:error] [pid 955873:tid 956009] [client 34.178.167.214:57862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8NQAAARA"]
[Thu Sep 17 15:06:26.829409 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8OAAAAUU"]
[Thu Sep 17 15:06:26.829546 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:51528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8OAAAAUU"]
[Thu Sep 17 15:06:26.897167 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.239.243:52112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8PAAAAVk"]
[Thu Sep 17 15:06:27.018682 2026] [security2:error] [pid 955873:tid 956050] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWUxFTPRVSLOsRVhr8QgAAATk"]
[Thu Sep 17 15:06:27.055227 2026] [security2:error] [pid 955873:tid 956069] [client 45.146.54.109:30495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8QAAAAUw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:27.111310 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8RAAAAV4"]
[Thu Sep 17 15:06:27.111434 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:51540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8RAAAAV4"]
[Thu Sep 17 15:06:27.291491 2026] [security2:error] [pid 955873:tid 956064] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWUxFTPRVSLOsRVhr8SAAAAUc"]
[Thu Sep 17 15:06:27.360543 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.239.243:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8SQAAASg"]
[Thu Sep 17 15:06:27.397254 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8TAAAAQw"]
[Thu Sep 17 15:06:27.397339 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:51548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8TAAAAQw"]
[Thu Sep 17 15:06:27.565833 2026] [security2:error] [pid 955873:tid 956032] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWUxFTPRVSLOsRVhr8VwAAASc"]
[Thu Sep 17 15:06:27.690098 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:51556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8WgAAAWA"]
[Thu Sep 17 15:06:27.690219 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:51556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8WgAAAWA"]
[Thu Sep 17 15:06:27.747696 2026] [security2:error] [pid 955873:tid 956080] [client 94.54.188.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8VgAAAVc"]
[Thu Sep 17 15:06:27.763224 2026] [security2:error] [pid 955873:tid 956010] [client 34.178.167.214:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8XAAAARE"]
[Thu Sep 17 15:06:27.849821 2026] [security2:error] [pid 955873:tid 956085] [client 34.154.239.243:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8YQAAAVw"]
[Thu Sep 17 15:06:27.886734 2026] [security2:error] [pid 955873:tid 956118] [client 34.35.44.204:33144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8XgAAAX0"]
[Thu Sep 17 15:06:27.979149 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8ZAAAAQ0"]
[Thu Sep 17 15:06:27.979286 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8ZAAAAQ0"]
[Thu Sep 17 15:06:28.206721 2026] [security2:error] [pid 955873:tid 956129] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8agAAAYg"], referer: http://alrayancont.com/console
[Thu Sep 17 15:06:28.271932 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8awAAATs"]
[Thu Sep 17 15:06:28.272042 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:51572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8awAAATs"]
[Thu Sep 17 15:06:28.337906 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:36212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8bAAAAUE"]
[Thu Sep 17 15:06:28.459847 2026] [security2:error] [pid 955873:tid 956090] [client 20.244.34.24:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8bwAAAWE"], referer: binance.com
[Thu Sep 17 15:06:28.551429 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8cwAAARc"]
[Thu Sep 17 15:06:28.551544 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:51584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8cwAAARc"]
[Thu Sep 17 15:06:28.659504 2026] [security2:error] [pid 955873:tid 956094] [client 34.178.167.214:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8dQAAAWU"]
[Thu Sep 17 15:06:28.683644 2026] [security2:error] [pid 955873:tid 956071] [client 154.160.1.216:64942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8dAABTkQ"]
[Thu Sep 17 15:06:28.724690 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:47890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8dgAAAVU"]
[Thu Sep 17 15:06:28.801013 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.239.243:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8eAAAAYI"]
[Thu Sep 17 15:06:28.826499 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8eQAAAVk"]
[Thu Sep 17 15:06:28.826601 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:51590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8eQAAAVk"]
[Thu Sep 17 15:06:29.104220 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8hgAAAW4"]
[Thu Sep 17 15:06:29.104320 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8hgAAAW4"]
[Thu Sep 17 15:06:29.291990 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.239.243:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8kwAAASg"]
[Thu Sep 17 15:06:29.317109 2026] [core:error] [pid 955873:tid 956063] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:29.317127 2026] [core:error] [pid 955873:tid 956063] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:29.401185 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8mAAAARE"]
[Thu Sep 17 15:06:29.401297 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:51620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8mAAAARE"]
[Thu Sep 17 15:06:29.562777 2026] [security2:error] [pid 955873:tid 956028] [client 34.35.44.204:45522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8pAAAASM"]
[Thu Sep 17 15:06:29.610469 2026] [security2:error] [pid 955873:tid 956054] [client 34.178.167.214:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8pgAAAT0"]
[Thu Sep 17 15:06:29.685978 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8qwAAASs"]
[Thu Sep 17 15:06:29.686085 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:51634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8qwAAASs"]
[Thu Sep 17 15:06:29.767248 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.239.243:36226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8rQAAAYc"]
[Thu Sep 17 15:06:29.958916 2026] [security2:error] [pid 955873:tid 956112] [client 185.55.149.49:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tAAAAXc"]
[Thu Sep 17 15:06:29.959022 2026] [security2:error] [pid 955873:tid 956112] [client 185.55.149.49:53242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tAAAAXc"]
[Thu Sep 17 15:06:29.972779 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tQAAAW8"]
[Thu Sep 17 15:06:29.972872 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tQAAAW8"]
[Thu Sep 17 15:06:30.255897 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:33022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8vQAAAWk"]
[Thu Sep 17 15:06:30.255994 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:33022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8vQAAAWk"]
[Thu Sep 17 15:06:30.337977 2026] [security2:error] [pid 955873:tid 956076] [client 34.178.167.214:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8wAAAAVM"]
[Thu Sep 17 15:06:30.376628 2026] [security2:error] [pid 955873:tid 956062] [client 34.35.44.204:45538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8wQAAAUU"]
[Thu Sep 17 15:06:30.464642 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8xQAAARI"]
[Thu Sep 17 15:06:30.562005 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8yAAAAWs"]
[Thu Sep 17 15:06:30.562136 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8yAAAAWs"]
[Thu Sep 17 15:06:30.871032 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8zQAAATo"]
[Thu Sep 17 15:06:30.871153 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8zQAAATo"]
[Thu Sep 17 15:06:30.933533 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.239.243:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8zgAAAWI"]
[Thu Sep 17 15:06:31.156550 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr81gAAAVw"]
[Thu Sep 17 15:06:31.156653 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:33048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr81gAAAVw"]
[Thu Sep 17 15:06:31.195953 2026] [security2:error] [pid 955873:tid 956073] [client 34.35.44.204:45544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWVxFTPRVSLOsRVhr81wAAAVA"]
[Thu Sep 17 15:06:31.407352 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.239.243:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWVxFTPRVSLOsRVhr84AAAASQ"]
[Thu Sep 17 15:06:31.443595 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr84wAAAQo"]
[Thu Sep 17 15:06:31.443697 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:33056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr84wAAAQo"]
[Thu Sep 17 15:06:31.657532 2026] [security2:error] [pid 955873:tid 955974] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.backup"] [unique_id "aqxWVxFTPRVSLOsRVhr88QABTWQ"]
[Thu Sep 17 15:06:31.657540 2026] [security2:error] [pid 955873:tid 955970] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.bak"] [unique_id "aqxWVxFTPRVSLOsRVhr87wABTWA"]
[Thu Sep 17 15:06:31.658476 2026] [security2:error] [pid 955873:tid 955970] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.old"] [unique_id "aqxWVxFTPRVSLOsRVhr88gABTWA"]
[Thu Sep 17 15:06:31.660254 2026] [security2:error] [pid 955873:tid 955979] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env"] [unique_id "aqxWVxFTPRVSLOsRVhr8-gABTWk"]
[Thu Sep 17 15:06:31.728188 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:33058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr8_QAAAVo"]
[Thu Sep 17 15:06:31.728298 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:33058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr8_QAAAVo"]
[Thu Sep 17 15:06:31.855703 2026] [security2:error] [pid 955873:tid 956096] [client 34.178.167.214:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWVxFTPRVSLOsRVhr8_wAAAWc"]
[Thu Sep 17 15:06:31.907025 2026] [security2:error] [pid 955873:tid 956112] [client 34.154.239.243:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWVxFTPRVSLOsRVhr9AgAAAXc"]
[Thu Sep 17 15:06:31.910305 2026] [security2:error] [pid 955873:tid 956017] [client 74.7.175.183:36776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.hoffman412.org"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxWVxFTPRVSLOsRVhr9AQAAARg"]
[Thu Sep 17 15:06:31.956766 2026] [security2:error] [pid 955873:tid 956048] [client 45.156.129.166:57556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWVxFTPRVSLOsRVhr9AAAAATc"], referer: http://alrayancont.com/index.jsp
[Thu Sep 17 15:06:32.013872 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9BwAAAWU"]
[Thu Sep 17 15:06:32.013979 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:33072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9BwAAAWU"]
[Thu Sep 17 15:06:32.021164 2026] [security2:error] [pid 955873:tid 956104] [client 34.35.44.204:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9CAAAAW8"]
[Thu Sep 17 15:06:32.141739 2026] [security2:error] [pid 955873:tid 955991] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env~"] [unique_id "aqxWWBFTPRVSLOsRVhr9DgABYXU"]
[Thu Sep 17 15:06:32.141750 2026] [security2:error] [pid 955873:tid 955988] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.swp"] [unique_id "aqxWWBFTPRVSLOsRVhr9DwABYXI"]
[Thu Sep 17 15:06:32.160927 2026] [security2:error] [pid 955873:tid 955994] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9DAABYXg"]
[Thu Sep 17 15:06:32.283104 2026] [security2:error] [pid 955873:tid 955981] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/app/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9HQABU2s"]
[Thu Sep 17 15:06:32.283110 2026] [security2:error] [pid 955873:tid 955998] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/backend/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9GQABU3w"]
[Thu Sep 17 15:06:32.283122 2026] [security2:error] [pid 955873:tid 955980] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/api/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9HwABU2o"]
[Thu Sep 17 15:06:32.293762 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9IAAAAUU"]
[Thu Sep 17 15:06:32.293832 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:33074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9IAAAAUU"]
[Thu Sep 17 15:06:32.336756 2026] [security2:error] [pid 955873:tid 956000] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/server/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9IQABXX4"]
[Thu Sep 17 15:06:32.378080 2026] [security2:error] [pid 955873:tid 956022] [client 207.180.11.123:18526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/gallery_med-150x150.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9IgAAAR0"]
[Thu Sep 17 15:06:32.381020 2026] [security2:error] [pid 955873:tid 956011] [client 216.75.132.234:17332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/betty-150x150.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9IwAAARI"]
[Thu Sep 17 15:06:32.384682 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9JAAAATU"]
[Thu Sep 17 15:06:32.405329 2026] [security2:error] [pid 955873:tid 956050] [client 49.13.164.148:27042] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxWWBFTPRVSLOsRVhr9JgAAATk"], referer: https://faewave.com
[Thu Sep 17 15:06:32.450832 2026] [security2:error] [pid 955873:tid 956037] [client 143.20.253.251:44246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/gallery_children2-253x310.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9JwAAASw"]
[Thu Sep 17 15:06:32.474307 2026] [security2:error] [pid 955873:tid 956055] [client 207.180.11.251:26104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2017/04/00000314-150x150.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9LgAAAT4"]
[Thu Sep 17 15:06:32.484684 2026] [security2:error] [pid 955873:tid 956001] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/config/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9LwABOn8"]
[Thu Sep 17 15:06:32.486966 2026] [security2:error] [pid 955873:tid 955875] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/var/www/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MwABcAE"]
[Thu Sep 17 15:06:32.487003 2026] [security2:error] [pid 955873:tid 955884] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/web/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NQABcAo"]
[Thu Sep 17 15:06:32.487003 2026] [security2:error] [pid 955873:tid 955886] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/laravel/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NAABcAw"]
[Thu Sep 17 15:06:32.487029 2026] [security2:error] [pid 955873:tid 955885] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/var/www/html/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MgABcAs"]
[Thu Sep 17 15:06:32.487052 2026] [security2:error] [pid 955873:tid 955882] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/client/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NwABcAg"]
[Thu Sep 17 15:06:32.487077 2026] [security2:error] [pid 955873:tid 955887] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/public/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MAABcA0"]
[Thu Sep 17 15:06:32.487075 2026] [security2:error] [pid 955873:tid 955874] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/src/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MQABcAA"]
[Thu Sep 17 15:06:32.487142 2026] [security2:error] [pid 955873:tid 955881] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/frontend/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NgABcAc"]
[Thu Sep 17 15:06:32.501958 2026] [security2:error] [pid 955873:tid 956091] [client 216.75.132.234:17334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/children-253x310.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9OAAAAWI"]
[Thu Sep 17 15:06:32.546930 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9OQAAAYY"]
[Thu Sep 17 15:06:32.565222 2026] [security2:error] [pid 955873:tid 956061] [client 143.20.253.251:44262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/gallery_comdev2-150x150.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9OwAAAUQ"]
[Thu Sep 17 15:06:32.576454 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9PAAAASA"]
[Thu Sep 17 15:06:32.576494 2026] [security2:error] [pid 955873:tid 956004] [client 4.240.114.86:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9PQAAAQs"], referer: binance.com
[Thu Sep 17 15:06:32.576607 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9PAAAASA"]
[Thu Sep 17 15:06:32.629540 2026] [security2:error] [pid 955873:tid 955891] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/application/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9PgABQBE"]
[Thu Sep 17 15:06:32.633640 2026] [security2:error] [pid 955873:tid 955883] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/prod/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QAABLQk"]
[Thu Sep 17 15:06:32.633649 2026] [security2:error] [pid 955873:tid 955892] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/backup/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9RAABLRI"]
[Thu Sep 17 15:06:32.633722 2026] [security2:error] [pid 955873:tid 955896] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/dev/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QwABLRY"]
[Thu Sep 17 15:06:32.633751 2026] [security2:error] [pid 955873:tid 955897] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/staging/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9RgABLRc"]
[Thu Sep 17 15:06:32.633757 2026] [security2:error] [pid 955873:tid 955894] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/back/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9RQABLRQ"]
[Thu Sep 17 15:06:32.633786 2026] [security2:error] [pid 955873:tid 955890] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/production/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QQABLRA"]
[Thu Sep 17 15:06:32.633790 2026] [security2:error] [pid 955873:tid 955888] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/apps/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9PwABLQ4"]
[Thu Sep 17 15:06:32.634253 2026] [security2:error] [pid 955873:tid 955893] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/cms/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QgABLRM"]
[Thu Sep 17 15:06:32.662300 2026] [security2:error] [pid 955873:tid 956085] [client 143.14.6.71:26816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2016/10/IMG_0243-Small-Large-253x310.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9SAAAAVw"]
[Thu Sep 17 15:06:32.691156 2026] [security2:error] [pid 955873:tid 956114] [client 143.14.6.249:51776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/subpage-EngCamp-253x310.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9SQAAAXk"]
[Thu Sep 17 15:06:32.753687 2026] [core:error] [pid 955873:tid 956027] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:32.753710 2026] [core:error] [pid 955873:tid 956027] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:32.758978 2026] [security2:error] [pid 955873:tid 956010] [client 143.14.6.71:26824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/summer_camp-253x310.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9TgAAARE"]
[Thu Sep 17 15:06:32.758979 2026] [security2:error] [pid 955873:tid 956111] [client 143.14.6.41:65146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2016/10/P1020289-253x310.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9TQAAAXY"]
[Thu Sep 17 15:06:32.860196 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:45562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9UgAAAUY"]
[Thu Sep 17 15:06:32.875338 2026] [security2:error] [pid 955873:tid 956107] [client 43.130.9.111:47394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.9.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php/Breath"] [unique_id "aqxWWBFTPRVSLOsRVhr9UwAAAXI"]
[Thu Sep 17 15:06:32.884159 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9VQAAAVc"]
[Thu Sep 17 15:06:32.885425 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:33084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9VgAAAT8"]
[Thu Sep 17 15:06:32.885499 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:33084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9VgAAAT8"]
[Thu Sep 17 15:06:32.937613 2026] [security2:error] [pid 955873:tid 956119] [client 24.159.185.48:64602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9UAABfhs"]
[Thu Sep 17 15:06:33.171614 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:33086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9XQAAAVE"]
[Thu Sep 17 15:06:33.171723 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:33086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9XQAAAVE"]
[Thu Sep 17 15:06:33.297423 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:47734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9XwAAAWQ"]
[Thu Sep 17 15:06:33.454076 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:33088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ZwAAAXU"]
[Thu Sep 17 15:06:33.454192 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:33088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ZwAAAXU"]
[Thu Sep 17 15:06:33.499618 2026] [security2:error] [pid 955873:tid 956082] [client 45.169.98.18:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9aQAAAVk"]
[Thu Sep 17 15:06:33.499783 2026] [security2:error] [pid 955873:tid 956082] [client 45.169.98.18:55506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9aQAAAVk"]
[Thu Sep 17 15:06:33.741356 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9eQAAATo"]
[Thu Sep 17 15:06:33.741492 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9eQAAATo"]
[Thu Sep 17 15:06:33.798113 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.239.243:36312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWWRFTPRVSLOsRVhr9fQAAAS8"]
[Thu Sep 17 15:06:33.969880 2026] [security2:error] [pid 955873:tid 956057] [client 34.35.44.204:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9hgAAAUA"]
[Thu Sep 17 15:06:34.022676 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9igAAAXk"]
[Thu Sep 17 15:06:34.022801 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9igAAAXk"]
[Thu Sep 17 15:06:34.276533 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:36320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9lAAAASI"]
[Thu Sep 17 15:06:34.317109 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:33108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9mQAAAXI"]
[Thu Sep 17 15:06:34.317265 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:33108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9mQAAAXI"]
[Thu Sep 17 15:06:34.317749 2026] [security2:error] [pid 955873:tid 956025] [client 34.178.167.214:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9mgAAASA"]
[Thu Sep 17 15:06:34.366911 2026] [security2:error] [pid 955873:tid 955906] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/admin-app/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9nwABOCA"]
[Thu Sep 17 15:06:34.367141 2026] [security2:error] [pid 955873:tid 955877] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/old/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9nAABOAM"]
[Thu Sep 17 15:06:34.367160 2026] [security2:error] [pid 955873:tid 955895] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/test/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9ngABOBU"]
[Thu Sep 17 15:06:34.367290 2026] [security2:error] [pid 955873:tid 955899] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/new/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9mwABOBk"]
[Thu Sep 17 15:06:34.369189 2026] [security2:error] [pid 955873:tid 955898] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/node-api/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9owABOBg"]
[Thu Sep 17 15:06:34.370579 2026] [security2:error] [pid 955873:tid 955908] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/api-backend/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9nQABOCI"]
[Thu Sep 17 15:06:34.370701 2026] [security2:error] [pid 955873:tid 955971] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/public_html/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9oAABOGE"]
[Thu Sep 17 15:06:34.370748 2026] [security2:error] [pid 955873:tid 955909] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/current/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9ogABOCM"]
[Thu Sep 17 15:06:34.419633 2026] [authz_core:error] [pid 955873:tid 956111] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:06:34.425547 2026] [security2:error] [pid 955873:tid 955904] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/administrator/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9oQABOB4"]
[Thu Sep 17 15:06:34.511201 2026] [security2:error] [pid 955873:tid 955915] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qAABdCk"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955911] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/aws/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9rQABdCU"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955914] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/stripe/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9pwABdCg"]
[Thu Sep 17 15:06:34.511204 2026] [security2:error] [pid 955873:tid 955903] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.docker/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qgABdB0"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955905] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/server/backend/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9rAABdB8"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955907] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/server/api/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qwABdCE"]
[Thu Sep 17 15:06:34.511247 2026] [security2:error] [pid 955873:tid 955910] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.aws/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qQABdCQ"]
[Thu Sep 17 15:06:34.611574 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9sgAAAW8"]
[Thu Sep 17 15:06:34.611692 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9sgAAAW8"]
[Thu Sep 17 15:06:34.688305 2026] [security2:error] [pid 955873:tid 956128] [client 115.244.164.14:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9tQAAAYc"]
[Thu Sep 17 15:06:34.688416 2026] [security2:error] [pid 955873:tid 956128] [client 115.244.164.14:65514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9tQAAAYc"]
[Thu Sep 17 15:06:34.774565 2026] [security2:error] [pid 955873:tid 956015] [client 34.154.239.243:36322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9tgAAARY"]
[Thu Sep 17 15:06:34.786543 2026] [security2:error] [pid 955873:tid 956074] [client 34.35.44.204:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9twAAAVE"]
[Thu Sep 17 15:06:34.894169 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9uQAAAWs"]
[Thu Sep 17 15:06:34.894288 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9uQAAAWs"]
[Thu Sep 17 15:06:34.945397 2026] [security2:error] [pid 955873:tid 956077] [client 34.178.167.214:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9uwAAAVQ"]
[Thu Sep 17 15:06:35.056028 2026] [security2:error] [pid 955873:tid 956087] [client 24.159.185.48:51701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9vAABXjA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&hideliu=1&hidemyself=1&target=The_Lord_Of_Dwarves&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:06:35.147587 2026] [security2:error] [pid 955873:tid 956089] [client 20.244.34.24:51400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9xwAAAWA"], referer: binance.com
[Thu Sep 17 15:06:35.178242 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9yQAAAXk"]
[Thu Sep 17 15:06:35.178391 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9yQAAAXk"]
[Thu Sep 17 15:06:35.197988 2026] [security2:error] [pid 955873:tid 955923] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/v1/.env"] [unique_id "aqxWWxFTPRVSLOsRVhr9ygABRTE"]
[Thu Sep 17 15:06:35.251176 2026] [security2:error] [pid 955873:tid 956004] [client 34.154.239.243:36330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9zQAAAQs"]
[Thu Sep 17 15:06:35.374921 2026] [security2:error] [pid 955873:tid 955931] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/v2/.env"] [unique_id "aqxWWxFTPRVSLOsRVhr9zwABIjk"]
[Thu Sep 17 15:06:35.468343 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:33134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr90wAAASs"]
[Thu Sep 17 15:06:35.468479 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:33134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr90wAAASs"]
[Thu Sep 17 15:06:35.555979 2026] [security2:error] [pid 955873:tid 956044] [client 34.178.167.214:47746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr91wAAATM"]
[Thu Sep 17 15:06:35.566708 2026] [core:error] [pid 955873:tid 956008] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:35.566735 2026] [core:error] [pid 955873:tid 956008] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:35.610383 2026] [security2:error] [pid 955873:tid 956115] [client 34.35.44.204:45584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr93AAAAXo"]
[Thu Sep 17 15:06:35.720423 2026] [security2:error] [pid 955873:tid 956021] [client 34.154.239.243:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr94AAAARw"]
[Thu Sep 17 15:06:35.775449 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:33140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr95QAAAR4"]
[Thu Sep 17 15:06:35.775559 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:33140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr95QAAAR4"]
[Thu Sep 17 15:06:35.837116 2026] [security2:error] [pid 955873:tid 956111] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWWxFTPRVSLOsRVhr94wAAAXY"], referer: http://alrayancont.com/WebInterface/
[Thu Sep 17 15:06:36.056621 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr96QAAARY"]
[Thu Sep 17 15:06:36.056773 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr96QAAARY"]
[Thu Sep 17 15:06:36.190648 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.239.243:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWXBFTPRVSLOsRVhr97gAAAVk"]
[Thu Sep 17 15:06:36.201705 2026] [security2:error] [pid 955873:tid 955929] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/v3/.env"] [unique_id "aqxWXBFTPRVSLOsRVhr97wABVDc"]
[Thu Sep 17 15:06:36.281194 2026] [security2:error] [pid 955873:tid 956046] [client 34.178.167.214:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWXBFTPRVSLOsRVhr98gAAATU"]
[Thu Sep 17 15:06:36.296062 2026] [security2:error] [pid 955873:tid 956128] [client 186.105.232.15:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr98wAAAYc"]
[Thu Sep 17 15:06:36.296205 2026] [security2:error] [pid 955873:tid 956128] [client 186.105.232.15:51552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr98wAAAYc"]
[Thu Sep 17 15:06:36.350031 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99QAAATo"]
[Thu Sep 17 15:06:36.350205 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99QAAATo"]
[Thu Sep 17 15:06:36.353128 2026] [security2:error] [pid 955873:tid 955930] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/media/.env"] [unique_id "aqxWXBFTPRVSLOsRVhr99gABezg"]
[Thu Sep 17 15:06:36.381617 2026] [security2:error] [pid 955873:tid 956085] [client 104.28.198.244:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99wAAAVw"]
[Thu Sep 17 15:06:36.382107 2026] [security2:error] [pid 955873:tid 956085] [client 104.28.198.244:22531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99wAAAVw"]
[Thu Sep 17 15:06:36.414405 2026] [autoindex:error] [pid 955873:tid 956121] [client 172.239.147.162:57389] AH01276: Cannot serve directory /home3/dieselr1/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:06:36.448413 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:45590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWXBFTPRVSLOsRVhr9-gAAAWs"]
[Thu Sep 17 15:06:36.635081 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:33180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr9_wAAAUs"]
[Thu Sep 17 15:06:36.635191 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:33180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr9_wAAAUs"]
[Thu Sep 17 15:06:36.674704 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWXBFTPRVSLOsRVhr-AAAAAXk"]
[Thu Sep 17 15:06:36.926111 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:33196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BAAAATw"]
[Thu Sep 17 15:06:36.926260 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:33196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BAAAATw"]
[Thu Sep 17 15:06:36.970318 2026] [security2:error] [pid 955873:tid 956062] [client 154.190.208.131:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BQAAAUU"]
[Thu Sep 17 15:06:36.974803 2026] [security2:error] [pid 955873:tid 956062] [client 154.190.208.131:41578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BQAAAUU"]
[Thu Sep 17 15:06:37.047648 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWXRFTPRVSLOsRVhr-BwAAAWg"]
[Thu Sep 17 15:06:37.197215 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:36368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWXRFTPRVSLOsRVhr-CgAAAVc"]
[Thu Sep 17 15:06:37.218444 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxWXRFTPRVSLOsRVhr-DAAAAWo"]
[Thu Sep 17 15:06:37.281822 2026] [security2:error] [pid 955873:tid 956025] [client 34.35.44.204:45600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWXRFTPRVSLOsRVhr-EgAAASA"]
[Thu Sep 17 15:06:37.370686 2026] [security2:error] [pid 955873:tid 956059] [client 52.167.144.221:44734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxWWxFTPRVSLOsRVhr93QABQic"]
[Thu Sep 17 15:06:37.658204 2026] [authz_core:error] [pid 955873:tid 956023] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/fields/error_log
[Thu Sep 17 15:06:37.659518 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxWXRFTPRVSLOsRVhr-GgAAAR4"]
[Thu Sep 17 15:06:37.674091 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.239.243:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWXRFTPRVSLOsRVhr-IgAAAXQ"]
[Thu Sep 17 15:06:37.803170 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/wp-includes/rest-api/"] [unique_id "aqxWXRFTPRVSLOsRVhr-JQAAARY"]
[Thu Sep 17 15:06:37.813262 2026] [authz_core:error] [pid 955873:tid 956104] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:06:38.019413 2026] [security2:error] [pid 955873:tid 956070] [client 34.178.167.214:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWXhFTPRVSLOsRVhr-LAAAAU0"]
[Thu Sep 17 15:06:38.101069 2026] [security2:error] [pid 955873:tid 956093] [client 34.35.44.204:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-MAAAAWQ"]
[Thu Sep 17 15:06:38.126970 2026] [security2:error] [pid 955873:tid 956073] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-LgAAAVA"], referer: http://alrayancont.com/identity
[Thu Sep 17 15:06:38.152108 2026] [security2:error] [pid 955873:tid 956014] [client 34.154.239.243:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWXhFTPRVSLOsRVhr-MgAAARU"]
[Thu Sep 17 15:06:38.174503 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWXRFTPRVSLOsRVhr-KAAAASw"]
[Thu Sep 17 15:06:38.174526 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWXRFTPRVSLOsRVhr-KAAAASw"]
[Thu Sep 17 15:06:38.426183 2026] [security2:error] [pid 955873:tid 956061] [client 127.0.0.1:14324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxWXhFTPRVSLOsRVhr-OgAAAUQ"]
[Thu Sep 17 15:06:38.426387 2026] [security2:error] [pid 955873:tid 956033] [client 74.7.175.134:36944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.findproductivity.com"] [uri "/robots.txt"] [unique_id "aqxWXhFTPRVSLOsRVhr-OQABKEY"]
[Thu Sep 17 15:06:38.449091 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-PAAAAWI"]
[Thu Sep 17 15:06:38.449231 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-PAAAAWI"]
[Thu Sep 17 15:06:38.616378 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.239.243:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWXhFTPRVSLOsRVhr-QQAAAQw"]
[Thu Sep 17 15:06:38.725098 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-RgAAAWg"]
[Thu Sep 17 15:06:38.725197 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-RgAAAWg"]
[Thu Sep 17 15:06:38.912573 2026] [security2:error] [pid 955873:tid 956003] [client 34.35.44.204:45606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-SQAAAQo"]
[Thu Sep 17 15:06:39.003261 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-SwAAASA"]
[Thu Sep 17 15:06:39.003372 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-SwAAASA"]
[Thu Sep 17 15:06:39.088435 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.239.243:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-TgAAAWo"]
[Thu Sep 17 15:06:39.097670 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:47776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWXxFTPRVSLOsRVhr-UAAAAYg"]
[Thu Sep 17 15:06:39.291967 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:33218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-VQAAARQ"]
[Thu Sep 17 15:06:39.292083 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:33218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-VQAAARQ"]
[Thu Sep 17 15:06:39.387285 2026] [security2:error] [pid 955873:tid 956096] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-VgAAAWc"], referer: http://alrayancont.com/cgi-bin/authLogin.cgi
[Thu Sep 17 15:06:39.480203 2026] [security2:error] [pid 955873:tid 956012] [client 142.93.254.125:57696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9dwAAARM"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480203 2026] [security2:error] [pid 955873:tid 956108] [client 192.241.158.95:54234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ggAAAXM"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480574 2026] [security2:error] [pid 955873:tid 956088] [client 157.245.81.142:38880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9iQAAAV8"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480725 2026] [security2:error] [pid 955873:tid 956069] [client 157.245.81.142:38864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9eAAAAUw"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480729 2026] [security2:error] [pid 955873:tid 956067] [client 142.93.123.56:58848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9fAAAAUo"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480872 2026] [security2:error] [pid 955873:tid 956007] [client 147.182.134.140:52514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ewAAAQ4"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.561205 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.239.243:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-XwAAAUY"]
[Thu Sep 17 15:06:39.577319 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-YAAAAWE"]
[Thu Sep 17 15:06:39.577474 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:33228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-YAAAAWE"]
[Thu Sep 17 15:06:39.594914 2026] [security2:error] [pid 955873:tid 956123] [client 198.211.116.252:34128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9cwAAAYI"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.598768 2026] [security2:error] [pid 955873:tid 956050] [client 157.230.48.236:40228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9hwAAATk"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.600702 2026] [security2:error] [pid 955873:tid 956065] [client 137.184.142.69:51932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9cQAAAUg"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.725359 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-ZQAAAXQ"]
[Thu Sep 17 15:06:39.790627 2026] [security2:error] [pid 955873:tid 956046] [client 74.7.230.46:38870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kolind.com"] [uri "/robots.txt"] [unique_id "aqxWXxFTPRVSLOsRVhr-ZgABNUU"]
[Thu Sep 17 15:06:39.849068 2026] [security2:error] [pid 955873:tid 956008] [client 34.178.167.214:47782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWXxFTPRVSLOsRVhr-aAAAAQ8"]
[Thu Sep 17 15:06:39.879440 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:48618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxWXxFTPRVSLOsRVhr-agAAARU"]
[Thu Sep 17 15:06:40.032473 2026] [authz_core:error] [pid 955873:tid 956064] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/search/error_log
[Thu Sep 17 15:06:40.033495 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxWYBFTPRVSLOsRVhr-bgAAAUc"]
[Thu Sep 17 15:06:40.041922 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.239.243:55510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-bwAAASw"]
[Thu Sep 17 15:06:40.179546 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:48618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/wp-includes/rest-api/"] [unique_id "aqxWYBFTPRVSLOsRVhr-cgAAAQs"]
[Thu Sep 17 15:06:40.274628 2026] [security2:error] [pid 955873:tid 956086] [client 178.128.145.39:41482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9hQAAAV0"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:40.541476 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-eAAAAUU"]
[Thu Sep 17 15:06:40.541499 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-eAAAAUU"]
[Thu Sep 17 15:06:40.545514 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-gAAAAWg"]
[Thu Sep 17 15:06:40.550174 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-gQAAASI"]
[Thu Sep 17 15:06:40.680918 2026] [security2:error] [pid 955873:tid 956117] [client 185.55.149.49:53914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-hwAAAXw"]
[Thu Sep 17 15:06:40.681037 2026] [security2:error] [pid 955873:tid 956117] [client 185.55.149.49:53914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-hwAAAXw"]
[Thu Sep 17 15:06:40.681804 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:48618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-iAAAAXw"]
[Thu Sep 17 15:06:40.681875 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:48618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-iAAAAXw"]
[Thu Sep 17 15:06:40.714032 2026] [security2:error] [pid 955873:tid 956112] [client 4.240.114.86:64631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-igAAAXc"], referer: binance.com
[Thu Sep 17 15:06:40.814224 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:43686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-jwAAAR4"]
[Thu Sep 17 15:06:40.873317 2026] [security2:error] [pid 955873:tid 956124] [client 45.156.129.164:58684] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "aqxWYBFTPRVSLOsRVhr-kwAAAYM"]
[Thu Sep 17 15:06:40.974571 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-lgAAAVg"]
[Thu Sep 17 15:06:40.974695 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:48628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-lgAAAVg"]
[Thu Sep 17 15:06:41.035399 2026] [security2:error] [pid 955873:tid 956022] [client 34.154.239.243:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-mQAAAR0"]
[Thu Sep 17 15:06:41.053279 2026] [security2:error] [pid 955873:tid 955959] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.git/config.bak"] [unique_id "aqxWYRFTPRVSLOsRVhr-oAABVlU"]
[Thu Sep 17 15:06:41.166494 2026] [security2:error] [pid 955873:tid 956110] [client 34.178.167.214:47790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-pAAAAXU"]
[Thu Sep 17 15:06:41.245129 2026] [security2:error] [pid 955873:tid 955957] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.aws/credentials.bak"] [unique_id "aqxWYRFTPRVSLOsRVhr-qQABOlM"]
[Thu Sep 17 15:06:41.262745 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:48638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-rwAAAWQ"]
[Thu Sep 17 15:06:41.262858 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:48638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-rwAAAWQ"]
[Thu Sep 17 15:06:41.447865 2026] [security2:error] [pid 955873:tid 955979] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.ssh/id_rsa"] [unique_id "aqxWYRFTPRVSLOsRVhr-uAABT2k"]
[Thu Sep 17 15:06:41.447871 2026] [security2:error] [pid 955873:tid 955970] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/id_rsa"] [unique_id "aqxWYRFTPRVSLOsRVhr-uwABT2A"]
[Thu Sep 17 15:06:41.507574 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-vgAAAVQ"]
[Thu Sep 17 15:06:41.563189 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-wQAAAWI"]
[Thu Sep 17 15:06:41.563302 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:48644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-wQAAAWI"]
[Thu Sep 17 15:06:41.587239 2026] [security2:error] [pid 955873:tid 956005] [client 216.73.160.161:29555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gothataway.ca"] [uri "/wp-login.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-vQAAAQw"]
[Thu Sep 17 15:06:41.647367 2026] [security2:error] [pid 955873:tid 956119] [client 216.73.160.163:40471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gothataway.ca"] [uri "/wp-login.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-wgAAAX4"]
[Thu Sep 17 15:06:41.648140 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:43690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-yAAAARU"]
[Thu Sep 17 15:06:41.849276 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-0QAAAV0"]
[Thu Sep 17 15:06:41.849364 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:48658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-0QAAAV0"]
[Thu Sep 17 15:06:41.961386 2026] [security2:error] [pid 955873:tid 956004] [client 34.178.167.214:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-1wAAAQs"]
[Thu Sep 17 15:06:41.977769 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-2AAAAXk"]
[Thu Sep 17 15:06:42.012991 2026] [security2:error] [pid 955873:tid 956056] [client 3.82.141.143:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "aqxWYhFTPRVSLOsRVhr-3AAAAT8"]
[Thu Sep 17 15:06:42.029059 2026] [security2:error] [pid 955873:tid 956084] [client 3.82.141.143:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "aqxWYhFTPRVSLOsRVhr-7gAAAVs"]
[Thu Sep 17 15:06:42.032836 2026] [security2:error] [pid 955873:tid 956126] [client 3.82.141.143:19276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "aqxWYhFTPRVSLOsRVhr-8wAAAYU"]
[Thu Sep 17 15:06:42.033739 2026] [security2:error] [pid 955873:tid 956030] [client 3.82.141.143:19610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php.old"] [unique_id "aqxWYhFTPRVSLOsRVhr-_QAAASU"]
[Thu Sep 17 15:06:42.034464 2026] [security2:error] [pid 955873:tid 956010] [client 3.82.141.143:19482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/web.config"] [unique_id "aqxWYhFTPRVSLOsRVhr--QAAARE"]
[Thu Sep 17 15:06:42.035033 2026] [security2:error] [pid 955873:tid 956094] [client 3.82.141.143:19662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php~"] [unique_id "aqxWYhFTPRVSLOsRVhr_AAAAAWU"]
[Thu Sep 17 15:06:42.040670 2026] [security2:error] [pid 955873:tid 956096] [client 3.82.141.143:19632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php.save"] [unique_id "aqxWYhFTPRVSLOsRVhr_DwAAAWc"]
[Thu Sep 17 15:06:42.040929 2026] [security2:error] [pid 955873:tid 956112] [client 3.82.141.143:19612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_DgAAAXc"]
[Thu Sep 17 15:06:42.044638 2026] [security2:error] [pid 955873:tid 956088] [client 3.82.141.143:19306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "aqxWYhFTPRVSLOsRVhr_EgAAAV8"]
[Thu Sep 17 15:06:42.045676 2026] [security2:error] [pid 955873:tid 956067] [client 3.82.141.143:19472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rpimanufacturing.com"] [uri "/config.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_FQAAAUo"]
[Thu Sep 17 15:06:42.050261 2026] [security2:error] [pid 955873:tid 956018] [client 3.82.141.143:19622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php.bak"] [unique_id "aqxWYhFTPRVSLOsRVhr_FgAAARk"]
[Thu Sep 17 15:06:42.056580 2026] [core:error] [pid 955873:tid 956065] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.056592 2026] [core:error] [pid 955873:tid 956065] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.125233 2026] [core:error] [pid 955873:tid 956128] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.125251 2026] [core:error] [pid 955873:tid 956128] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.129979 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxWYhFTPRVSLOsRVhr_IAAAAQ8"]
[Thu Sep 17 15:06:42.173997 2026] [core:error] [pid 955873:tid 956019] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.174016 2026] [core:error] [pid 955873:tid 956019] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.176121 2026] [core:error] [pid 955873:tid 956077] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.176137 2026] [core:error] [pid 955873:tid 956077] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.178625 2026] [core:error] [pid 955873:tid 956127] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.178649 2026] [core:error] [pid 955873:tid 956127] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.180092 2026] [core:error] [pid 955873:tid 956075] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.180105 2026] [core:error] [pid 955873:tid 956075] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.182031 2026] [core:error] [pid 955873:tid 956037] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.182049 2026] [core:error] [pid 955873:tid 956037] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185425 2026] [core:error] [pid 955873:tid 956119] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185440 2026] [core:error] [pid 955873:tid 956119] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185782 2026] [core:error] [pid 955873:tid 956005] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185794 2026] [core:error] [pid 955873:tid 956005] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.188219 2026] [core:error] [pid 955873:tid 956033] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.188232 2026] [core:error] [pid 955873:tid 956033] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.192972 2026] [core:error] [pid 955873:tid 956014] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.192985 2026] [core:error] [pid 955873:tid 956014] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.193088 2026] [core:error] [pid 955873:tid 956043] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.193104 2026] [core:error] [pid 955873:tid 956043] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.195790 2026] [core:error] [pid 955873:tid 956026] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.195802 2026] [core:error] [pid 955873:tid 956026] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196228 2026] [core:error] [pid 955873:tid 956086] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196236 2026] [core:error] [pid 955873:tid 956086] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196441 2026] [core:error] [pid 955873:tid 956098] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196450 2026] [core:error] [pid 955873:tid 956098] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198074 2026] [core:error] [pid 955873:tid 956057] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198090 2026] [core:error] [pid 955873:tid 956057] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198466 2026] [core:error] [pid 955873:tid 956074] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198474 2026] [core:error] [pid 955873:tid 956074] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198578 2026] [core:error] [pid 955873:tid 956122] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198587 2026] [core:error] [pid 955873:tid 956122] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227875 2026] [core:error] [pid 955873:tid 956030] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227895 2026] [core:error] [pid 955873:tid 956030] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227962 2026] [core:error] [pid 955873:tid 956069] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227970 2026] [core:error] [pid 955873:tid 956069] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227995 2026] [core:error] [pid 955873:tid 956056] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.228003 2026] [core:error] [pid 955873:tid 956056] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.228051 2026] [core:error] [pid 955873:tid 956099] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.228059 2026] [core:error] [pid 955873:tid 956099] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.259999 2026] [security2:error] [pid 955873:tid 956128] [client 45.156.129.164:58694] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "aqxWYhFTPRVSLOsRVhr_OQAAAYc"]
[Thu Sep 17 15:06:42.292115 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxWYhFTPRVSLOsRVhr_PAAAAUc"]
[Thu Sep 17 15:06:42.432209 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/wp-includes/"] [unique_id "aqxWYhFTPRVSLOsRVhr_RgAAASE"]
[Thu Sep 17 15:06:42.465423 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.239.243:55564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_RwAAARg"]
[Thu Sep 17 15:06:42.481813 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_SAAAAWU"]
[Thu Sep 17 15:06:42.604975 2026] [security2:error] [pid 955873:tid 956013] [client 20.244.34.24:55373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_TgAAARQ"], referer: binance.com
[Thu Sep 17 15:06:42.777190 2026] [security2:error] [pid 955873:tid 956122] [client 34.178.167.214:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_UwAAAYE"]
[Thu Sep 17 15:06:42.781199 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_TQAAAX8"]
[Thu Sep 17 15:06:42.781221 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_TQAAAX8"]
[Thu Sep 17 15:06:42.917722 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_WwAAAS8"]
[Thu Sep 17 15:06:42.917823 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_WwAAAS8"]
[Thu Sep 17 15:06:42.948223 2026] [security2:error] [pid 955873:tid 956025] [client 34.154.239.243:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_XQAAASA"]
[Thu Sep 17 15:06:43.196416 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:48678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-provider.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_ZQAAARY"]
[Thu Sep 17 15:06:43.196512 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:48678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-provider.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_ZQAAARY"]
[Thu Sep 17 15:06:43.205778 2026] [security2:error] [pid 955873:tid 956051] [client 45.156.129.164:58700] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "aqxWYxFTPRVSLOsRVhr_ZgAAATo"]
[Thu Sep 17 15:06:43.212112 2026] [security2:error] [pid 955873:tid 955887] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_aAABcA0"]
[Thu Sep 17 15:06:43.310241 2026] [security2:error] [pid 955873:tid 956110] [client 34.35.44.204:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_bQAAAXU"]
[Thu Sep 17 15:06:43.428900 2026] [security2:error] [pid 955873:tid 956093] [client 34.154.239.243:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cAAAAWQ"]
[Thu Sep 17 15:06:43.446476 2026] [security2:error] [pid 955873:tid 956059] [client 34.178.167.214:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cQAAAUI"]
[Thu Sep 17 15:06:43.481066 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-registry.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cgAAAWs"]
[Thu Sep 17 15:06:43.481170 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:48690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-registry.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cgAAAWs"]
[Thu Sep 17 15:06:43.516399 2026] [security2:error] [pid 955873:tid 956085] [client 196.117.51.2:51262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_bwABXBI"]
[Thu Sep 17 15:06:43.704305 2026] [security2:error] [pid 955873:tid 955902] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/aws.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_gAABRRw"]
[Thu Sep 17 15:06:43.770080 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:48698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-renderer.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_hQAAAR0"]
[Thu Sep 17 15:06:43.770217 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:48698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-renderer.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_hQAAAR0"]
[Thu Sep 17 15:06:43.849616 2026] [security2:error] [pid 955873:tid 955895] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/stripe.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_iQABKBU"]
[Thu Sep 17 15:06:43.851306 2026] [security2:error] [pid 955873:tid 955899] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/mail.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_iwABKBk"]
[Thu Sep 17 15:06:43.851348 2026] [security2:error] [pid 955873:tid 955906] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/config.inc.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_jQABKCA"]
[Thu Sep 17 15:06:43.851450 2026] [security2:error] [pid 955873:tid 955908] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/nexmo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_jgABKCI"]
[Thu Sep 17 15:06:43.872231 2026] [security2:error] [pid 955873:tid 956116] [client 165.227.81.25:49414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_eQAAAXs"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:43.897667 2026] [security2:error] [pid 955873:tid 956124] [client 68.183.24.99:39320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_egAAAYM"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:43.921531 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_kgAAAVI"]
[Thu Sep 17 15:06:43.982323 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_kwAAAQw"]
[Thu Sep 17 15:06:43.982435 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:56065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_kwAAAQw"]
[Thu Sep 17 15:06:44.061612 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:48714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-stylesheet.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mQAAAVs"]
[Thu Sep 17 15:06:44.061773 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-stylesheet.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mQAAAVs"]
[Thu Sep 17 15:06:44.135271 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:43722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mgAAAWw"]
[Thu Sep 17 15:06:44.189429 2026] [security2:error] [pid 955873:tid 955900] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php.bak"] [unique_id "aqxWZBFTPRVSLOsRVhr_nAABeBo"]
[Thu Sep 17 15:06:44.189429 2026] [security2:error] [pid 955873:tid 955907] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php.new"] [unique_id "aqxWZBFTPRVSLOsRVhr_ngABeCE"]
[Thu Sep 17 15:06:44.189430 2026] [security2:error] [pid 955873:tid 955905] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php.old"] [unique_id "aqxWZBFTPRVSLOsRVhr_nQABeB8"]
[Thu Sep 17 15:06:44.189928 2026] [security2:error] [pid 955873:tid 955915] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/.wp-config.php.swp"] [unique_id "aqxWZBFTPRVSLOsRVhr_nwABeCk"]
[Thu Sep 17 15:06:44.189944 2026] [security2:error] [pid 955873:tid 955904] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mwABeB4"]
[Thu Sep 17 15:06:44.214656 2026] [security2:error] [pid 955873:tid 956086] [client 45.156.129.167:25378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxWZBFTPRVSLOsRVhr_oAAAAV0"]
[Thu Sep 17 15:06:44.327712 2026] [security2:error] [pid 955873:tid 955903] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-content/mysql.sql"] [unique_id "aqxWZBFTPRVSLOsRVhr_pwABZx0"]
[Thu Sep 17 15:06:44.336968 2026] [security2:error] [pid 955873:tid 956031] [client 34.178.167.214:58268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_qQAAASY"]
[Thu Sep 17 15:06:44.344027 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:48722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_rAAAARQ"]
[Thu Sep 17 15:06:44.344092 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:48722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_rAAAARQ"]
[Thu Sep 17 15:06:44.389409 2026] [security2:error] [pid 955873:tid 956057] [client 34.154.239.243:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_rwAAAUA"]
[Thu Sep 17 15:06:44.400498 2026] [security2:error] [pid 955873:tid 956106] [client 127.0.0.1:25386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxWZBFTPRVSLOsRVhr_rgAAAXE"]
[Thu Sep 17 15:06:44.400675 2026] [security2:error] [pid 955873:tid 956112] [client 74.7.175.164:52996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.ybo.gqk.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWZBFTPRVSLOsRVhr_rQABdys"]
[Thu Sep 17 15:06:44.669972 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:48732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxWZBFTPRVSLOsRVhr_tQAAAQ4"]
[Thu Sep 17 15:06:44.704232 2026] [security2:error] [pid 955873:tid 955927] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/terraform.tfstate.backup"] [unique_id "aqxWZBFTPRVSLOsRVhr_vQABKzU"]
[Thu Sep 17 15:06:44.781957 2026] [security2:error] [pid 955873:tid 956097] [client 37.139.53.124:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "golovefoundation.org"] [uri "/wp-login.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_uAAAAWg"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:06:44.833970 2026] [authz_core:error] [pid 955873:tid 956056] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sitemaps/providers/error_log
[Thu Sep 17 15:06:44.834814 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxWZBFTPRVSLOsRVhr_xQAAAT8"]
[Thu Sep 17 15:06:44.853310 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_zAAAATM"]
[Thu Sep 17 15:06:44.887922 2026] [security2:error] [pid 955873:tid 956046] [client 4.240.114.86:50431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_zQAAATU"], referer: binance.com
[Thu Sep 17 15:06:44.932048 2026] [security2:error] [pid 955873:tid 956038] [client 34.178.167.214:58284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_zgAAAS0"]
[Thu Sep 17 15:06:44.957748 2026] [security2:error] [pid 955873:tid 956040] [client 34.35.44.204:43726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_0AAAAS8"]
[Thu Sep 17 15:06:44.980628 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:48732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/wp-includes/sitemaps/"] [unique_id "aqxWZBFTPRVSLOsRVhr_0gAAATQ"]
[Thu Sep 17 15:06:45.043808 2026] [security2:error] [pid 955873:tid 956049] [client 66.132.186.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "162.241.8.124"] [uri "/index.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_xwAAATg"]
[Thu Sep 17 15:06:45.264690 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:49780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_3wAAAXU"]
[Thu Sep 17 15:06:45.264834 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:49780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_3wAAAXU"]
[Thu Sep 17 15:06:45.317337 2026] [security2:error] [pid 955873:tid 956020] [client 34.154.239.243:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_4gAAARs"]
[Thu Sep 17 15:06:45.394981 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_1QAAAWQ"]
[Thu Sep 17 15:06:45.395005 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_1QAAAWQ"]
[Thu Sep 17 15:06:45.410634 2026] [security2:error] [pid 955873:tid 956087] [client 154.190.208.131:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_5gAAAV4"]
[Thu Sep 17 15:06:45.415163 2026] [security2:error] [pid 955873:tid 956087] [client 154.190.208.131:42096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_5gAAAV4"]
[Thu Sep 17 15:06:45.541125 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_7gAAAT4"]
[Thu Sep 17 15:06:45.541234 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:48732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_7gAAAT4"]
[Thu Sep 17 15:06:45.726497 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_9AAAAYY"]
[Thu Sep 17 15:06:45.817113 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxWZRFTPRVSLOsRVhr__gAAAXI"]
[Thu Sep 17 15:06:45.817209 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:48736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxWZRFTPRVSLOsRVhr__gAAAXI"]
[Thu Sep 17 15:06:45.991672 2026] [security2:error] [pid 955873:tid 956117] [client 74.7.244.38:35176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bnb.sib.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWZRFTPRVSLOsRVhoABgABfEM"]
[Thu Sep 17 15:06:46.050263 2026] [security2:error] [pid 955873:tid 956069] [client 40.77.167.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ritamayblog.com"] [uri "/index.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_xAAAAUw"]
[Thu Sep 17 15:06:46.107439 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxWZhFTPRVSLOsRVhoADQAAAUo"]
[Thu Sep 17 15:06:46.107529 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:48750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxWZhFTPRVSLOsRVhoADQAAAUo"]
[Thu Sep 17 15:06:46.359509 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:43736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWZhFTPRVSLOsRVhoAFwAAAW4"]
[Thu Sep 17 15:06:46.402344 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxWZhFTPRVSLOsRVhoAJgAAARA"]
[Thu Sep 17 15:06:46.420285 2026] [security2:error] [pid 955873:tid 956045] [client 34.178.167.214:58288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAJwAAATQ"]
[Thu Sep 17 15:06:46.572872 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxWZhFTPRVSLOsRVhoAMQAAAWM"]
[Thu Sep 17 15:06:46.598989 2026] [security2:error] [pid 955873:tid 956119] [client 45.156.129.167:15738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "aqxWZhFTPRVSLOsRVhoAPwAAAX4"]
[Thu Sep 17 15:06:46.737181 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/wp-includes/"] [unique_id "aqxWZhFTPRVSLOsRVhoASgAAASk"]
[Thu Sep 17 15:06:46.776540 2026] [security2:error] [pid 955873:tid 956073] [client 74.7.241.136:56614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.hdu.jxc.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxWZhFTPRVSLOsRVhoATAAAAVA"]
[Thu Sep 17 15:06:47.066853 2026] [security2:error] [pid 955873:tid 956010] [client 41.56.188.14:29052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAUQABEVw"]
[Thu Sep 17 15:06:47.101609 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAUAAAAVs"]
[Thu Sep 17 15:06:47.101645 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAUAAAAVs"]
[Thu Sep 17 15:06:47.185656 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:43738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAVwAAAWw"]
[Thu Sep 17 15:06:47.247819 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxWZxFTPRVSLOsRVhoAXAAAAVY"]
[Thu Sep 17 15:06:47.253311 2026] [security2:error] [pid 955873:tid 956055] [client 104.28.198.244:22780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAXQAAAT4"]
[Thu Sep 17 15:06:47.253459 2026] [security2:error] [pid 955873:tid 956055] [client 104.28.198.244:22780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAXQAAAT4"]
[Thu Sep 17 15:06:47.304515 2026] [security2:error] [pid 955873:tid 955983] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAawABVW0"]
[Thu Sep 17 15:06:47.304548 2026] [security2:error] [pid 955873:tid 955986] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/info.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAbQABVXA"]
[Thu Sep 17 15:06:47.350826 2026] [security2:error] [pid 955873:tid 956017] [client 34.178.167.214:58302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAbgAAARg"]
[Thu Sep 17 15:06:47.375309 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:52157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAcAAAAWU"]
[Thu Sep 17 15:06:47.385625 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:52157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAcAAAAWU"]
[Thu Sep 17 15:06:47.388805 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxWZxFTPRVSLOsRVhoAcQAAAW0"]
[Thu Sep 17 15:06:47.468736 2026] [security2:error] [pid 955873:tid 955992] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAegABM3Y"]
[Thu Sep 17 15:06:47.468750 2026] [security2:error] [pid 955873:tid 955998] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/infophp.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAdQABM3w"]
[Thu Sep 17 15:06:47.468786 2026] [security2:error] [pid 955873:tid 955994] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/php.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAeQABM3g"]
[Thu Sep 17 15:06:47.468807 2026] [security2:error] [pid 955873:tid 955996] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/api/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAfAABM3o"]
[Thu Sep 17 15:06:47.468839 2026] [security2:error] [pid 955873:tid 956001] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/public/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAfQABM38"]
[Thu Sep 17 15:06:47.468859 2026] [security2:error] [pid 955873:tid 955990] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/infos.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAdAABM3Q"]
[Thu Sep 17 15:06:47.468896 2026] [security2:error] [pid 955873:tid 955980] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/php-info.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAeAABM2o"]
[Thu Sep 17 15:06:47.468941 2026] [security2:error] [pid 955873:tid 955982] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/php_info.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAcwABM2w"]
[Thu Sep 17 15:06:47.468964 2026] [security2:error] [pid 955873:tid 955969] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/admin_phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAewABM18"]
[Thu Sep 17 15:06:47.468967 2026] [security2:error] [pid 955873:tid 955984] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAdwABM24"]
[Thu Sep 17 15:06:47.535226 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAggAAAS8"]
[Thu Sep 17 15:06:47.535317 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAggAAAS8"]
[Thu Sep 17 15:06:47.622913 2026] [security2:error] [pid 955873:tid 956025] [client 45.156.129.166:41386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "aqxWZxFTPRVSLOsRVhoAhAAAASA"]
[Thu Sep 17 15:06:47.817060 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAjQAAAUs"]
[Thu Sep 17 15:06:47.817186 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:48770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAjQAAAUs"]
[Thu Sep 17 15:06:48.018149 2026] [security2:error] [pid 955873:tid 956046] [client 34.35.44.204:43748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAlAAAATU"]
[Thu Sep 17 15:06:48.122079 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:48784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxWaBFTPRVSLOsRVhoAlgAAAXM"]
[Thu Sep 17 15:06:48.214740 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:58316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAoQAAAXs"]
[Thu Sep 17 15:06:48.276967 2026] [authz_core:error] [pid 955873:tid 956003] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/lib/error_log
[Thu Sep 17 15:06:48.281578 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxWaBFTPRVSLOsRVhoAowAAAQo"]
[Thu Sep 17 15:06:48.328352 2026] [security2:error] [pid 955873:tid 955883] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/database.sql"] [unique_id "aqxWaBFTPRVSLOsRVhoAqwABMgk"]
[Thu Sep 17 15:06:48.382000 2026] [security2:error] [pid 955873:tid 956124] [client 4.240.114.86:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAswAAAYM"], referer: binance.com
[Thu Sep 17 15:06:48.420073 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:48784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/wp-includes/sodium_compat/"] [unique_id "aqxWaBFTPRVSLOsRVhoAtQAAAV0"]
[Thu Sep 17 15:06:48.778020 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAvQAAASY"]
[Thu Sep 17 15:06:48.778047 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAvQAAASY"]
[Thu Sep 17 15:06:48.841561 2026] [security2:error] [pid 955873:tid 956081] [client 34.35.44.204:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAxQAAAVg"]
[Thu Sep 17 15:06:48.896062 2026] [security2:error] [pid 955873:tid 956057] [client 34.178.167.214:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAxwAAAUA"]
[Thu Sep 17 15:06:48.917588 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAyAAAAQ4"]
[Thu Sep 17 15:06:48.917756 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:48784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAyAAAAQ4"]
[Thu Sep 17 15:06:49.099680 2026] [security2:error] [pid 955873:tid 956083] [client 45.156.129.166:41402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/groma-canary-not-a-real-plugin/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoAzQAAAVo"]
[Thu Sep 17 15:06:49.204984 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:48786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxWaRFTPRVSLOsRVhoA0AAAASc"]
[Thu Sep 17 15:06:49.205126 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:48786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxWaRFTPRVSLOsRVhoA0AAAASc"]
[Thu Sep 17 15:06:49.227297 2026] [security2:error] [pid 955873:tid 956040] [client 45.156.129.165:55552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA0wAAAS8"]
[Thu Sep 17 15:06:49.227491 2026] [security2:error] [pid 955873:tid 956096] [client 45.156.129.164:38680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1AAAAWc"]
[Thu Sep 17 15:06:49.227699 2026] [security2:error] [pid 955873:tid 956038] [client 45.156.129.164:38670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1QAAAS0"]
[Thu Sep 17 15:06:49.240302 2026] [security2:error] [pid 955873:tid 956103] [client 45.156.129.164:38692] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1gAAAW4"]
[Thu Sep 17 15:06:49.240947 2026] [security2:error] [pid 955873:tid 956109] [client 45.156.129.167:15740] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1wAAAXQ"]
[Thu Sep 17 15:06:49.247270 2026] [security2:error] [pid 955873:tid 956106] [client 45.156.129.164:38704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA2QAAAXE"]
[Thu Sep 17 15:06:49.256252 2026] [security2:error] [pid 955873:tid 956009] [client 45.156.129.166:41404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA2gAAARA"]
[Thu Sep 17 15:06:49.257764 2026] [security2:error] [pid 955873:tid 956090] [client 45.156.129.165:55556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA2wAAAWE"]
[Thu Sep 17 15:06:49.263308 2026] [security2:error] [pid 955873:tid 956045] [client 45.156.129.165:55566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3AAAATQ"]
[Thu Sep 17 15:06:49.263443 2026] [security2:error] [pid 955873:tid 956025] [client 45.156.129.166:41416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3QAAASA"]
[Thu Sep 17 15:06:49.264000 2026] [security2:error] [pid 955873:tid 956016] [client 45.156.129.164:38720] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3gAAARc"]
[Thu Sep 17 15:06:49.268474 2026] [security2:error] [pid 955873:tid 956063] [client 45.156.129.166:41412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3wAAAUY"]
[Thu Sep 17 15:06:49.271685 2026] [security2:error] [pid 955873:tid 956085] [client 45.156.129.164:38736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4AAAAVw"]
[Thu Sep 17 15:06:49.273074 2026] [security2:error] [pid 955873:tid 956118] [client 45.156.129.165:55578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4QAAAX0"]
[Thu Sep 17 15:06:49.280187 2026] [security2:error] [pid 955873:tid 956110] [client 45.156.129.165:55580] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4gAAAXU"]
[Thu Sep 17 15:06:49.289808 2026] [security2:error] [pid 955873:tid 956068] [client 45.156.129.165:55594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4wAAAUs"]
[Thu Sep 17 15:06:49.292286 2026] [security2:error] [pid 955873:tid 956092] [client 45.156.129.167:15748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5AAAAWM"]
[Thu Sep 17 15:06:49.299337 2026] [security2:error] [pid 955873:tid 956125] [client 45.156.129.164:38748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5QAAAYQ"]
[Thu Sep 17 15:06:49.305629 2026] [security2:error] [pid 955873:tid 956064] [client 45.156.129.167:15742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5gAAAUc"]
[Thu Sep 17 15:06:49.305807 2026] [security2:error] [pid 955873:tid 956042] [client 45.156.129.167:15762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5wAAATE"]
[Thu Sep 17 15:06:49.306028 2026] [security2:error] [pid 955873:tid 956119] [client 45.156.129.164:38764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6AAAAX4"]
[Thu Sep 17 15:06:49.311414 2026] [security2:error] [pid 955873:tid 956074] [client 45.156.129.165:55606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6QAAAVE"]
[Thu Sep 17 15:06:49.317885 2026] [security2:error] [pid 955873:tid 956020] [client 45.156.129.167:15770] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6gAAARs"]
[Thu Sep 17 15:06:49.322806 2026] [security2:error] [pid 955873:tid 956046] [client 45.156.129.164:38772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6wAAATU"]
[Thu Sep 17 15:06:49.322917 2026] [security2:error] [pid 955873:tid 956015] [client 45.156.129.167:15768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7AAAARY"]
[Thu Sep 17 15:06:49.322996 2026] [security2:error] [pid 955873:tid 956108] [client 45.156.129.165:55596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7QAAAXM"]
[Thu Sep 17 15:06:49.327546 2026] [security2:error] [pid 955873:tid 956071] [client 45.156.129.166:41436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7gAAAU4"]
[Thu Sep 17 15:06:49.333987 2026] [security2:error] [pid 955873:tid 956075] [client 45.156.129.167:15800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7wAAAVI"]
[Thu Sep 17 15:06:49.337207 2026] [security2:error] [pid 955873:tid 956116] [client 45.156.129.166:41420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8AAAAXs"]
[Thu Sep 17 15:06:49.338809 2026] [security2:error] [pid 955873:tid 956073] [client 45.156.129.167:15816] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8QAAAVA"]
[Thu Sep 17 15:06:49.343495 2026] [security2:error] [pid 955873:tid 956126] [client 45.156.129.164:38788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8gAAAYU"]
[Thu Sep 17 15:06:49.343603 2026] [security2:error] [pid 955873:tid 956029] [client 45.156.129.165:55614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8wAAASQ"]
[Thu Sep 17 15:06:49.345161 2026] [security2:error] [pid 955873:tid 956091] [client 45.156.129.166:41446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9AAAAWI"]
[Thu Sep 17 15:06:49.350004 2026] [security2:error] [pid 955873:tid 956043] [client 45.156.129.165:55610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9QAAATI"]
[Thu Sep 17 15:06:49.350753 2026] [security2:error] [pid 955873:tid 956123] [client 45.156.129.164:38786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9gAAAYI"]
[Thu Sep 17 15:06:49.353908 2026] [security2:error] [pid 955873:tid 956080] [client 45.156.129.167:15784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9wAAAVc"]
[Thu Sep 17 15:06:49.356376 2026] [security2:error] [pid 955873:tid 956124] [client 45.156.129.164:38792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-AAAAYM"]
[Thu Sep 17 15:06:49.359505 2026] [security2:error] [pid 955873:tid 956086] [client 45.156.129.165:55640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-QAAAV0"]
[Thu Sep 17 15:06:49.360346 2026] [security2:error] [pid 955873:tid 956006] [client 45.156.129.165:55632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-gAAAQ0"]
[Thu Sep 17 15:06:49.361977 2026] [security2:error] [pid 955873:tid 956028] [client 45.156.129.165:55622] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-wAAASM"]
[Thu Sep 17 15:06:49.362796 2026] [security2:error] [pid 955873:tid 956010] [client 45.156.129.164:38814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA_AAAARE"]
[Thu Sep 17 15:06:49.371385 2026] [security2:error] [pid 955873:tid 956088] [client 45.156.129.164:38844] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA_QAAAV8"]
[Thu Sep 17 15:06:49.375932 2026] [security2:error] [pid 955873:tid 956105] [client 45.156.129.164:38800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA_gAAAXA"]
[Thu Sep 17 15:06:49.383128 2026] [security2:error] [pid 955873:tid 956024] [client 45.156.129.164:38830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAAAAAR8"]
[Thu Sep 17 15:06:49.390566 2026] [security2:error] [pid 955873:tid 956079] [client 45.156.129.165:55642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAQAAAVY"]
[Thu Sep 17 15:06:49.395117 2026] [security2:error] [pid 955873:tid 956026] [client 45.156.129.166:41448] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAgAAASE"]
[Thu Sep 17 15:06:49.399873 2026] [security2:error] [pid 955873:tid 956062] [client 45.156.129.166:41458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAwAAAUU"]
[Thu Sep 17 15:06:49.407902 2026] [security2:error] [pid 955873:tid 956057] [client 45.156.129.165:55648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBBAAAAUA"]
[Thu Sep 17 15:06:49.416044 2026] [security2:error] [pid 955873:tid 956054] [client 45.156.129.164:38824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBBQAAAT0"]
[Thu Sep 17 15:06:49.454286 2026] [security2:error] [pid 955873:tid 956030] [client 45.156.129.164:38856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBBwAAASU"]
[Thu Sep 17 15:06:49.494886 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:48802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBCQAAAWo"]
[Thu Sep 17 15:06:49.494982 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:48802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBCQAAAWo"]
[Thu Sep 17 15:06:49.608110 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:58332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBCgAAAR4"]
[Thu Sep 17 15:06:49.616397 2026] [security2:error] [pid 955873:tid 956103] [client 45.156.129.165:55662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBCwAAAW4"]
[Thu Sep 17 15:06:49.672263 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBDQAAAVU"]
[Thu Sep 17 15:06:49.776771 2026] [security2:error] [pid 955873:tid 956085] [client 37.139.53.124:52317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAkQAAARY"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:06:49.785827 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:48810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBEwAAATg"]
[Thu Sep 17 15:06:49.785930 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:48810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBEwAAATg"]
[Thu Sep 17 15:06:50.072091 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:38180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBGQAAAYQ"]
[Thu Sep 17 15:06:50.072214 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:38180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBGQAAAYQ"]
[Thu Sep 17 15:06:50.082072 2026] [security2:error] [pid 955873:tid 956022] [client 20.244.34.24:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxWahFTPRVSLOsRVhoBGgAAAR0"], referer: binance.com
[Thu Sep 17 15:06:50.304260 2026] [security2:error] [pid 955873:tid 956046] [client 162.241.226.11:50220] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWahFTPRVSLOsRVhoBHgAAATU"]
[Thu Sep 17 15:06:50.316354 2026] [security2:error] [pid 955873:tid 956093] [client 4.240.114.86:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxWahFTPRVSLOsRVhoBHwAAAWQ"], referer: binance.com
[Thu Sep 17 15:06:50.319473 2026] [security2:error] [pid 955873:tid 956068] [client 181.46.66.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBFQAAAUs"], referer: https://devilsarmynetwork.com
[Thu Sep 17 15:06:50.328767 2026] [security2:error] [pid 955873:tid 956075] [client 169.58.198.243:51544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/shell/about.php"] [unique_id "aqxWahFTPRVSLOsRVhoBIAAAAVI"], referer: www.google.com
[Thu Sep 17 15:06:50.358874 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxWahFTPRVSLOsRVhoBJwAAAU0"]
[Thu Sep 17 15:06:50.358994 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:38190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxWahFTPRVSLOsRVhoBJwAAAU0"]
[Thu Sep 17 15:06:50.400835 2026] [security2:error] [pid 955873:tid 956074] [client 34.178.167.214:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWahFTPRVSLOsRVhoBKAAAAVE"]
[Thu Sep 17 15:06:50.495531 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:36432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWahFTPRVSLOsRVhoBLwAAARU"]
[Thu Sep 17 15:06:50.672234 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:38194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxWahFTPRVSLOsRVhoBOAAAAVY"]
[Thu Sep 17 15:06:50.672354 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:38194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxWahFTPRVSLOsRVhoBOAAAAVY"]
[Thu Sep 17 15:06:50.682775 2026] [security2:error] [pid 955873:tid 955888] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/localhost.sql"] [unique_id "aqxWahFTPRVSLOsRVhoBOwABIQ4"]
[Thu Sep 17 15:06:50.961219 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:38208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBRQAAAXg"]
[Thu Sep 17 15:06:50.961341 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:38208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBRQAAAXg"]
[Thu Sep 17 15:06:51.125114 2026] [security2:error] [pid 955873:tid 956027] [client 78.161.201.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWahFTPRVSLOsRVhoBQgAAASI"]
[Thu Sep 17 15:06:51.246112 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBSAAAAT8"]
[Thu Sep 17 15:06:51.246219 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:38216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBSAAAAT8"]
[Thu Sep 17 15:06:51.337364 2026] [security2:error] [pid 955873:tid 956069] [client 34.35.44.204:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWaxFTPRVSLOsRVhoBTwAAAUw"]
[Thu Sep 17 15:06:51.352074 2026] [security2:error] [pid 955873:tid 956012] [client 185.55.149.49:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBUAAAARM"]
[Thu Sep 17 15:06:51.352185 2026] [security2:error] [pid 955873:tid 956012] [client 185.55.149.49:61280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBUAAAARM"]
[Thu Sep 17 15:06:51.530430 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxWaxFTPRVSLOsRVhoBUwAAASs"]
[Thu Sep 17 15:06:51.588869 2026] [security2:error] [pid 955873:tid 956106] [client 45.156.129.167:15834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "aqxWaxFTPRVSLOsRVhoBVwAAAXE"]
[Thu Sep 17 15:06:51.684846 2026] [authz_core:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/error_log
[Thu Sep 17 15:06:51.693225 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxWaxFTPRVSLOsRVhoBWAAAAVU"]
[Thu Sep 17 15:06:51.834778 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:38226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/wp-includes/sodium_compat/"] [unique_id "aqxWaxFTPRVSLOsRVhoBZAAAAR0"]
[Thu Sep 17 15:06:51.857956 2026] [security2:error] [pid 955873:tid 955917] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/backend-api/.env"] [unique_id "aqxWaxFTPRVSLOsRVhoBZwABLCs"]
[Thu Sep 17 15:06:52.150265 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWbBFTPRVSLOsRVhoBbwAAAWs"]
[Thu Sep 17 15:06:52.176229 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBawAAAVM"]
[Thu Sep 17 15:06:52.176261 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBawAAAVM"]
[Thu Sep 17 15:06:52.277705 2026] [security2:error] [pid 955873:tid 955920] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/sql/.env"] [unique_id "aqxWbBFTPRVSLOsRVhoBdAABZC4"]
[Thu Sep 17 15:06:52.277895 2026] [security2:error] [pid 955873:tid 955926] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/db.bak"] [unique_id "aqxWbBFTPRVSLOsRVhoBdQABZDQ"]
[Thu Sep 17 15:06:52.315650 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxWbBFTPRVSLOsRVhoBfAAAATo"]
[Thu Sep 17 15:06:52.315746 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxWbBFTPRVSLOsRVhoBfAAAATo"]
[Thu Sep 17 15:06:52.594540 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWbBFTPRVSLOsRVhoBiAAAARE"]
[Thu Sep 17 15:06:52.759578 2026] [authz_core:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/error_log
[Thu Sep 17 15:06:52.787889 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWbBFTPRVSLOsRVhoBjwAAARo"]
[Thu Sep 17 15:06:52.927732 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxWbBFTPRVSLOsRVhoBmQAAAXo"]
[Thu Sep 17 15:06:52.972505 2026] [security2:error] [pid 955873:tid 956024] [client 34.35.44.204:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWbBFTPRVSLOsRVhoBngAAAR8"]
[Thu Sep 17 15:06:53.240303 2026] [security2:error] [pid 955873:tid 956058] [client 4.240.114.86:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBpgAAAUE"], referer: binance.com
[Thu Sep 17 15:06:53.278089 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBogAAATw"]
[Thu Sep 17 15:06:53.278114 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBogAAATw"]
[Thu Sep 17 15:06:53.418498 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:38232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBrgAAARM"]
[Thu Sep 17 15:06:53.418606 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBrgAAARM"]
[Thu Sep 17 15:06:53.428110 2026] [security2:error] [pid 955873:tid 956040] [client 45.156.129.167:15860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "aqxWbRFTPRVSLOsRVhoBsAAAAS8"]
[Thu Sep 17 15:06:53.719458 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:38234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBugAAAVs"]
[Thu Sep 17 15:06:53.719571 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:38234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBugAAAVs"]
[Thu Sep 17 15:06:53.834167 2026] [security2:error] [pid 955873:tid 956009] [client 34.35.44.204:36466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWbRFTPRVSLOsRVhoBwQAAARA"]
[Thu Sep 17 15:06:54.011545 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:38250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxWbhFTPRVSLOsRVhoBxwAAAVM"]
[Thu Sep 17 15:06:54.167985 2026] [authz_core:error] [pid 955873:tid 956119] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/ChaCha20/error_log
[Thu Sep 17 15:06:54.170608 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxWbhFTPRVSLOsRVhoByQAAAX4"]
[Thu Sep 17 15:06:54.311814 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:38250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWbhFTPRVSLOsRVhoB0QAAAV0"]
[Thu Sep 17 15:06:54.402418 2026] [security2:error] [pid 955873:tid 956124] [client 181.45.133.126:7100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB0AABg00"]
[Thu Sep 17 15:06:54.452101 2026] [security2:error] [pid 955873:tid 956077] [client 37.139.53.124:52741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBaQAAATs"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:06:54.458129 2026] [security2:error] [pid 955873:tid 956010] [client 45.169.98.18:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB1QAAARE"]
[Thu Sep 17 15:06:54.458233 2026] [security2:error] [pid 955873:tid 956010] [client 45.169.98.18:56733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB1QAAARE"]
[Thu Sep 17 15:06:54.646624 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB0wAAAYU"]
[Thu Sep 17 15:06:54.646649 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB0wAAAYU"]
[Thu Sep 17 15:06:54.676138 2026] [security2:error] [pid 955873:tid 956104] [client 34.35.44.204:36468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWbhFTPRVSLOsRVhoB2QAAAW8"]
[Thu Sep 17 15:06:54.825076 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:38250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB4AAAAX8"]
[Thu Sep 17 15:06:54.825181 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:38250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB4AAAAX8"]
[Thu Sep 17 15:06:54.841805 2026] [security2:error] [pid 955873:tid 956105] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB1wABcE8"]
[Thu Sep 17 15:06:55.125225 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:38256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB5AAAAUg"]
[Thu Sep 17 15:06:55.125332 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:38256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB5AAAAUg"]
[Thu Sep 17 15:06:55.168997 2026] [security2:error] [pid 955873:tid 956130] [client 45.156.129.165:55668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxWbxFTPRVSLOsRVhoB5QAAAYk"]
[Thu Sep 17 15:06:55.292978 2026] [autoindex:error] [pid 955873:tid 956055] [client 34.178.167.214:45048] AH01276: Cannot serve directory /home1/gscqjxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:55.401598 2026] [security2:error] [pid 955873:tid 956127] [client 4.240.114.86:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB7QAAAYY"], referer: binance.com
[Thu Sep 17 15:06:55.415669 2026] [security2:error] [pid 955873:tid 956026] [client 169.58.198.243:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB8AAAASE"], referer: www.google.com
[Thu Sep 17 15:06:55.415675 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB7wAAAUk"]
[Thu Sep 17 15:06:55.415789 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB7wAAAUk"]
[Thu Sep 17 15:06:55.500856 2026] [security2:error] [pid 955873:tid 956042] [client 34.35.44.204:36482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB9AAAATE"]
[Thu Sep 17 15:06:55.696025 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxWbxFTPRVSLOsRVhoB-AAAAW4"]
[Thu Sep 17 15:06:55.785327 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB-wAAATM"]
[Thu Sep 17 15:06:55.785431 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:50422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB-wAAATM"]
[Thu Sep 17 15:06:55.851274 2026] [authz_core:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/error_log
[Thu Sep 17 15:06:55.859680 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxWbxFTPRVSLOsRVhoB_QAAASw"]
[Thu Sep 17 15:06:55.950809 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:41333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoCAwAAASs"]
[Thu Sep 17 15:06:55.950957 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:41333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoCAwAAASs"]
[Thu Sep 17 15:06:56.002803 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWcBFTPRVSLOsRVhoCBQAAASc"]
[Thu Sep 17 15:06:56.042616 2026] [fcgid:warn] [pid 955873:tid 956041] (70014)End of file found: [client 199.45.155.30:41016] mod_fcgid: can't get data from http client
[Thu Sep 17 15:06:56.323690 2026] [security2:error] [pid 955873:tid 956125] [client 45.156.129.166:47282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "aqxWcBFTPRVSLOsRVhoCDwAAAYQ"]
[Thu Sep 17 15:06:56.340215 2026] [security2:error] [pid 955873:tid 956128] [client 47.79.202.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWbxFTPRVSLOsRVhoCBAAAAYc"], referer: https://www.google.com/
[Thu Sep 17 15:06:56.348841 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:36494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCEAAAAWk"]
[Thu Sep 17 15:06:56.356350 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCCQAAAXE"]
[Thu Sep 17 15:06:56.356389 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCCQAAAXE"]
[Thu Sep 17 15:06:56.516186 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCFQAAAUM"]
[Thu Sep 17 15:06:56.516348 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCFQAAAUM"]
[Thu Sep 17 15:06:56.759418 2026] [security2:error] [pid 955873:tid 956019] [client 194.163.128.162:57229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wildamerika.com"] [uri "/index.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB_gAAARo"], referer: binance.com
[Thu Sep 17 15:06:56.783700 2026] [security2:error] [pid 955873:tid 956052] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCBwABO1A"]
[Thu Sep 17 15:06:56.880825 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:38286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxWcBFTPRVSLOsRVhoCIQAAAXc"]
[Thu Sep 17 15:06:56.993711 2026] [security2:error] [pid 955873:tid 956014] [client 191.92.189.134:55798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCIAABFUo"]
[Thu Sep 17 15:06:57.038401 2026] [authz_core:error] [pid 955873:tid 956101] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/error_log
[Thu Sep 17 15:06:57.042574 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxWcRFTPRVSLOsRVhoCIgAAAWw"]
[Thu Sep 17 15:06:57.171048 2026] [security2:error] [pid 955873:tid 956079] [client 34.35.44.204:36508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCJgAAAVY"]
[Thu Sep 17 15:06:57.180564 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:38286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxWcRFTPRVSLOsRVhoCJwAAAXA"]
[Thu Sep 17 15:06:57.346527 2026] [security2:error] [pid 955873:tid 956065] [client 45.156.129.164:59664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "aqxWcRFTPRVSLOsRVhoCMAAAAUg"]
[Thu Sep 17 15:06:57.535448 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCLwAAAYg"]
[Thu Sep 17 15:06:57.535472 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCLwAAAYg"]
[Thu Sep 17 15:06:57.725926 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCNwAAATE"]
[Thu Sep 17 15:06:57.726074 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCNwAAATE"]
[Thu Sep 17 15:06:57.782158 2026] [security2:error] [pid 955873:tid 956061] [client 104.28.198.244:22674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCOAAAAUQ"]
[Thu Sep 17 15:06:57.782299 2026] [security2:error] [pid 955873:tid 956061] [client 104.28.198.244:22674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCOAAAAUQ"]
[Thu Sep 17 15:06:57.991788 2026] [security2:error] [pid 955873:tid 956053] [client 34.35.44.204:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCPgAAATw"]
[Thu Sep 17 15:06:58.010256 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:38292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWchFTPRVSLOsRVhoCPwAAATg"]
[Thu Sep 17 15:06:58.010338 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:38292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWchFTPRVSLOsRVhoCPwAAATg"]
[Thu Sep 17 15:06:58.136420 2026] [security2:error] [pid 955873:tid 956037] [client 4.240.114.86:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxWchFTPRVSLOsRVhoCQgAAASw"], referer: binance.com
[Thu Sep 17 15:06:58.296620 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWchFTPRVSLOsRVhoCQwAAASs"]
[Thu Sep 17 15:06:58.296775 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWchFTPRVSLOsRVhoCQwAAASs"]
[Thu Sep 17 15:06:58.307818 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:52744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWchFTPRVSLOsRVhoCRwAAASQ"]
[Thu Sep 17 15:06:58.307923 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:52744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWchFTPRVSLOsRVhoCRwAAASQ"]
[Thu Sep 17 15:06:58.575948 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWchFTPRVSLOsRVhoCUQAAATo"]
[Thu Sep 17 15:06:58.576062 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWchFTPRVSLOsRVhoCUQAAATo"]
[Thu Sep 17 15:06:58.837677 2026] [security2:error] [pid 955873:tid 956046] [client 34.35.44.204:36528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWAAAATU"]
[Thu Sep 17 15:06:58.838764 2026] [security2:error] [pid 955873:tid 956119] [client 17.166.153.136:39682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWchFTPRVSLOsRVhoCUgABfmM"]
[Thu Sep 17 15:06:58.880920 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:38322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWwAAARo"]
[Thu Sep 17 15:06:58.881035 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:38322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWwAAARo"]
[Thu Sep 17 15:06:58.922803 2026] [security2:error] [pid 955873:tid 956057] [client 127.0.0.1:14636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxWchFTPRVSLOsRVhoCXAAAAUA"]
[Thu Sep 17 15:06:58.922839 2026] [security2:error] [pid 955873:tid 956080] [client 74.7.241.141:49594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.owp.dxd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWchFTPRVSLOsRVhoCWgABV2k"]
[Thu Sep 17 15:06:59.092756 2026] [security2:error] [pid 955873:tid 956079] [client 20.244.34.24:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCZQAAAVY"], referer: binance.com
[Thu Sep 17 15:06:59.119648 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:58382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWcxFTPRVSLOsRVhoCZgAAATI"]
[Thu Sep 17 15:06:59.173203 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:38334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCZwAAAR8"]
[Thu Sep 17 15:06:59.173317 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:38334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCZwAAAR8"]
[Thu Sep 17 15:06:59.199740 2026] [security2:error] [pid 955873:tid 956006] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWQABDWY"]
[Thu Sep 17 15:06:59.259402 2026] [security2:error] [pid 955873:tid 956113] [client 45.156.129.164:59668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "aqxWcxFTPRVSLOsRVhoCagAAAXg"]
[Thu Sep 17 15:06:59.404920 2026] [security2:error] [pid 955873:tid 956007] [client 169.58.198.243:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCbgAAAQ4"], referer: www.google.com
[Thu Sep 17 15:06:59.432638 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:58390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWcxFTPRVSLOsRVhoCbwAAAYk"]
[Thu Sep 17 15:06:59.457188 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:38346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCcAAAARs"]
[Thu Sep 17 15:06:59.457283 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:38346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCcAAAARs"]
[Thu Sep 17 15:06:59.658884 2026] [security2:error] [pid 955873:tid 956058] [client 34.35.44.204:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCeAAAAUE"]
[Thu Sep 17 15:06:59.747709 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:38352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCeQAAAUw"]
[Thu Sep 17 15:06:59.747829 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:38352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCeQAAAUw"]
[Thu Sep 17 15:06:59.797797 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:58392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWcxFTPRVSLOsRVhoCfwAAAYA"]
[Thu Sep 17 15:06:59.828831 2026] [security2:error] [pid 955873:tid 956034] [client 4.240.114.86:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCggAAASk"], referer: binance.com
[Thu Sep 17 15:07:00.044366 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxWdBFTPRVSLOsRVhoChgAAATM"]
[Thu Sep 17 15:07:00.044517 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxWdBFTPRVSLOsRVhoChgAAATM"]
[Thu Sep 17 15:07:00.232063 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:58400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWdBFTPRVSLOsRVhoCiQAAASA"]
[Thu Sep 17 15:07:00.332470 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCjwAAAU4"]
[Thu Sep 17 15:07:00.332579 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCjwAAAU4"]
[Thu Sep 17 15:07:00.530282 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env"] [unique_id "aqxWdBFTPRVSLOsRVhoClQAAAU8"]
[Thu Sep 17 15:07:00.615677 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:40778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxWdBFTPRVSLOsRVhoClwAAATo"]
[Thu Sep 17 15:07:00.686808 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCmgAAAWs"]
[Thu Sep 17 15:07:00.722823 2026] [security2:error] [pid 955873:tid 956046] [client 34.166.221.252:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCmwAAATU"]
[Thu Sep 17 15:07:00.771408 2026] [authz_core:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Poly1305/error_log
[Thu Sep 17 15:07:00.773276 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxWdBFTPRVSLOsRVhoCnQAAARo"]
[Thu Sep 17 15:07:00.931711 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:40778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWdBFTPRVSLOsRVhoCowAAAQ8"]
[Thu Sep 17 15:07:01.083878 2026] [security2:error] [pid 955873:tid 956035] [client 88.136.135.42:58966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCpwABKnk"]
[Thu Sep 17 15:07:01.106267 2026] [security2:error] [pid 955873:tid 956101] [client 45.156.129.166:47290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxWdRFTPRVSLOsRVhoCrQAAAWw"]
[Thu Sep 17 15:07:01.218132 2026] [security2:error] [pid 955873:tid 956098] [client 45.66.42.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "compassalpha.com"] [uri "/index.php"] [unique_id "aqxWdBFTPRVSLOsRVhoClgAAAWk"], referer: https://compassalpha.com
[Thu Sep 17 15:07:01.324184 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCrAAAARU"]
[Thu Sep 17 15:07:01.324209 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCrAAAARU"]
[Thu Sep 17 15:07:01.333424 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.bak"] [unique_id "aqxWdRFTPRVSLOsRVhoCuAAAAVg"]
[Thu Sep 17 15:07:01.420823 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.221.252:49982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/info.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCuwAAAXA"]
[Thu Sep 17 15:07:01.447004 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.backup"] [unique_id "aqxWdRFTPRVSLOsRVhoCvAAAARs"]
[Thu Sep 17 15:07:01.461944 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCvgAAAVQ"]
[Thu Sep 17 15:07:01.462039 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCvgAAAVQ"]
[Thu Sep 17 15:07:01.505857 2026] [security2:error] [pid 955873:tid 956124] [client 34.35.44.204:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCwAAAAYM"]
[Thu Sep 17 15:07:01.626470 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.old"] [unique_id "aqxWdRFTPRVSLOsRVhoCxAAAAWA"]
[Thu Sep 17 15:07:01.790360 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCyQAAAS8"]
[Thu Sep 17 15:07:01.790479 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCyQAAAS8"]
[Thu Sep 17 15:07:01.819756 2026] [security2:error] [pid 955873:tid 956011] [client 57.141.14.101:27076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCxgABEm8"]
[Thu Sep 17 15:07:01.861956 2026] [security2:error] [pid 955873:tid 956110] [client 37.139.53.124:53034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCswAAAYQ"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:07:02.056704 2026] [security2:error] [pid 955873:tid 956049] [client 185.55.149.49:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0gAAATg"]
[Thu Sep 17 15:07:02.056832 2026] [security2:error] [pid 955873:tid 956049] [client 185.55.149.49:61947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0gAAATg"]
[Thu Sep 17 15:07:02.082242 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0wAAAS0"]
[Thu Sep 17 15:07:02.082355 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0wAAAS0"]
[Thu Sep 17 15:07:02.117127 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.221.252:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/php.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC1AAAATM"]
[Thu Sep 17 15:07:02.276459 2026] [security2:error] [pid 955873:tid 955998] [remote 216.73.217.142:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWdhFTPRVSLOsRVhoC2AABMHw"]
[Thu Sep 17 15:07:02.345799 2026] [security2:error] [pid 955873:tid 956015] [client 34.35.44.204:52600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC2gAAARY"]
[Thu Sep 17 15:07:02.380840 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC3QAAAVw"]
[Thu Sep 17 15:07:02.380968 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:40812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC3QAAAVw"]
[Thu Sep 17 15:07:02.672833 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC6QAAATs"]
[Thu Sep 17 15:07:02.672944 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC6QAAATs"]
[Thu Sep 17 15:07:02.820397 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.221.252:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/i.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC8AAAAXI"]
[Thu Sep 17 15:07:02.838083 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.swp"] [unique_id "aqxWdhFTPRVSLOsRVhoC8gAAAVA"]
[Thu Sep 17 15:07:02.938644 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env~"] [unique_id "aqxWdhFTPRVSLOsRVhoC9gAAAXA"]
[Thu Sep 17 15:07:02.966081 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC-wAAAWc"]
[Thu Sep 17 15:07:02.966220 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC-wAAAWc"]
[Thu Sep 17 15:07:03.194855 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDBwAAARU"]
[Thu Sep 17 15:07:03.228671 2026] [security2:error] [pid 955873:tid 956040] [client 4.240.114.86:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDCQAAAS8"], referer: binance.com
[Thu Sep 17 15:07:03.350613 2026] [security2:error] [pid 955873:tid 956059] [client 169.58.198.243:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/ph-file-manager/wp-file.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDAAAAUI"], referer: www.google.com
[Thu Sep 17 15:07:03.370686 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:40846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDQAAAXU"]
[Thu Sep 17 15:07:03.370833 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:40846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDQAAAXU"]
[Thu Sep 17 15:07:03.446699 2026] [autoindex:error] [pid 955873:tid 956011] [client 45.55.41.71:49602] AH01276: Cannot serve directory /home1/kgrvnlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:03.501299 2026] [security2:error] [pid 955873:tid 956065] [client 31.206.188.182:7878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDwABSF8"]
[Thu Sep 17 15:07:03.503711 2026] [security2:error] [pid 955873:tid 956067] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDBAABSm4"]
[Thu Sep 17 15:07:03.524132 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.221.252:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/pi.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDGAAAAQ4"]
[Thu Sep 17 15:07:03.668251 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDGwAAAXY"]
[Thu Sep 17 15:07:03.668362 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDGwAAAXY"]
[Thu Sep 17 15:07:03.844791 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/app/.env"] [unique_id "aqxWdxFTPRVSLOsRVhoDIAAAAYU"]
[Thu Sep 17 15:07:03.927283 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/apps/.env"] [unique_id "aqxWdxFTPRVSLOsRVhoDKAAAAVY"]
[Thu Sep 17 15:07:03.967036 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDKgAAATs"]
[Thu Sep 17 15:07:03.967152 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDKgAAATs"]
[Thu Sep 17 15:07:04.021670 2026] [security2:error] [pid 955873:tid 956080] [client 34.35.44.204:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDKwAAAVc"]
[Thu Sep 17 15:07:04.038706 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDLAAAAR8"]
[Thu Sep 17 15:07:04.135525 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/web/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDMQAAAVQ"]
[Thu Sep 17 15:07:04.204708 2026] [security2:error] [pid 955873:tid 956027] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/site/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDMwAAASI"]
[Thu Sep 17 15:07:04.210691 2026] [security2:error] [pid 955873:tid 956120] [client 34.166.221.252:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/pinfo.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDNAAAAX8"]
[Thu Sep 17 15:07:04.250956 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:40872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxWeBFTPRVSLOsRVhoDNQAAAUw"]
[Thu Sep 17 15:07:04.276230 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/public/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDOAAAAT4"]
[Thu Sep 17 15:07:04.389244 2026] [security2:error] [pid 955873:tid 956083] [client 4.240.114.86:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDPAAAAVo"], referer: binance.com
[Thu Sep 17 15:07:04.423306 2026] [authz_core:error] [pid 955873:tid 956102] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/error_log
[Thu Sep 17 15:07:04.430792 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxWeBFTPRVSLOsRVhoDPQAAAW0"]
[Thu Sep 17 15:07:04.453575 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/backend/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDQQAAATY"]
[Thu Sep 17 15:07:04.521345 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/server/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDSQAAAUQ"]
[Thu Sep 17 15:07:04.575517 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:40872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/wp-includes/sodium_compat/"] [unique_id "aqxWeBFTPRVSLOsRVhoDSgAAAWE"]
[Thu Sep 17 15:07:04.626945 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/frontend/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDSwAAAXU"]
[Thu Sep 17 15:07:04.715530 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/src/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDTQAAASY"]
[Thu Sep 17 15:07:04.809312 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/core/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDTwAAAYc"]
[Thu Sep 17 15:07:04.853524 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDUAAAAU4"]
[Thu Sep 17 15:07:04.902460 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/core/app/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDVAAAAQ4"]
[Thu Sep 17 15:07:04.937389 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.221.252:38282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/test.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDVQAAASQ"]
[Thu Sep 17 15:07:04.950514 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDTgAAATg"]
[Thu Sep 17 15:07:04.950548 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDTgAAATg"]
[Thu Sep 17 15:07:04.957338 2026] [security2:error] [pid 955873:tid 956009] [client 45.169.98.18:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDVwAAARA"]
[Thu Sep 17 15:07:04.957473 2026] [security2:error] [pid 955873:tid 956009] [client 45.169.98.18:57295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDVwAAARA"]
[Thu Sep 17 15:07:04.981785 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/config/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDWAAAATA"]
[Thu Sep 17 15:07:05.066110 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/private/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDWQAAARY"]
[Thu Sep 17 15:07:05.100180 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDWgAAAXY"]
[Thu Sep 17 15:07:05.100290 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDWgAAAXY"]
[Thu Sep 17 15:07:05.129106 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/application/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDXAAAAVw"]
[Thu Sep 17 15:07:05.259467 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/bootstrap/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDXgAAAYU"]
[Thu Sep 17 15:07:05.345365 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/database/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDYQAAAVY"]
[Thu Sep 17 15:07:05.402930 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWeRFTPRVSLOsRVhoDZwAAASo"]
[Thu Sep 17 15:07:05.439062 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/storage/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDaQAAAQ8"]
[Thu Sep 17 15:07:05.547432 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/var/www/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDagAAAXA"]
[Thu Sep 17 15:07:05.607015 2026] [authz_core:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/error_log
[Thu Sep 17 15:07:05.644516 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWeRFTPRVSLOsRVhoDawAAAWQ"]
[Thu Sep 17 15:07:05.666339 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/var/www/html/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDcQAAAW8"]
[Thu Sep 17 15:07:05.680203 2026] [security2:error] [pid 955873:tid 956006] [client 34.35.44.204:52644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDcwAAAQ0"]
[Thu Sep 17 15:07:05.740774 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/current/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDdgAAARk"]
[Thu Sep 17 15:07:05.785746 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/wp-includes/sodium_compat/src/"] [unique_id "aqxWeRFTPRVSLOsRVhoDdwAAAYQ"]
[Thu Sep 17 15:07:05.834030 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/release/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDeAAAAVg"]
[Thu Sep 17 15:07:05.865764 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.221.252:38296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/p.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDegAAAYg"]
[Thu Sep 17 15:07:05.930031 2026] [security2:error] [pid 955873:tid 956087] [client 45.156.128.66:12428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travisklassen.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDbgABXhE"]
[Thu Sep 17 15:07:05.935994 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/releases/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDfwAAAS8"]
[Thu Sep 17 15:07:06.014251 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/shared/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDgQAAATE"]
[Thu Sep 17 15:07:06.041060 2026] [security2:error] [pid 955873:tid 956120] [client 57.141.14.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reddomconstruction.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDdQAAAX8"]
[Thu Sep 17 15:07:06.149330 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/deploy/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDigAAAUs"]
[Thu Sep 17 15:07:06.159573 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDfAAAATY"]
[Thu Sep 17 15:07:06.159597 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDfAAAATY"]
[Thu Sep 17 15:07:06.209747 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/build/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDjAAAAU0"]
[Thu Sep 17 15:07:06.293155 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/dist/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDjwAAAUk"]
[Thu Sep 17 15:07:06.300610 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxWehFTPRVSLOsRVhoDkAAAASc"]
[Thu Sep 17 15:07:06.405588 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/public_html/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDkgAAAU4"]
[Thu Sep 17 15:07:06.410913 2026] [security2:error] [pid 955873:tid 956028] [client 115.244.164.14:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDkwAAASM"]
[Thu Sep 17 15:07:06.411014 2026] [security2:error] [pid 955873:tid 956028] [client 115.244.164.14:51076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDkwAAASM"]
[Thu Sep 17 15:07:06.456799 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxWehFTPRVSLOsRVhoDlAAAAUo"]
[Thu Sep 17 15:07:06.480736 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/htdocs/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDlwAAAQ4"]
[Thu Sep 17 15:07:06.498335 2026] [security2:error] [pid 955873:tid 956056] [client 45.156.128.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travisklassen.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDjQAAAT8"]
[Thu Sep 17 15:07:06.518506 2026] [security2:error] [pid 955873:tid 956128] [client 34.35.44.204:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWehFTPRVSLOsRVhoDmAAAAYc"]
[Thu Sep 17 15:07:06.561246 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.221.252:38298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/debug.php"] [unique_id "aqxWehFTPRVSLOsRVhoDmgAAAUc"]
[Thu Sep 17 15:07:06.567063 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/www/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDmwAAATA"]
[Thu Sep 17 15:07:06.604105 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWehFTPRVSLOsRVhoDnwAAAVk"]
[Thu Sep 17 15:07:06.649393 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/html/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDoQAAAT0"]
[Thu Sep 17 15:07:06.688983 2026] [security2:error] [pid 955873:tid 956055] [client 194.163.128.162:60391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wildamerika.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDogAAAT4"], referer: binance.com
[Thu Sep 17 15:07:06.724799 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/live/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDowAAAQw"]
[Thu Sep 17 15:07:06.811876 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/prod/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDpwAAAYU"]
[Thu Sep 17 15:07:06.847436 2026] [security2:error] [pid 955873:tid 956118] [client 154.190.208.131:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDqgAAAX0"]
[Thu Sep 17 15:07:06.847566 2026] [security2:error] [pid 955873:tid 956118] [client 154.190.208.131:41658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDqgAAAX0"]
[Thu Sep 17 15:07:06.860192 2026] [security2:error] [pid 955873:tid 956111] [client 104.207.47.59:13715] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWehFTPRVSLOsRVhoDqwAAAXY"]
[Thu Sep 17 15:07:06.875373 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/dev/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDrQAAAWU"]
[Thu Sep 17 15:07:06.955196 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/staging/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDsQAAAWI"]
[Thu Sep 17 15:07:06.988526 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDpAAAAUg"]
[Thu Sep 17 15:07:06.988559 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDpAAAAUg"]
[Thu Sep 17 15:07:07.015186 2026] [autoindex:error] [pid 955873:tid 955902] [remote 93.152.209.11:46060] AH01276: Cannot serve directory /home1/ymjxogmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:07.074917 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/opt/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDuwAAAWQ"]
[Thu Sep 17 15:07:07.134611 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:40888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoDvwAAARQ"]
[Thu Sep 17 15:07:07.134744 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoDvwAAARQ"]
[Thu Sep 17 15:07:07.137876 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/laravel/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDwAAAAXo"]
[Thu Sep 17 15:07:07.251008 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/symfony/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDwgAAATI"]
[Thu Sep 17 15:07:07.267401 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.221.252:38306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWexFTPRVSLOsRVhoDwwAAAXA"]
[Thu Sep 17 15:07:07.345180 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/wordpress/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDyAAAAV4"]
[Thu Sep 17 15:07:07.413281 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxWexFTPRVSLOsRVhoDyQAAAS8"]
[Thu Sep 17 15:07:07.413426 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxWexFTPRVSLOsRVhoDyQAAAS8"]
[Thu Sep 17 15:07:07.458007 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/wp/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDzQAAAXU"]
[Thu Sep 17 15:07:07.497880 2026] [security2:error] [pid 955873:tid 956120] [client 20.244.34.24:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxWexFTPRVSLOsRVhoDzwAAAX8"], referer: binance.com
[Thu Sep 17 15:07:07.572259 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cms/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD1QAAARM"]
[Thu Sep 17 15:07:07.590524 2026] [security2:error] [pid 955873:tid 956039] [client 77.232.40.141:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.40.232.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxWexFTPRVSLOsRVhoD0wAAAS4"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:07:07.590628 2026] [security2:error] [pid 955873:tid 956039] [client 77.232.40.141:59898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxWexFTPRVSLOsRVhoD0wAAAS4"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:07:07.644599 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/drupal/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD2gAAAWE"]
[Thu Sep 17 15:07:07.689357 2026] [security2:error] [pid 955873:tid 956121] [client 45.156.128.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "travisklassen.com"] [uri "/index.php"] [unique_id "aqxWexFTPRVSLOsRVhoD1AAAAYA"], referer: http://travisklassen.com/favicon.ico
[Thu Sep 17 15:07:07.716641 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/joomla/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD3AAAAUk"]
[Thu Sep 17 15:07:07.817938 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/magento/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD3gAAASs"]
[Thu Sep 17 15:07:07.893747 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoD4QAAATg"]
[Thu Sep 17 15:07:07.893843 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:40910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoD4QAAATg"]
[Thu Sep 17 15:07:07.953065 2026] [security2:error] [pid 955873:tid 956032] [client 34.166.221.252:38312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWexFTPRVSLOsRVhoD4gAAASc"]
[Thu Sep 17 15:07:08.134483 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/shopify/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD6gAAAXc"]
[Thu Sep 17 15:07:08.178155 2026] [security2:error] [pid 955873:tid 956033] [client 4.240.114.86:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD7AAAASg"], referer: binance.com
[Thu Sep 17 15:07:08.228832 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/prestashop/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD7QAAATc"]
[Thu Sep 17 15:07:08.252700 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD7gAAAYU"]
[Thu Sep 17 15:07:08.252799 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD7gAAAYU"]
[Thu Sep 17 15:07:08.304254 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/codeigniter/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD8QAAATs"]
[Thu Sep 17 15:07:08.378988 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cakephp/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD8wAAAXY"]
[Thu Sep 17 15:07:08.487286 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/zend/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD-wAAAV8"]
[Thu Sep 17 15:07:08.559030 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:40918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD_QAAAUE"]
[Thu Sep 17 15:07:08.559125 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:40918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD_QAAAUE"]
[Thu Sep 17 15:07:08.561842 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/yii/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD_gAAAVQ"]
[Thu Sep 17 15:07:08.643008 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/laravel5/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoEAAAAAR8"]
[Thu Sep 17 15:07:08.649879 2026] [security2:error] [pid 955873:tid 956123] [client 34.166.221.252:38324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWfBFTPRVSLOsRVhoEAQAAAYI"]
[Thu Sep 17 15:07:08.752241 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/v1/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoEBAAAAYY"]
[Thu Sep 17 15:07:08.871589 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/v2/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoEBgAAARk"]
[Thu Sep 17 15:07:08.875077 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:40924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxWfBFTPRVSLOsRVhoEBwAAAXk"]
[Thu Sep 17 15:07:08.962877 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/v3/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoECwAAAWk"]
[Thu Sep 17 15:07:09.038250 2026] [authz_core:error] [pid 955873:tid 956026] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/AES/error_log
[Thu Sep 17 15:07:09.040944 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxWfRFTPRVSLOsRVhoEDgAAASE"]
[Thu Sep 17 15:07:09.185344 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWfRFTPRVSLOsRVhoEDwAAAS8"]
[Thu Sep 17 15:07:09.331765 2026] [security2:error] [pid 955873:tid 956081] [client 186.105.232.15:53335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFQAAAVg"]
[Thu Sep 17 15:07:09.331874 2026] [security2:error] [pid 955873:tid 956081] [client 186.105.232.15:53335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFQAAAVg"]
[Thu Sep 17 15:07:09.335948 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.221.252:38332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFgAAARU"]
[Thu Sep 17 15:07:09.389137 2026] [security2:error] [pid 955873:tid 956008] [client 4.240.114.86:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFwAAAQ8"], referer: binance.com
[Thu Sep 17 15:07:09.433201 2026] [fcgid:warn] [pid 955873:tid 956047] (70014)End of file found: [client 66.132.172.223:28590] mod_fcgid: can't get data from http client
[Thu Sep 17 15:07:09.578462 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFAAAARM"]
[Thu Sep 17 15:07:09.578492 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFAAAARM"]
[Thu Sep 17 15:07:09.719179 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEIwAAASk"]
[Thu Sep 17 15:07:09.719324 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:40924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEIwAAASk"]
[Thu Sep 17 15:07:09.902943 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/v1/.env"] [unique_id "aqxWfRFTPRVSLOsRVhoEKgAAAYc"]
[Thu Sep 17 15:07:09.999653 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/v2/.env"] [unique_id "aqxWfRFTPRVSLOsRVhoELAAAAUQ"]
[Thu Sep 17 15:07:10.007279 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxWfhFTPRVSLOsRVhoELgAAARY"]
[Thu Sep 17 15:07:10.007385 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxWfhFTPRVSLOsRVhoELgAAARY"]
[Thu Sep 17 15:07:10.023726 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.221.252:38346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWfhFTPRVSLOsRVhoELwAAAQs"]
[Thu Sep 17 15:07:10.088540 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/rest/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEMwAAAUU"]
[Thu Sep 17 15:07:10.159056 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/graphql/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoENQAAAYg"]
[Thu Sep 17 15:07:10.272439 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/gateway/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoENwAAAXc"]
[Thu Sep 17 15:07:10.291849 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEOQAAAT4"]
[Thu Sep 17 15:07:10.291978 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:35192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEOQAAAT4"]
[Thu Sep 17 15:07:10.328947 2026] [security2:error] [pid 955873:tid 956104] [client 104.207.47.59:44283] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWfhFTPRVSLOsRVhoEOwAAAW8"]
[Thu Sep 17 15:07:10.422934 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/microservice/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEPwAAAYU"]
[Thu Sep 17 15:07:10.559523 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/service/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEQgAAAX0"]
[Thu Sep 17 15:07:10.578302 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:35208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEQwAAAWc"]
[Thu Sep 17 15:07:10.578406 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:35208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEQwAAAWc"]
[Thu Sep 17 15:07:10.678737 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/v3/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoERQAAAXY"]
[Thu Sep 17 15:07:10.709043 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.221.252:38360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWfhFTPRVSLOsRVhoERgAAARA"]
[Thu Sep 17 15:07:10.744420 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/dev/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoESQAAAV8"]
[Thu Sep 17 15:07:10.841191 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/staging/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoETQAAAR8"]
[Thu Sep 17 15:07:10.870402 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:35212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxWfhFTPRVSLOsRVhoETgAAAYI"]
[Thu Sep 17 15:07:10.922719 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/vendor/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEUQAAARQ"]
[Thu Sep 17 15:07:10.993487 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/lib/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEVQAAAXI"]
[Thu Sep 17 15:07:11.031326 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxWfxFTPRVSLOsRVhoEVgAAAXg"]
[Thu Sep 17 15:07:11.102339 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/resources/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEWwAAASE"]
[Thu Sep 17 15:07:11.102740 2026] [core:error] [pid 955873:tid 956043] [client 69.171.231.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:11.102754 2026] [core:error] [pid 955873:tid 956043] [client 69.171.231.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:11.181117 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:35212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWfxFTPRVSLOsRVhoEXAAAARc"]
[Thu Sep 17 15:07:11.229234 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/assets/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEXwAAATw"]
[Thu Sep 17 15:07:11.338014 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/uploads/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEYgAAAQ8"]
[Thu Sep 17 15:07:11.414893 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/internal/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEZQAAAYQ"]
[Thu Sep 17 15:07:11.514968 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/tools/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEZgAAAYA"]
[Thu Sep 17 15:07:11.547633 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEYQAAASY"]
[Thu Sep 17 15:07:11.547655 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEYQAAASY"]
[Thu Sep 17 15:07:11.575449 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/scripts/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEaAAAARM"]
[Thu Sep 17 15:07:11.644011 2026] [security2:error] [pid 955873:tid 956028] [client 34.166.221.252:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/php-info.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbAAAASM"]
[Thu Sep 17 15:07:11.657670 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/bin/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEbQAAARs"]
[Thu Sep 17 15:07:11.695085 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:35212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbgAAAQ4"]
[Thu Sep 17 15:07:11.695221 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:35212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbgAAAQ4"]
[Thu Sep 17 15:07:11.727555 2026] [security2:error] [pid 955873:tid 956101] [client 20.255.75.24:1028] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hopmanchaissconsulting.com"] [uri "/1.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbwAAAWw"]
[Thu Sep 17 15:07:11.727699 2026] [security2:error] [pid 955873:tid 956101] [client 20.255.75.24:1028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/1.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbwAAAWw"]
[Thu Sep 17 15:07:11.737495 2026] [security2:error] [pid 955873:tid 956124] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sbin/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEcQAAAYM"]
[Thu Sep 17 15:07:11.740820 2026] [autoindex:error] [pid 955873:tid 956117] [client 34.35.44.204:43892] AH01276: Cannot serve directory /home1/omqzshmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:11.788584 2026] [security2:error] [pid 955873:tid 956010] [client 169.58.198.243:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/root-file-manager/wp-file.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEcwAAARE"], referer: www.google.com
[Thu Sep 17 15:07:11.843568 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/local/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEdAAAARY"]
[Thu Sep 17 15:07:11.939536 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/portal/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEdQAAAUU"]
[Thu Sep 17 15:07:11.985614 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEdgAAAVo"]
[Thu Sep 17 15:07:11.985786 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEdgAAAVo"]
[Thu Sep 17 15:07:12.040633 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/dashboard/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEegAAAT8"]
[Thu Sep 17 15:07:12.113583 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEfgAAAW4"]
[Thu Sep 17 15:07:12.147751 2026] [security2:error] [pid 955873:tid 956050] [client 20.255.75.24:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/new.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEgAAAATk"]
[Thu Sep 17 15:07:12.233796 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/crm/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEgwAAATc"]
[Thu Sep 17 15:07:12.272490 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEiAAAAYU"]
[Thu Sep 17 15:07:12.272586 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:35234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEiAAAAYU"]
[Thu Sep 17 15:07:12.298392 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/erp/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEiwAAAVY"]
[Thu Sep 17 15:07:12.324642 2026] [security2:error] [pid 955873:tid 956033] [client 34.166.221.252:38382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpversion.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEjgAAASg"]
[Thu Sep 17 15:07:12.349950 2026] [security2:error] [pid 955873:tid 956089] [client 84.33.131.77:54890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEhgABYCM"]
[Thu Sep 17 15:07:12.409094 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/shop/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEkAAAAXY"]
[Thu Sep 17 15:07:12.488021 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/store/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEkQAAARg"]
[Thu Sep 17 15:07:12.558128 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/saas/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoElgAAAVI"]
[Thu Sep 17 15:07:12.561392 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:35236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxWgBFTPRVSLOsRVhoElwAAARQ"]
[Thu Sep 17 15:07:12.631579 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/client/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEmgAAARk"]
[Thu Sep 17 15:07:12.637681 2026] [security2:error] [pid 955873:tid 956009] [client 20.255.75.24:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/num.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEmwAAARA"]
[Thu Sep 17 15:07:12.729319 2026] [security2:error] [pid 955873:tid 956088] [client 185.55.149.49:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEngAAAV8"]
[Thu Sep 17 15:07:12.729338 2026] [authz_core:error] [pid 955873:tid 956094] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/ChaCha20/error_log
[Thu Sep 17 15:07:12.729410 2026] [security2:error] [pid 955873:tid 956088] [client 185.55.149.49:62643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEngAAAV8"]
[Thu Sep 17 15:07:12.731115 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxWgBFTPRVSLOsRVhoEnQAAAWU"]
[Thu Sep 17 15:07:12.732985 2026] [security2:error] [pid 955873:tid 956086] [client 134.185.85.61:55592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thehivetribe.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxWgBFTPRVSLOsRVhoEnwAAAV0"]
[Thu Sep 17 15:07:12.733611 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/project/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEoAAAASE"]
[Thu Sep 17 15:07:12.757486 2026] [security2:error] [pid 955873:tid 956115] [client 4.240.114.86:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEogAAAXo"], referer: binance.com
[Thu Sep 17 15:07:12.803744 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/admin-panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEpQAAAVc"]
[Thu Sep 17 15:07:12.878584 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:35236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWgBFTPRVSLOsRVhoEpwAAAWM"]
[Thu Sep 17 15:07:12.900034 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/control-panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEqAAAAWE"]
[Thu Sep 17 15:07:12.986783 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/user-panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEqgAAAS0"]
[Thu Sep 17 15:07:13.018141 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.221.252:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/_phpinfo.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEqwAAAS8"]
[Thu Sep 17 15:07:13.115165 2026] [security2:error] [pid 955873:tid 956007] [client 134.185.85.61:58408] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thehivetribe.com"] [uri "/media/system/js/core.js"] [unique_id "aqxWgRFTPRVSLOsRVhoEsQAAAQ4"]
[Thu Sep 17 15:07:13.141896 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/node/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEtgAAAXw"]
[Thu Sep 17 15:07:13.233135 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/express/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEuQAAAYc"]
[Thu Sep 17 15:07:13.236405 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgRFTPRVSLOsRVhoErAAAARI"]
[Thu Sep 17 15:07:13.236421 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgRFTPRVSLOsRVhoErAAAARI"]
[Thu Sep 17 15:07:13.250528 2026] [autoindex:error] [pid 955873:tid 956049] [client 20.255.75.24:0] AH01276: Cannot serve directory /home2/hopmanch/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:13.301148 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/next/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEuwAAAVk"]
[Thu Sep 17 15:07:13.374729 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/nuxt/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEvAAAAUY"]
[Thu Sep 17 15:07:13.378600 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEvQAAAVo"]
[Thu Sep 17 15:07:13.378702 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEvQAAAVo"]
[Thu Sep 17 15:07:13.430084 2026] [security2:error] [pid 955873:tid 956112] [client 20.255.75.24:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/admin.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEvgAAAXc"]
[Thu Sep 17 15:07:13.444609 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/nest/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEvwAAAT4"]
[Thu Sep 17 15:07:13.569226 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/react/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEwgAAAU0"]
[Thu Sep 17 15:07:13.666939 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/vue/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoExwAAAXE"]
[Thu Sep 17 15:07:13.667243 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEyAAAAXY"]
[Thu Sep 17 15:07:13.667317 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEyAAAAXY"]
[Thu Sep 17 15:07:13.713516 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.221.252:38398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEzQAAAW4"]
[Thu Sep 17 15:07:13.772275 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/angular/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoE0AAAARQ"]
[Thu Sep 17 15:07:13.853623 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/svelte/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoE0gAAAVM"]
[Thu Sep 17 15:07:13.860878 2026] [security2:error] [pid 955873:tid 956079] [client 104.207.47.59:41923] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWgRFTPRVSLOsRVhoE0wAAAVY"]
[Thu Sep 17 15:07:13.933871 2026] [security2:error] [pid 955873:tid 956075] [client 20.255.75.24:1047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/13.php"] [unique_id "aqxWgRFTPRVSLOsRVhoE1QAAAVI"]
[Thu Sep 17 15:07:13.946895 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxWgRFTPRVSLOsRVhoE1wAAARo"]
[Thu Sep 17 15:07:13.947046 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:35260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxWgRFTPRVSLOsRVhoE1wAAARo"]
[Thu Sep 17 15:07:13.998523 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/vite/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoE2AAAAXI"]
[Thu Sep 17 15:07:14.053194 2026] [security2:error] [pid 955873:tid 956093] [client 20.244.34.24:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxWghFTPRVSLOsRVhoE2QAAAWQ"], referer: binance.com
[Thu Sep 17 15:07:14.117907 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/backup/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE3QAAATI"]
[Thu Sep 17 15:07:14.193108 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/backups/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE5AAAAVg"]
[Thu Sep 17 15:07:14.225069 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:35268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxWghFTPRVSLOsRVhoE5wAAAYY"]
[Thu Sep 17 15:07:14.261374 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/old/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE6QAAAWE"]
[Thu Sep 17 15:07:14.315849 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoE6AAAAXU"]
[Thu Sep 17 15:07:14.338060 2026] [security2:error] [pid 955873:tid 956032] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEjwABJwM"], referer: http://cfbpp.org/wordpress/
[Thu Sep 17 15:07:14.352746 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/tmp/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE6wAAASY"]
[Thu Sep 17 15:07:14.391898 2026] [authz_core:error] [pid 955873:tid 956098] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Curve25519/error_log
[Thu Sep 17 15:07:14.397922 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.221.252:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/server-info.php"] [unique_id "aqxWghFTPRVSLOsRVhoE7QAAAXo"]
[Thu Sep 17 15:07:14.403092 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxWghFTPRVSLOsRVhoE7AAAAWk"]
[Thu Sep 17 15:07:14.417553 2026] [security2:error] [pid 955873:tid 956092] [client 20.255.75.24:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/222.php"] [unique_id "aqxWghFTPRVSLOsRVhoE8AAAAWM"]
[Thu Sep 17 15:07:14.434492 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/temp/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE8wAAARM"]
[Thu Sep 17 15:07:14.527250 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/lab/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE9QAAAQ4"]
[Thu Sep 17 15:07:14.542442 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:35268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWghFTPRVSLOsRVhoE9gAAAXw"]
[Thu Sep 17 15:07:14.602610 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE9wAAARE"]
[Thu Sep 17 15:07:14.618561 2026] [security2:error] [pid 955873:tid 956034] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoE9AABKSg"], referer: http://cfbpp.org/wp/
[Thu Sep 17 15:07:14.621808 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cronlab/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE-gAAATg"]
[Thu Sep 17 15:07:14.718781 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cron/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFBAAAAUU"]
[Thu Sep 17 15:07:14.796701 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/en/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFCQAAAT4"]
[Thu Sep 17 15:07:14.858647 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFBwAAAUY"]
[Thu Sep 17 15:07:14.898422 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/administrator/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFCgAAAYE"]
[Thu Sep 17 15:07:14.933124 2026] [security2:error] [pid 955873:tid 956022] [client 20.255.75.24:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/aa.php"] [unique_id "aqxWghFTPRVSLOsRVhoFDAAAAR0"]
[Thu Sep 17 15:07:14.950645 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFAwAAAUo"]
[Thu Sep 17 15:07:14.950685 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFAwAAAUo"]
[Thu Sep 17 15:07:14.968701 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/psnlink/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFDwAAATQ"]
[Thu Sep 17 15:07:15.082500 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.221.252:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/server-status.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFFAAAAYg"]
[Thu Sep 17 15:07:15.085479 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFEQAAAUI"]
[Thu Sep 17 15:07:15.089406 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFFgAAAVs"]
[Thu Sep 17 15:07:15.089503 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:35268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFFgAAAVs"]
[Thu Sep 17 15:07:15.111594 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/exapi/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFFwAAAYU"]
[Thu Sep 17 15:07:15.177283 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sitemaps/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFGgAAAUc"]
[Thu Sep 17 15:07:15.182557 2026] [security2:error] [pid 955873:tid 956106] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFEgABcSQ"], referer: http://cfbpp.org/new/
[Thu Sep 17 15:07:15.337857 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFIQAAARk"]
[Thu Sep 17 15:07:15.370594 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:35276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxWgxFTPRVSLOsRVhoFJQAAAXA"]
[Thu Sep 17 15:07:15.435700 2026] [security2:error] [pid 955873:tid 956019] [client 20.255.75.24:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/abcd.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFKwAAARo"]
[Thu Sep 17 15:07:15.435939 2026] [security2:error] [pid 955873:tid 956060] [client 45.169.98.18:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFLAAAAUM"]
[Thu Sep 17 15:07:15.436040 2026] [security2:error] [pid 955873:tid 956060] [client 45.169.98.18:57850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFLAAAAUM"]
[Thu Sep 17 15:07:15.456499 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/logs/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFLQAAAYQ"]
[Thu Sep 17 15:07:15.462543 2026] [security2:error] [pid 955873:tid 956086] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFIwABXS4"], referer: http://cfbpp.org/old/
[Thu Sep 17 15:07:15.541274 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxWgxFTPRVSLOsRVhoFLwAAAS0"]
[Thu Sep 17 15:07:15.549195 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFLgAAASE"]
[Thu Sep 17 15:07:15.568963 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cache/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFMQAAAXU"]
[Thu Sep 17 15:07:15.608116 2026] [security2:error] [pid 955873:tid 956025] [client 47.79.201.238:51880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFJgAAASA"], referer: https://www.google.com/
[Thu Sep 17 15:07:15.668399 2026] [security2:error] [pid 955873:tid 956039] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailer/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFOAAAAS4"]
[Thu Sep 17 15:07:15.686652 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:35276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxWgxFTPRVSLOsRVhoFOQAAAQ4"]
[Thu Sep 17 15:07:15.755509 2026] [security2:error] [pid 955873:tid 956115] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFNQABejI"], referer: http://cfbpp.org/blog/
[Thu Sep 17 15:07:15.759680 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mail/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFPAAAARE"]
[Thu Sep 17 15:07:15.820444 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/email/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFPwAAAUQ"]
[Thu Sep 17 15:07:15.848645 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFPQAAASs"]
[Thu Sep 17 15:07:15.925845 2026] [security2:error] [pid 955873:tid 956030] [client 20.255.75.24:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/about.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFRAAAASU"]
[Thu Sep 17 15:07:16.029699 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/smtp/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFSAAAAT0"]
[Thu Sep 17 15:07:16.031593 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFQQAAAQs"]
[Thu Sep 17 15:07:16.031610 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFQQAAAQs"]
[Thu Sep 17 15:07:16.045035 2026] [security2:error] [pid 955873:tid 956101] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFQwABbC8"], referer: http://cfbpp.org/backup/
[Thu Sep 17 15:07:16.145603 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFSgAAATk"]
[Thu Sep 17 15:07:16.164087 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailing/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFTwAAATQ"]
[Thu Sep 17 15:07:16.176223 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFUQAAAYg"]
[Thu Sep 17 15:07:16.176346 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFUQAAAYg"]
[Thu Sep 17 15:07:16.274785 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.221.252:56670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWhBFTPRVSLOsRVhoFVQAAATo"]
[Thu Sep 17 15:07:16.349136 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWhBFTPRVSLOsRVhoFVgAAATU"]
[Thu Sep 17 15:07:16.363699 2026] [security2:error] [pid 955873:tid 956126] [client 169.58.198.243:55107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/wp-help/mini.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFVwAAAYU"], referer: www.google.com
[Thu Sep 17 15:07:16.425556 2026] [security2:error] [pid 955873:tid 956109] [client 20.255.75.24:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/admin.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFWQAAAXQ"]
[Thu Sep 17 15:07:16.452442 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWhBFTPRVSLOsRVhoFWwAAARQ"]
[Thu Sep 17 15:07:16.459192 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFXAAAAQ0"]
[Thu Sep 17 15:07:16.459282 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:35292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFXAAAAQ0"]
[Thu Sep 17 15:07:16.472388 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/notifications/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFXQAAATA"]
[Thu Sep 17 15:07:16.554051 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/notify/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFYAAAASg"]
[Thu Sep 17 15:07:16.630681 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sender/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFZgAAAWA"]
[Thu Sep 17 15:07:16.661653 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFYQAAAVY"]
[Thu Sep 17 15:07:16.718683 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/campaign/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFZwAAAWQ"]
[Thu Sep 17 15:07:16.740613 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWhBFTPRVSLOsRVhoFaAAAATI"]
[Thu Sep 17 15:07:16.746376 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFaQAAARk"]
[Thu Sep 17 15:07:16.746461 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFaQAAARk"]
[Thu Sep 17 15:07:16.789384 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/newsletter/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFagAAAW8"]
[Thu Sep 17 15:07:16.852123 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/ses/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFbgAAAVg"]
[Thu Sep 17 15:07:16.907902 2026] [security2:error] [pid 955873:tid 956058] [client 20.255.75.24:1040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/adminfuns.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFcgAAAUE"]
[Thu Sep 17 15:07:16.923730 2026] [core:error] [pid 955873:tid 956019] [client 74.7.175.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:16.923745 2026] [core:error] [pid 955873:tid 956019] [client 74.7.175.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:16.923871 2026] [security2:error] [pid 955873:tid 956019] [client 74.7.175.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.grieveonpurpose.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFcwAAARo"]
[Thu Sep 17 15:07:16.930872 2026] [security2:error] [pid 955873:tid 956105] [client 74.7.175.153:37866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.grieveonpurpose.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxWhBFTPRVSLOsRVhoFcAABcCw"]
[Thu Sep 17 15:07:16.935643 2026] [security2:error] [pid 955873:tid 956107] [client 115.244.164.14:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFdAAAAXI"]
[Thu Sep 17 15:07:16.935772 2026] [security2:error] [pid 955873:tid 956107] [client 115.244.164.14:51730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFdAAAAXI"]
[Thu Sep 17 15:07:16.938447 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFbwAAAWI"]
[Thu Sep 17 15:07:16.952145 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sendgrid/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFdQAAAW0"]
[Thu Sep 17 15:07:16.958210 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.221.252:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFdgAAAWU"]
[Thu Sep 17 15:07:17.037729 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:35322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFdwAAASE"]
[Thu Sep 17 15:07:17.037883 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:35322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFdwAAASE"]
[Thu Sep 17 15:07:17.057607 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sparkpost/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFeQAAAYk"]
[Thu Sep 17 15:07:17.174413 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/postmark/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFgwAAAWM"]
[Thu Sep 17 15:07:17.200939 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFfwAAAWk"]
[Thu Sep 17 15:07:17.274134 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailgun/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFhQAAARE"]
[Thu Sep 17 15:07:17.274343 2026] [security2:error] [pid 955873:tid 956121] [client 187.20.37.14:57938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFgQABgDw"]
[Thu Sep 17 15:07:17.281710 2026] [security2:error] [pid 955873:tid 956110] [client 104.207.47.59:60361] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWhRFTPRVSLOsRVhoFhgAAAXU"]
[Thu Sep 17 15:07:17.298172 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.190.5:40924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhRFTPRVSLOsRVhoFiQAAAQo"]
[Thu Sep 17 15:07:17.314367 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFigAAATg"]
[Thu Sep 17 15:07:17.314432 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:35324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFigAAATg"]
[Thu Sep 17 15:07:17.349696 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mandrill/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFjQAAASs"]
[Thu Sep 17 15:07:17.368127 2026] [security2:error] [pid 955873:tid 956060] [client 154.190.208.131:42245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFjwAAAUM"]
[Thu Sep 17 15:07:17.368232 2026] [security2:error] [pid 955873:tid 956060] [client 154.190.208.131:42245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFjwAAAUM"]
[Thu Sep 17 15:07:17.395010 2026] [security2:error] [pid 955873:tid 956039] [client 20.255.75.24:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFkAAAAS4"]
[Thu Sep 17 15:07:17.468447 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailjet/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFkwAAASU"]
[Thu Sep 17 15:07:17.547589 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFlAAAAT8"]
[Thu Sep 17 15:07:17.560244 2026] [security2:error] [pid 955873:tid 956048] [client 4.240.114.86:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFmAAAATc"], referer: binance.com
[Thu Sep 17 15:07:17.589500 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFmQAAAYc"]
[Thu Sep 17 15:07:17.589614 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:35334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFmQAAAYc"]
[Thu Sep 17 15:07:17.604624 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/brevo/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFmgAAATM"]
[Thu Sep 17 15:07:17.652419 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.221.252:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFngAAASI"]
[Thu Sep 17 15:07:17.676128 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/transactional/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFoQAAAUk"]
[Thu Sep 17 15:07:17.764265 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/bulk/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFowAAAVo"]
[Thu Sep 17 15:07:17.792305 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFogAAATo"]
[Thu Sep 17 15:07:17.833588 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/aws/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFpQAAAXQ"]
[Thu Sep 17 15:07:17.889327 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqAAAAUc"]
[Thu Sep 17 15:07:17.889436 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:35340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqAAAAUc"]
[Thu Sep 17 15:07:17.899523 2026] [security2:error] [pid 955873:tid 956057] [client 20.255.75.24:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/ae.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqQAAAUA"]
[Thu Sep 17 15:07:17.946046 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/azure/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFqwAAAXE"]
[Thu Sep 17 15:07:18.008826 2026] [security2:error] [pid 955873:tid 956020] [client 34.166.190.5:40930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhhFTPRVSLOsRVhoFrAAAARs"]
[Thu Sep 17 15:07:18.014982 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqgAAATA"]
[Thu Sep 17 15:07:18.079197 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/gcp/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFrgAAAXg"]
[Thu Sep 17 15:07:18.152031 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cloud/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFsQAAAVw"]
[Thu Sep 17 15:07:18.176130 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFuAAAAR0"]
[Thu Sep 17 15:07:18.176225 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:35350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFuAAAAR0"]
[Thu Sep 17 15:07:18.247567 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/infrastructure/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFuwAAAUE"]
[Thu Sep 17 15:07:18.272590 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFuQAAAVg"]
[Thu Sep 17 15:07:18.338260 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.221.252:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFvgAAATI"]
[Thu Sep 17 15:07:18.344378 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/docker/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFvwAAAV0"]
[Thu Sep 17 15:07:18.411059 2026] [security2:error] [pid 955873:tid 956080] [client 20.255.75.24:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/akcc.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFwAAAAVc"]
[Thu Sep 17 15:07:18.416916 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/k8s/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFwQAAAW0"]
[Thu Sep 17 15:07:18.454061 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFxAAAAYk"]
[Thu Sep 17 15:07:18.454205 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFxAAAAYk"]
[Thu Sep 17 15:07:18.512629 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/kubernetes/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFxgAAAVQ"]
[Thu Sep 17 15:07:18.577564 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFxQAAASA"]
[Thu Sep 17 15:07:18.581313 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/terraform/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFyAAAAWg"]
[Thu Sep 17 15:07:18.713774 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/ansible/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFzgAAAYY"]
[Thu Sep 17 15:07:18.724990 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.190.5:40938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhhFTPRVSLOsRVhoFzwAAAWM"]
[Thu Sep 17 15:07:18.742796 2026] [security2:error] [pid 955873:tid 956116] [client 51.161.128.55:34020] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ritamayblog.com"] [uri "/mail"] [unique_id "aqxWhhFTPRVSLOsRVhoF0QAAAXs"]
[Thu Sep 17 15:07:18.749077 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:35372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF0gAAASs"]
[Thu Sep 17 15:07:18.749162 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:35372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF0gAAASs"]
[Thu Sep 17 15:07:18.760265 2026] [security2:error] [pid 955873:tid 956099] [client 51.161.128.55:34026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ritamayblog.com"] [uri "/webmail"] [unique_id "aqxWhhFTPRVSLOsRVhoF1AAAAWo"]
[Thu Sep 17 15:07:18.760265 2026] [security2:error] [pid 955873:tid 956047] [client 51.161.128.55:34032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.ritamayblog.com"] [uri "/"] [unique_id "aqxWhhFTPRVSLOsRVhoF1QAAATY"]
[Thu Sep 17 15:07:18.817248 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.git/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoF1gAAAU4"]
[Thu Sep 17 15:07:18.856926 2026] [security2:error] [pid 955873:tid 956030] [client 192.178.6.3:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF1wAAASU"]
[Thu Sep 17 15:07:18.920855 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/ci/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoF2AAAAWw"]
[Thu Sep 17 15:07:18.931773 2026] [security2:error] [pid 955873:tid 956039] [client 20.255.75.24:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/bak.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF2QAAAS4"]
[Thu Sep 17 15:07:19.010165 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cd/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF2wAAAUY"]
[Thu Sep 17 15:07:19.036386 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.221.252:56706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF3AAAAT4"]
[Thu Sep 17 15:07:19.049040 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:35374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxWhxFTPRVSLOsRVhoF3QAAAVk"]
[Thu Sep 17 15:07:19.151685 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/jenkins/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF4AAAAUI"]
[Thu Sep 17 15:07:19.206948 2026] [authz_core:error] [pid 955873:tid 956046] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Poly1305/error_log
[Thu Sep 17 15:07:19.208153 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxWhxFTPRVSLOsRVhoF4gAAATU"]
[Thu Sep 17 15:07:19.238131 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF4QAAATk"]
[Thu Sep 17 15:07:19.240412 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/gitlab/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF5QAAAR8"]
[Thu Sep 17 15:07:19.266442 2026] [security2:error] [pid 955873:tid 956044] [client 51.161.128.55:34044] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.ritamayblog.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxWhxFTPRVSLOsRVhoF5gAAATM"]
[Thu Sep 17 15:07:19.331554 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/github/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF5wAAAYg"]
[Thu Sep 17 15:07:19.356264 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:35374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWhxFTPRVSLOsRVhoF6gAAARQ"]
[Thu Sep 17 15:07:19.403675 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/actions/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF7wAAARA"]
[Thu Sep 17 15:07:19.423564 2026] [security2:error] [pid 955873:tid 956126] [client 20.255.75.24:1066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/cc.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF8QAAAYU"]
[Thu Sep 17 15:07:19.484230 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF7gAAASw"]
[Thu Sep 17 15:07:19.538110 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/circleci/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF9AAAAUE"]
[Thu Sep 17 15:07:19.625510 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/travis/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF-AAAAXA"]
[Thu Sep 17 15:07:19.659980 2026] [security2:error] [pid 955873:tid 956091] [client 34.166.190.5:40946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhxFTPRVSLOsRVhoF_AAAAWI"]
[Thu Sep 17 15:07:19.702054 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/buildkite/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoGAAAAARk"]
[Thu Sep 17 15:07:19.703695 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF8wAAAVw"]
[Thu Sep 17 15:07:19.703730 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF8wAAAVw"]
[Thu Sep 17 15:07:19.724023 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.221.252:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGAwAAAXg"]
[Thu Sep 17 15:07:19.773060 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF_wAAATI"]
[Thu Sep 17 15:07:19.846861 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGBAAAAUg"]
[Thu Sep 17 15:07:19.846982 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:35374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGBAAAAUg"]
[Thu Sep 17 15:07:19.849324 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mysql/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoGBQAAAYI"]
[Thu Sep 17 15:07:19.904294 2026] [security2:error] [pid 955873:tid 956120] [client 20.255.75.24:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/chosen.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGCgAAAX8"]
[Thu Sep 17 15:07:19.954845 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/postgres/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoGDQAAAQ4"]
[Thu Sep 17 15:07:19.988226 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGCwAAAV4"]
[Thu Sep 17 15:07:20.022078 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mongodb/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGDgAAAYA"]
[Thu Sep 17 15:07:20.106002 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWiBFTPRVSLOsRVhoGFAAAAXM"]
[Thu Sep 17 15:07:20.121580 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGFQAAAUM"]
[Thu Sep 17 15:07:20.121688 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:37218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGFQAAAUM"]
[Thu Sep 17 15:07:20.165182 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/redis/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGFwAAASU"]
[Thu Sep 17 15:07:20.185903 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWiBFTPRVSLOsRVhoGGQAAATg"]
[Thu Sep 17 15:07:20.196535 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:53937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGGAAAAVU"]
[Thu Sep 17 15:07:20.196698 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:53937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGGAAAAVU"]
[Thu Sep 17 15:07:20.223066 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/elasticsearch/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGHAAAAXU"]
[Thu Sep 17 15:07:20.300957 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/rabbitmq/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGJgAAAUk"]
[Thu Sep 17 15:07:20.365803 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGJQAAAYc"]
[Thu Sep 17 15:07:20.376271 2026] [security2:error] [pid 955873:tid 956100] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/kafka/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGKAAAAWs"]
[Thu Sep 17 15:07:20.385989 2026] [security2:error] [pid 955873:tid 956010] [client 20.255.75.24:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/classwithtostring.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGKQAAARE"]
[Thu Sep 17 15:07:20.401665 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGLQAAAVs"]
[Thu Sep 17 15:07:20.401767 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:37222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGLQAAAVs"]
[Thu Sep 17 15:07:20.413395 2026] [security2:error] [pid 955873:tid 956056] [client 34.166.221.252:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWiBFTPRVSLOsRVhoGLgAAAT8"]
[Thu Sep 17 15:07:20.435972 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/queue/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGMAAAAUA"]
[Thu Sep 17 15:07:20.530459 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/worker/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGNQAAASg"]
[Thu Sep 17 15:07:20.582625 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGNAAAAXc"]
[Thu Sep 17 15:07:20.584991 2026] [security2:error] [pid 955873:tid 956041] [client 162.241.226.11:60196] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGNgAAATA"]
[Thu Sep 17 15:07:20.592701 2026] [security2:error] [pid 955873:tid 956099] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGFgABakI"]
[Thu Sep 17 15:07:20.601120 2026] [security2:error] [pid 955873:tid 956079] [client 4.240.114.86:52001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGOQAAAVY"], referer: binance.com
[Thu Sep 17 15:07:20.614977 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/job/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGPAAAAUQ"]
[Thu Sep 17 15:07:20.641445 2026] [security2:error] [pid 955873:tid 956109] [client 104.207.47.59:59971] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWiBFTPRVSLOsRVhoGPgAAAXQ"]
[Thu Sep 17 15:07:20.680543 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:37226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxWiBFTPRVSLOsRVhoGRQAAAWI"]
[Thu Sep 17 15:07:20.684557 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/test/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGRwAAAVw"]
[Thu Sep 17 15:07:20.780339 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGSAAAAV0"]
[Thu Sep 17 15:07:20.815945 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/qa/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGSwAAAYk"]
[Thu Sep 17 15:07:20.846305 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxWiBFTPRVSLOsRVhoGTAAAAUg"]
[Thu Sep 17 15:07:20.881285 2026] [security2:error] [pid 955873:tid 956038] [client 20.255.75.24:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/wp-signup.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGTwAAAS0"]
[Thu Sep 17 15:07:20.901206 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/preview/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGUgAAASA"]
[Thu Sep 17 15:07:20.987667 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:37226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWiBFTPRVSLOsRVhoGVgAAAXo"]
[Thu Sep 17 15:07:20.987889 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/beta/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGVQAAATs"]
[Thu Sep 17 15:07:21.015433 2026] [security2:error] [pid 955873:tid 956103] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGPwABbkg"]
[Thu Sep 17 15:07:21.066164 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/uat/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGWQAAAVA"]
[Thu Sep 17 15:07:21.106921 2026] [security2:error] [pid 955873:tid 956074] [client 34.166.221.252:56730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWiRFTPRVSLOsRVhoGXAAAAVE"]
[Thu Sep 17 15:07:21.131493 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/stage/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGYwAAAWw"]
[Thu Sep 17 15:07:21.219885 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/development/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGagAAAQw"]
[Thu Sep 17 15:07:21.221155 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGYAAAAVU"]
[Thu Sep 17 15:07:21.342758 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGYQAAAXU"]
[Thu Sep 17 15:07:21.342789 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGYQAAAXU"]
[Thu Sep 17 15:07:21.350078 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/production/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGdAAAAVs"]
[Thu Sep 17 15:07:21.392341 2026] [security2:error] [pid 955873:tid 956027] [client 20.255.75.24:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/doc.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGdgAAASI"]
[Thu Sep 17 15:07:21.457100 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGdQAAASQ"]
[Thu Sep 17 15:07:21.459318 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/config/app/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGfAAAASg"]
[Thu Sep 17 15:07:21.514484 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGfQAAAYU"]
[Thu Sep 17 15:07:21.514592 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:37226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGfQAAAYU"]
[Thu Sep 17 15:07:21.554154 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.224.217:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGfgAAARw"]
[Thu Sep 17 15:07:21.571544 2026] [security2:error] [pid 955873:tid 956099] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGfwAAAWo"]
[Thu Sep 17 15:07:21.679167 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGhgAAASo"]
[Thu Sep 17 15:07:21.740503 2026] [security2:error] [pid 955873:tid 956118] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGewAAAX0"]
[Thu Sep 17 15:07:21.752264 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGhwAAARk"]
[Thu Sep 17 15:07:21.784134 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.221.252:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php~"] [unique_id "aqxWiRFTPRVSLOsRVhoGiAAAATo"]
[Thu Sep 17 15:07:21.797997 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:37242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGiwAAAQs"]
[Thu Sep 17 15:07:21.798088 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:37242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGiwAAAQs"]
[Thu Sep 17 15:07:21.812784 2026] [security2:error] [pid 955873:tid 956012] [client 169.58.198.243:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/themes/travel/issue.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGjAAAARM"], referer: www.google.com
[Thu Sep 17 15:07:21.824279 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGjgAAARI"]
[Thu Sep 17 15:07:21.846522 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/info.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGkgAAAXA"]
[Thu Sep 17 15:07:21.897527 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGlQAAAVI"]
[Thu Sep 17 15:07:21.905978 2026] [security2:error] [pid 955873:tid 956091] [client 20.255.75.24:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/edit.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGlgAAAWI"]
[Thu Sep 17 15:07:21.941751 2026] [access_compat:error] [pid 955873:tid 956111] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/comments
[Thu Sep 17 15:07:21.960809 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGnQAAAUg"]
[Thu Sep 17 15:07:22.075075 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxWihFTPRVSLOsRVhoGoQAAATE"]
[Thu Sep 17 15:07:22.075175 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxWihFTPRVSLOsRVhoGoQAAATE"]
[Thu Sep 17 15:07:22.178887 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/php.php"] [unique_id "aqxWihFTPRVSLOsRVhoGpwAAAVQ"]
[Thu Sep 17 15:07:22.187566 2026] [security2:error] [pid 955873:tid 956038] [client 24.49.37.67:40409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWihFTPRVSLOsRVhoGngABLVI"]
[Thu Sep 17 15:07:22.324894 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWihFTPRVSLOsRVhoGqQAAAXM"]
[Thu Sep 17 15:07:22.362136 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxWihFTPRVSLOsRVhoGtQAAAWs"]
[Thu Sep 17 15:07:22.362232 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:37264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxWihFTPRVSLOsRVhoGtQAAAWs"]
[Thu Sep 17 15:07:22.394869 2026] [security2:error] [pid 955873:tid 956070] [client 20.255.75.24:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/worksec.php"] [unique_id "aqxWihFTPRVSLOsRVhoGtgAAAU0"]
[Thu Sep 17 15:07:22.447625 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGtwAAAR8"]
[Thu Sep 17 15:07:22.459980 2026] [security2:error] [pid 955873:tid 956047] [client 104.248.203.175:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxWihFTPRVSLOsRVhoGsgABNko"], referer: http://mail.darfieldearthship.com/old/
[Thu Sep 17 15:07:22.485397 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.221.252:56752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/info.php.bak"] [unique_id "aqxWihFTPRVSLOsRVhoGuQAAAXs"]
[Thu Sep 17 15:07:22.525889 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGugAAASQ"]
[Thu Sep 17 15:07:22.607993 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGvwAAAS8"]
[Thu Sep 17 15:07:22.649061 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxWihFTPRVSLOsRVhoGwgAAAUw"]
[Thu Sep 17 15:07:22.649173 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:37266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxWihFTPRVSLOsRVhoGwgAAAUw"]
[Thu Sep 17 15:07:22.669068 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/i.php"] [unique_id "aqxWihFTPRVSLOsRVhoGxAAAASg"]
[Thu Sep 17 15:07:22.678267 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGxgAAASw"]
[Thu Sep 17 15:07:22.715371 2026] [security2:error] [pid 955873:tid 956099] [client 127.0.0.1:58452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxWihFTPRVSLOsRVhoGxQAAAWo"]
[Thu Sep 17 15:07:22.716254 2026] [security2:error] [pid 955873:tid 956126] [client 74.7.230.0:48616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.kuh.cvd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWihFTPRVSLOsRVhoGwwABhT4"]
[Thu Sep 17 15:07:22.769220 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGyAAAAX0"]
[Thu Sep 17 15:07:22.853287 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGzgAAAXA"]
[Thu Sep 17 15:07:22.877166 2026] [security2:error] [pid 955873:tid 956061] [client 20.255.75.24:1061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/ultra.php"] [unique_id "aqxWihFTPRVSLOsRVhoGzwAAAUQ"]
[Thu Sep 17 15:07:22.903566 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/pi.php"] [unique_id "aqxWihFTPRVSLOsRVhoG0AAAAVY"]
[Thu Sep 17 15:07:22.918262 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWihFTPRVSLOsRVhoG0QAAAV0"]
[Thu Sep 17 15:07:22.957720 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxWihFTPRVSLOsRVhoG0gAAAWI"]
[Thu Sep 17 15:07:22.957826 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:37276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxWihFTPRVSLOsRVhoG0gAAAWI"]
[Thu Sep 17 15:07:23.001780 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG0wAAAWE"]
[Thu Sep 17 15:07:23.106705 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG2gAAAUg"]
[Thu Sep 17 15:07:23.169729 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.221.252:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWixFTPRVSLOsRVhoG4gAAAVI"]
[Thu Sep 17 15:07:23.169899 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG4AAAASE"]
[Thu Sep 17 15:07:23.177099 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/pinfo.php"] [unique_id "aqxWixFTPRVSLOsRVhoG4wAAAXY"]
[Thu Sep 17 15:07:23.247219 2026] [security2:error] [pid 955873:tid 956101] [client 122.14.226.11:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "revelinfear.com"] [uri "/robots.txt"] [unique_id "aqxWixFTPRVSLOsRVhoG5AAAAWw"]
[Thu Sep 17 15:07:23.260003 2026] [security2:error] [pid 955873:tid 956052] [client 104.248.203.175:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoG4QABO2k"], referer: http://mail.darfieldearthship.com/blog/
[Thu Sep 17 15:07:23.261620 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:37282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWixFTPRVSLOsRVhoG5QAAAW4"]
[Thu Sep 17 15:07:23.263591 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG5gAAASU"]
[Thu Sep 17 15:07:23.350798 2026] [security2:error] [pid 955873:tid 956038] [client 20.255.75.24:1051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/gecko.php"] [unique_id "aqxWixFTPRVSLOsRVhoG7AAAAS0"]
[Thu Sep 17 15:07:23.351726 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG6wAAARU"]
[Thu Sep 17 15:07:23.401536 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWixFTPRVSLOsRVhoG7gAAAVA"]
[Thu Sep 17 15:07:23.401685 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:55542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWixFTPRVSLOsRVhoG7gAAAVA"]
[Thu Sep 17 15:07:23.442437 2026] [authz_core:error] [pid 955873:tid 956100] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/error_log
[Thu Sep 17 15:07:23.467050 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWixFTPRVSLOsRVhoG8AAAAWs"]
[Thu Sep 17 15:07:23.474706 2026] [security2:error] [pid 955873:tid 956072] [client 157.90.156.63:63806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoG8gAAAU8"], referer: https://eris.media
[Thu Sep 17 15:07:23.503970 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG8wAAATg"]
[Thu Sep 17 15:07:23.520132 2026] [security2:error] [pid 955873:tid 956110] [client 4.240.114.86:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxWixFTPRVSLOsRVhoG9QAAAXU"], referer: binance.com
[Thu Sep 17 15:07:23.566980 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/test.php"] [unique_id "aqxWixFTPRVSLOsRVhoG-AAAAXg"]
[Thu Sep 17 15:07:23.573397 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG-gAAAVs"]
[Thu Sep 17 15:07:23.605241 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:37282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/wp-includes/sodium_compat/src/"] [unique_id "aqxWixFTPRVSLOsRVhoG_QAAATk"]
[Thu Sep 17 15:07:23.652007 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG_wAAASQ"]
[Thu Sep 17 15:07:23.660032 2026] [security2:error] [pid 955873:tid 956044] [client 104.248.203.175:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoG-QABM2A"], referer: http://mail.darfieldearthship.com/backup/
[Thu Sep 17 15:07:23.742397 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHAQAAAV8"]
[Thu Sep 17 15:07:23.799701 2026] [security2:error] [pid 955873:tid 956126] [client 96.126.117.175:38218] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1452"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.bejackson.com"] [uri "/"] [unique_id "aqxWixFTPRVSLOsRVhoHBQAAAYU"]
[Thu Sep 17 15:07:23.818489 2026] [security2:error] [pid 955873:tid 956041] [client 24.49.37.67:57153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoHAAABMGU"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818001109&hideliu=1&hideminor=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:07:23.821183 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHBwAAAX0"]
[Thu Sep 17 15:07:23.823273 2026] [security2:error] [pid 955873:tid 956045] [client 20.255.75.24:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/goods.php"] [unique_id "aqxWixFTPRVSLOsRVhoHCAAAATQ"]
[Thu Sep 17 15:07:23.864160 2026] [security2:error] [pid 955873:tid 956057] [client 34.166.221.252:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWixFTPRVSLOsRVhoHCQAAAUA"]
[Thu Sep 17 15:07:23.920654 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHCgAAAT4"]
[Thu Sep 17 15:07:23.935601 2026] [security2:error] [pid 955873:tid 956015] [client 104.207.47.59:35261] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWixFTPRVSLOsRVhoHCwAAARY"]
[Thu Sep 17 15:07:23.951076 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoHAgAAAQ0"]
[Thu Sep 17 15:07:23.951101 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoHAgAAAQ0"]
[Thu Sep 17 15:07:23.994142 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHDgAAARk"]
[Thu Sep 17 15:07:24.040346 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.228.3:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHEQAAAXc"]
[Thu Sep 17 15:07:24.068188 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHEgAAATo"]
[Thu Sep 17 15:07:24.078813 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.224.217:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/p.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHEwAAAQs"]
[Thu Sep 17 15:07:24.088466 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHFgAAARM"]
[Thu Sep 17 15:07:24.088576 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:37282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHFgAAARM"]
[Thu Sep 17 15:07:24.136254 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHHAAAAV0"]
[Thu Sep 17 15:07:24.211899 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHIAAAARg"]
[Thu Sep 17 15:07:24.274801 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHJAAAAWw"]
[Thu Sep 17 15:07:24.316118 2026] [security2:error] [pid 955873:tid 956034] [client 20.255.75.24:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/man.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHJQAAASk"]
[Thu Sep 17 15:07:24.367862 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHKQAAAXM"]
[Thu Sep 17 15:07:24.373744 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/debug.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHKgAAAXY"]
[Thu Sep 17 15:07:24.380431 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHKwAAAVM"]
[Thu Sep 17 15:07:24.380536 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:37290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHKwAAAVM"]
[Thu Sep 17 15:07:24.452125 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHLQAAAS0"]
[Thu Sep 17 15:07:24.525460 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHLwAAAVQ"]
[Thu Sep 17 15:07:24.543730 2026] [security2:error] [pid 955873:tid 956078] [client 34.166.221.252:40236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHMAAAAVU"]
[Thu Sep 17 15:07:24.573618 2026] [security2:error] [pid 955873:tid 956120] [client 49.13.134.145:54624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxWjBFTPRVSLOsRVhoHMQAAAX8"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:07:24.616504 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHNgAAAU8"]
[Thu Sep 17 15:07:24.650748 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.224.217:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHNwAAAUo"]
[Thu Sep 17 15:07:24.678013 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:37298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxWjBFTPRVSLOsRVhoHOAAAAR8"]
[Thu Sep 17 15:07:24.687285 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHOQAAATY"]
[Thu Sep 17 15:07:24.741846 2026] [security2:error] [pid 955873:tid 956121] [client 34.166.228.3:33386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHOgAAAYA"]
[Thu Sep 17 15:07:24.770367 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHPAAAATk"]
[Thu Sep 17 15:07:24.840654 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHPgAAAQo"]
[Thu Sep 17 15:07:24.848417 2026] [authz_core:error] [pid 955873:tid 956092] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/ChaCha20/error_log
[Thu Sep 17 15:07:24.850983 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxWjBFTPRVSLOsRVhoHPQAAAWM"]
[Thu Sep 17 15:07:24.853172 2026] [security2:error] [pid 955873:tid 956070] [client 20.255.75.24:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/wp-settings.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHPwAAAU0"]
[Thu Sep 17 15:07:24.917430 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHQAAAAYg"]
[Thu Sep 17 15:07:24.974675 2026] [fcgid:warn] [pid 955873:tid 956127] (70014)End of file found: [client 66.132.186.206:9022] mod_fcgid: can't get data from http client
[Thu Sep 17 15:07:24.995856 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:37298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWjBFTPRVSLOsRVhoHRgAAAX0"]
[Thu Sep 17 15:07:25.003553 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHSAAAARY"]
[Thu Sep 17 15:07:25.045575 2026] [security2:error] [pid 955873:tid 956130] [client 49.13.134.145:54626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxWjRFTPRVSLOsRVhoHSQAAAYk"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:07:25.056104 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHSgAAASg"]
[Thu Sep 17 15:07:25.244014 2026] [security2:error] [pid 955873:tid 956006] [client 34.166.221.252:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHUQAAAQ0"]
[Thu Sep 17 15:07:25.326417 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHVQAAAV0"]
[Thu Sep 17 15:07:25.361133 2026] [security2:error] [pid 955873:tid 956012] [client 20.255.75.24:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/k.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHVwAAARM"]
[Thu Sep 17 15:07:25.373220 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHWAAAATI"]
[Thu Sep 17 15:07:25.375524 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHTQAAATo"]
[Thu Sep 17 15:07:25.375544 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHTQAAATo"]
[Thu Sep 17 15:07:25.419744 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHWgAAARg"]
[Thu Sep 17 15:07:25.436922 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.228.3:33394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHWwAAAUQ"]
[Thu Sep 17 15:07:25.507316 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHXQAAAXo"]
[Thu Sep 17 15:07:25.522302 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHXwAAAW4"]
[Thu Sep 17 15:07:25.522405 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:37298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHXwAAAW4"]
[Thu Sep 17 15:07:25.584974 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHYgAAASY"]
[Thu Sep 17 15:07:25.655848 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHaAAAAXY"]
[Thu Sep 17 15:07:25.687913 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.224.217:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHagAAASc"]
[Thu Sep 17 15:07:25.733766 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHawAAATc"]
[Thu Sep 17 15:07:25.804906 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHbwAAAR8"]
[Thu Sep 17 15:07:25.805080 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHcAAAATY"]
[Thu Sep 17 15:07:25.805171 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:37314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHcAAAATY"]
[Thu Sep 17 15:07:25.864804 2026] [security2:error] [pid 955873:tid 956038] [client 20.255.75.24:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/autoload_classmap.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHdgAAAS0"]
[Thu Sep 17 15:07:25.931921 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHggAAAS4"]
[Thu Sep 17 15:07:25.936169 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:58410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHggAAAS4"]
[Thu Sep 17 15:07:25.937120 2026] [security2:error] [pid 955873:tid 956122] [client 34.166.221.252:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHgwAAAYE"]
[Thu Sep 17 15:07:25.944544 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHhAAAAQo"]
[Thu Sep 17 15:07:26.017034 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHhwAAAV8"]
[Thu Sep 17 15:07:26.086386 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:37322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHigAAAWo"]
[Thu Sep 17 15:07:26.086502 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:37322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHigAAAWo"]
[Thu Sep 17 15:07:26.090850 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHjAAAAT0"]
[Thu Sep 17 15:07:26.093920 2026] [autoindex:error] [pid 955873:tid 956034] [client 4.240.114.86:54312] AH01276: Cannot serve directory /home2/ftlbllcn/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:07:26.100852 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.224.217:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHjQAAASQ"]
[Thu Sep 17 15:07:26.117731 2026] [security2:error] [pid 955873:tid 956028] [client 34.166.228.3:33396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHjgAAASM"]
[Thu Sep 17 15:07:26.158195 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHkQAAATA"]
[Thu Sep 17 15:07:26.280272 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHlwAAARA"]
[Thu Sep 17 15:07:26.363707 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHmAAAAWE"]
[Thu Sep 17 15:07:26.375783 2026] [security2:error] [pid 955873:tid 956114] [client 20.255.75.24:1075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/profile.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHmQAAAXk"]
[Thu Sep 17 15:07:26.386512 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:37332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxWjhFTPRVSLOsRVhoHmgAAARs"]
[Thu Sep 17 15:07:26.420495 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHnwAAAYk"]
[Thu Sep 17 15:07:26.461973 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHowAAATo"]
[Thu Sep 17 15:07:26.545225 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHpgAAAT8"]
[Thu Sep 17 15:07:26.546903 2026] [authz_core:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Curve25519/error_log
[Thu Sep 17 15:07:26.556305 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxWjhFTPRVSLOsRVhoHpQAAARo"]
[Thu Sep 17 15:07:26.663945 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHqQAAAQ8"]
[Thu Sep 17 15:07:26.669870 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.221.252:40260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHqwAAAUE"]
[Thu Sep 17 15:07:26.703478 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:37332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWjhFTPRVSLOsRVhoHrQAAASo"]
[Thu Sep 17 15:07:26.742378 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHrgAAASY"]
[Thu Sep 17 15:07:26.745354 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.224.217:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/php-info.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHsAAAAUI"]
[Thu Sep 17 15:07:26.812872 2026] [security2:error] [pid 955873:tid 956026] [client 34.166.228.3:33406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHsgAAASE"]
[Thu Sep 17 15:07:26.820560 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHswAAASc"]
[Thu Sep 17 15:07:26.907348 2026] [security2:error] [pid 955873:tid 956080] [client 20.255.75.24:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/server.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHuQAAAVc"]
[Thu Sep 17 15:07:26.915753 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHugAAAVQ"]
[Thu Sep 17 15:07:27.044036 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHvQAAASA"]
[Thu Sep 17 15:07:27.048672 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpversion.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHvgAAAUU"]
[Thu Sep 17 15:07:27.068523 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHuAAAATc"]
[Thu Sep 17 15:07:27.068553 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHuAAAATc"]
[Thu Sep 17 15:07:27.135873 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHxgAAAVs"]
[Thu Sep 17 15:07:27.206615 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHyQAAAUM"]
[Thu Sep 17 15:07:27.215450 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:37332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHygAAAXg"]
[Thu Sep 17 15:07:27.215600 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:37332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHygAAAXg"]
[Thu Sep 17 15:07:27.294118 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHzAAAATM"]
[Thu Sep 17 15:07:27.371510 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.221.252:40268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHzwAAATk"]
[Thu Sep 17 15:07:27.411230 2026] [security2:error] [pid 955873:tid 956073] [client 20.255.75.24:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/shell.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH0AAAAVA"]
[Thu Sep 17 15:07:27.430021 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/_phpinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH0QAAAYg"]
[Thu Sep 17 15:07:27.431471 2026] [security2:error] [pid 955873:tid 956027] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH0gAAASI"]
[Thu Sep 17 15:07:27.487750 2026] [security2:error] [pid 955873:tid 956087] [client 115.244.164.14:52371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH1AAAAV4"]
[Thu Sep 17 15:07:27.487889 2026] [security2:error] [pid 955873:tid 956087] [client 115.244.164.14:52371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH1AAAAV4"]
[Thu Sep 17 15:07:27.498906 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.228.3:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH1gAAAQo"]
[Thu Sep 17 15:07:27.502006 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH1wAAASM"]
[Thu Sep 17 15:07:27.502386 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:37338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxWjxFTPRVSLOsRVhoH2AAAASw"]
[Thu Sep 17 15:07:27.588918 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH3AAAAUA"]
[Thu Sep 17 15:07:27.669974 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxWjxFTPRVSLOsRVhoH3wAAAYc"]
[Thu Sep 17 15:07:27.714996 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH4gAAAXc"]
[Thu Sep 17 15:07:27.768833 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH5AAAAWE"]
[Thu Sep 17 15:07:27.805157 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH5QAAATI"]
[Thu Sep 17 15:07:27.819457 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:37338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxWjxFTPRVSLOsRVhoH5gAAATo"]
[Thu Sep 17 15:07:27.917955 2026] [security2:error] [pid 955873:tid 956012] [client 20.255.75.24:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/t.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH6AAAARM"]
[Thu Sep 17 15:07:27.925218 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH6QAAAT8"]
[Thu Sep 17 15:07:28.024347 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH7wAAAVw"]
[Thu Sep 17 15:07:28.056603 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.221.252:40280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8AAAAQ4"]
[Thu Sep 17 15:07:28.073536 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:41493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8QAAAXA"]
[Thu Sep 17 15:07:28.073724 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:41493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8QAAAXA"]
[Thu Sep 17 15:07:28.085625 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/server-info.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8wAAAYQ"]
[Thu Sep 17 15:07:28.124356 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH9QAAASc"]
[Thu Sep 17 15:07:28.179836 2026] [security2:error] [pid 955873:tid 956115] [client 4.240.114.86:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH9wAAAXo"], referer: binance.com
[Thu Sep 17 15:07:28.183205 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH-AAAAWU"]
[Thu Sep 17 15:07:28.194299 2026] [security2:error] [pid 955873:tid 956035] [client 34.166.228.3:33420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH-gAAASo"]
[Thu Sep 17 15:07:28.209923 2026] [security2:error] [pid 955873:tid 955908] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH_QABfyI"]
[Thu Sep 17 15:07:28.216490 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH6gAAAUE"]
[Thu Sep 17 15:07:28.216521 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH6gAAAUE"]
[Thu Sep 17 15:07:28.259025 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIAwAAAVQ"]
[Thu Sep 17 15:07:28.311014 2026] [security2:error] [pid 955873:tid 956072] [client 74.7.175.182:56044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hz2b27bgxqptl.dov.wxt.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWkBFTPRVSLOsRVhoIBgAAAU8"]
[Thu Sep 17 15:07:28.311069 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH-wABfxM"]
[Thu Sep 17 15:07:28.315019 2026] [security2:error] [pid 955873:tid 955907] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.bak"] [unique_id "aqxWkBFTPRVSLOsRVhoICwABfyE"]
[Thu Sep 17 15:07:28.316705 2026] [security2:error] [pid 955873:tid 955915] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.backup"] [unique_id "aqxWkBFTPRVSLOsRVhoIBwABfyk"]
[Thu Sep 17 15:07:28.320574 2026] [security2:error] [pid 955873:tid 955915] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.old"] [unique_id "aqxWkBFTPRVSLOsRVhoIDwABfyk"]
[Thu Sep 17 15:07:28.338830 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIAAABfwY"]
[Thu Sep 17 15:07:28.339547 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIAQABfyI"]
[Thu Sep 17 15:07:28.340305 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH_wABfw4"]
[Thu Sep 17 15:07:28.340533 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH_AABfxg"]
[Thu Sep 17 15:07:28.350155 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH_gABfyA"]
[Thu Sep 17 15:07:28.352325 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIEAAAAVs"]
[Thu Sep 17 15:07:28.358485 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEQAAAUg"]
[Thu Sep 17 15:07:28.358692 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:37338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEQAAAUg"]
[Thu Sep 17 15:07:28.368498 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/server-status.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEgAAATc"]
[Thu Sep 17 15:07:28.399217 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIDAABfx0"]
[Thu Sep 17 15:07:28.422057 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIFAAAAVU"]
[Thu Sep 17 15:07:28.426174 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoICQABfyU"]
[Thu Sep 17 15:07:28.427041 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIDgABfyE"]
[Thu Sep 17 15:07:28.434039 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIDQABfyo"]
[Thu Sep 17 15:07:28.435038 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoICgABfx8"]
[Thu Sep 17 15:07:28.438194 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoICAABfxM"]
[Thu Sep 17 15:07:28.438257 2026] [security2:error] [pid 955873:tid 956063] [client 20.255.75.24:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/hello.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIFQAAAUY"]
[Thu Sep 17 15:07:28.479002 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEwABfzA"]
[Thu Sep 17 15:07:28.501217 2026] [security2:error] [pid 955873:tid 955923] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env~"] [unique_id "aqxWkBFTPRVSLOsRVhoIGgABMzE"]
[Thu Sep 17 15:07:28.506262 2026] [security2:error] [pid 955873:tid 955900] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/.env.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIGQABMxo"]
[Thu Sep 17 15:07:28.520936 2026] [security2:error] [pid 955873:tid 955919] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.swp"] [unique_id "aqxWkBFTPRVSLOsRVhoIGwABMy0"]
[Thu Sep 17 15:07:28.527461 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIHQAAAXI"]
[Thu Sep 17 15:07:28.579246 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIFwABMys"]
[Thu Sep 17 15:07:28.582914 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIGAABMyQ"]
[Thu Sep 17 15:07:28.600391 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIHAABMzQ"]
[Thu Sep 17 15:07:28.607782 2026] [security2:error] [pid 955873:tid 955927] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/api/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIJAABMzU"]
[Thu Sep 17 15:07:28.608250 2026] [security2:error] [pid 955873:tid 955934] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/app/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIJgABMzw"]
[Thu Sep 17 15:07:28.630585 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIKQAAATk"]
[Thu Sep 17 15:07:28.642544 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:37340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIKgAAARQ"]
[Thu Sep 17 15:07:28.642702 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:37340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIKgAAARQ"]
[Thu Sep 17 15:07:28.653300 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIHwABMzI"]
[Thu Sep 17 15:07:28.654324 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIHgABMy4"]
[Thu Sep 17 15:07:28.654472 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIIAABMzc"]
[Thu Sep 17 15:07:28.662025 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIIgABMzg"]
[Thu Sep 17 15:07:28.666159 2026] [security2:error] [pid 955873:tid 956109] [client 169.58.198.243:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/themes/jaida/lang.php"] [unique_id "aqxWkBFTPRVSLOsRVhoILgAAAXQ"], referer: www.google.com
[Thu Sep 17 15:07:28.670595 2026] [security2:error] [pid 955873:tid 955932] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/backend/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoILwABMzo"]
[Thu Sep 17 15:07:28.683035 2026] [security2:error] [pid 955873:tid 955945] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/server/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIMgABM0c"]
[Thu Sep 17 15:07:28.688455 2026] [security2:error] [pid 955873:tid 955912] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/config/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIMwABMyY"]
[Thu Sep 17 15:07:28.703191 2026] [security2:error] [pid 955873:tid 955947] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/src/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoINAABM0k"]
[Thu Sep 17 15:07:28.703510 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIKAABMzY"]
[Thu Sep 17 15:07:28.708776 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoINQAAAT0"]
[Thu Sep 17 15:07:28.751636 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIMAABM0U"]
[Thu Sep 17 15:07:28.754090 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIMQABMzM"]
[Thu Sep 17 15:07:28.760591 2026] [security2:error] [pid 955873:tid 955939] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/web/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoINwABhkE"]
[Thu Sep 17 15:07:28.763318 2026] [security2:error] [pid 955873:tid 955938] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/client/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIOAABCkA"]
[Thu Sep 17 15:07:28.772909 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.221.252:40286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIOQAAAXw"]
[Thu Sep 17 15:07:28.781987 2026] [security2:error] [pid 955873:tid 955937] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/frontend/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIOgABJD8"]
[Thu Sep 17 15:07:28.789809 2026] [security2:error] [pid 955873:tid 955933] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/var/www/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIOwABIzs"]
[Thu Sep 17 15:07:28.789847 2026] [security2:error] [pid 955873:tid 955944] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/public/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIPAABI0Y"]
[Thu Sep 17 15:07:28.839147 2026] [security2:error] [pid 955873:tid 955904] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/var/www/html/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQQABMB4"]
[Thu Sep 17 15:07:28.839163 2026] [security2:error] [pid 955873:tid 955889] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/application/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIPwABMA8"]
[Thu Sep 17 15:07:28.839166 2026] [security2:error] [pid 955873:tid 955940] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/laravel/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQAABMEI"]
[Thu Sep 17 15:07:28.845763 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQwAAAVk"]
[Thu Sep 17 15:07:28.845843 2026] [security2:error] [pid 955873:tid 955879] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/apps/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQgABNAU"]
[Thu Sep 17 15:07:28.850644 2026] [security2:error] [pid 955873:tid 955949] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/back/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRAABPks"]
[Thu Sep 17 15:07:28.865151 2026] [security2:error] [pid 955873:tid 955931] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/backup/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRQABGTk"]
[Thu Sep 17 15:07:28.870198 2026] [security2:error] [pid 955873:tid 955941] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/cms/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRgABYEM"]
[Thu Sep 17 15:07:28.885561 2026] [security2:error] [pid 955873:tid 955913] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/prod/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRwABHCc"]
[Thu Sep 17 15:07:28.885591 2026] [security2:error] [pid 955873:tid 955946] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/dev/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoISAABHEg"]
[Thu Sep 17 15:07:28.933442 2026] [security2:error] [pid 955873:tid 955963] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/production/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoITQABWFk"]
[Thu Sep 17 15:07:28.934143 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoITgAAAYc"]
[Thu Sep 17 15:07:28.936143 2026] [security2:error] [pid 955873:tid 955942] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/staging/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoITwABWEQ"]
[Thu Sep 17 15:07:28.942331 2026] [security2:error] [pid 955873:tid 955959] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/test/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIUAABd1U"]
[Thu Sep 17 15:07:28.945314 2026] [security2:error] [pid 955873:tid 955956] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/old/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIUQABeVI"]
[Thu Sep 17 15:07:28.963851 2026] [security2:error] [pid 955873:tid 955955] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/new/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIVAABO1E"]
[Thu Sep 17 15:07:28.970281 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:37348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIVwAAARs"]
[Thu Sep 17 15:07:28.970388 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:37348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIVwAAARs"]
[Thu Sep 17 15:07:28.971365 2026] [security2:error] [pid 955873:tid 955936] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/api-backend/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIVQABRz4"]
[Thu Sep 17 15:07:28.971396 2026] [security2:error] [pid 955873:tid 955948] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/node-api/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIVgABR0o"]
[Thu Sep 17 15:07:29.022367 2026] [security2:error] [pid 955873:tid 955950] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/admin-app/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIWgABZ0w"]
[Thu Sep 17 15:07:29.022375 2026] [security2:error] [pid 955873:tid 955960] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/public_html/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIWwABZ1Y"]
[Thu Sep 17 15:07:29.026622 2026] [security2:error] [pid 955873:tid 955979] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/current/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXQABZ2k"]
[Thu Sep 17 15:07:29.027363 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXgAAAQs"]
[Thu Sep 17 15:07:29.030633 2026] [security2:error] [pid 955873:tid 955964] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/server/api/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXwABZ1o"]
[Thu Sep 17 15:07:29.047706 2026] [security2:error] [pid 955873:tid 955954] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/server/backend/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIYQABZ1A"]
[Thu Sep 17 15:07:29.051108 2026] [security2:error] [pid 955873:tid 955970] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.docker/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIYgABZ2A"]
[Thu Sep 17 15:07:29.067677 2026] [security2:error] [pid 955873:tid 955975] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/aws/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIYwABZ2U"]
[Thu Sep 17 15:07:29.067762 2026] [security2:error] [pid 955873:tid 955961] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIZAABZ1c"]
[Thu Sep 17 15:07:29.091355 2026] [security2:error] [pid 955873:tid 955968] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/administrator/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXAABZ14"]
[Thu Sep 17 15:07:29.115190 2026] [security2:error] [pid 955873:tid 955966] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.aws/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIZwABHlw"]
[Thu Sep 17 15:07:29.118171 2026] [security2:error] [pid 955873:tid 955973] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/stripe/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIaAABGGM"]
[Thu Sep 17 15:07:29.141216 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.228.3:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIawAAAUQ"]
[Thu Sep 17 15:07:29.145961 2026] [security2:error] [pid 955873:tid 955884] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/v1/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbAABgwo"]
[Thu Sep 17 15:07:29.154584 2026] [security2:error] [pid 955873:tid 955995] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/v3/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbQABg3k"]
[Thu Sep 17 15:07:29.154640 2026] [security2:error] [pid 955873:tid 955991] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/v2/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbgABg3U"]
[Thu Sep 17 15:07:29.155494 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbwAAARo"]
[Thu Sep 17 15:07:29.207101 2026] [security2:error] [pid 955873:tid 955972] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/media/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIdwABg2I"]
[Thu Sep 17 15:07:29.214565 2026] [security2:error] [pid 955873:tid 956124] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIaQABg3E"]
[Thu Sep 17 15:07:29.214973 2026] [security2:error] [pid 955873:tid 956124] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIagABg2c"]
[Thu Sep 17 15:07:29.238051 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIgAAAAQw"]
[Thu Sep 17 15:07:29.284464 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIgQAAATE"]
[Thu Sep 17 15:07:29.284608 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIgQAAATE"]
[Thu Sep 17 15:07:29.300882 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWkRFTPRVSLOsRVhoIggAAASA"]
[Thu Sep 17 15:07:29.337593 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIhAAAATg"]
[Thu Sep 17 15:07:29.407430 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIhgAAAXM"]
[Thu Sep 17 15:07:29.432328 2026] [security2:error] [pid 955873:tid 955969] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.git/config.bak"] [unique_id "aqxWkRFTPRVSLOsRVhoIkAABSF8"]
[Thu Sep 17 15:07:29.452707 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.221.252:40302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWkRFTPRVSLOsRVhoImQAAAU4"]
[Thu Sep 17 15:07:29.501112 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoInQAAATk"]
[Thu Sep 17 15:07:29.573754 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:37362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIogAAASk"]
[Thu Sep 17 15:07:29.573859 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:37362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIogAAASk"]
[Thu Sep 17 15:07:29.593337 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIpAAAAV4"]
[Thu Sep 17 15:07:29.615570 2026] [security2:error] [pid 955873:tid 955935] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.aws/credentials.bak"] [unique_id "aqxWkRFTPRVSLOsRVhoIqwABiD0"]
[Thu Sep 17 15:07:29.618096 2026] [security2:error] [pid 955873:tid 955874] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/id_rsa"] [unique_id "aqxWkRFTPRVSLOsRVhoIsAABiAA"]
[Thu Sep 17 15:07:29.618631 2026] [security2:error] [pid 955873:tid 955875] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.ssh/id_rsa"] [unique_id "aqxWkRFTPRVSLOsRVhoIrwABiAE"]
[Thu Sep 17 15:07:29.627282 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIuQAAAV8"]
[Thu Sep 17 15:07:29.674102 2026] [security2:error] [pid 955873:tid 956113] [client 57.141.14.33:45090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoImAABeHM"]
[Thu Sep 17 15:07:29.678750 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIvwAAARA"]
[Thu Sep 17 15:07:29.706133 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoItgABiH0"]
[Thu Sep 17 15:07:29.707952 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoItAABiBQ"]
[Thu Sep 17 15:07:29.708082 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIqgABiAg"]
[Thu Sep 17 15:07:29.708164 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIqQABiAc"]
[Thu Sep 17 15:07:29.708303 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIrQABiA0"]
[Thu Sep 17 15:07:29.711810 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIrAABiBE"]
[Thu Sep 17 15:07:29.720076 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIrgABiBY"]
[Thu Sep 17 15:07:29.776125 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIwQAAARI"]
[Thu Sep 17 15:07:29.826409 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.228.3:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIywAAAXw"]
[Thu Sep 17 15:07:29.875832 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzAAAAV0"]
[Thu Sep 17 15:07:29.875964 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:43954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzAAAAV0"]
[Thu Sep 17 15:07:29.879601 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIzQAAATs"]
[Thu Sep 17 15:07:29.886726 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIyQABL3c"]
[Thu Sep 17 15:07:29.886833 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIxwABL2E"]
[Thu Sep 17 15:07:29.886933 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIygABLyk"]
[Thu Sep 17 15:07:29.887008 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIxQABLxU"]
[Thu Sep 17 15:07:29.889118 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIxgABLyM"]
[Thu Sep 17 15:07:29.952169 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoI1QAAAYk"]
[Thu Sep 17 15:07:29.968312 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI0gABLxk"]
[Thu Sep 17 15:07:29.968637 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI0wABLyA"]
[Thu Sep 17 15:07:29.969139 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzwABLw4"]
[Thu Sep 17 15:07:29.969629 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzgABLwY"]
[Thu Sep 17 15:07:29.971538 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI0QABLxg"]
[Thu Sep 17 15:07:30.012955 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI2wAAAVg"]
[Thu Sep 17 15:07:30.039117 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoI3QAAAR4"]
[Thu Sep 17 15:07:30.064539 2026] [security2:error] [pid 955873:tid 956043] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI2QABMio"]
[Thu Sep 17 15:07:30.064685 2026] [security2:error] [pid 955873:tid 956043] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI2AABMiE"]
[Thu Sep 17 15:07:30.066679 2026] [security2:error] [pid 955873:tid 955917] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI4gABaSs"]
[Thu Sep 17 15:07:30.113098 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoI6gAAARo"]
[Thu Sep 17 15:07:30.141081 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.221.252:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI9QAAAUc"]
[Thu Sep 17 15:07:30.150915 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI4wABaTQ"]
[Thu Sep 17 15:07:30.153312 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI5QABaTU"]
[Thu Sep 17 15:07:30.159010 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-wAAAT8"]
[Thu Sep 17 15:07:30.159159 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:43968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-wAAAT8"]
[Thu Sep 17 15:07:30.170529 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI5wABaTI"]
[Thu Sep 17 15:07:30.208892 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJAwAAAR0"]
[Thu Sep 17 15:07:30.245013 2026] [security2:error] [pid 955873:tid 955933] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/aws.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJBQABaTs"]
[Thu Sep 17 15:07:30.246693 2026] [security2:error] [pid 955873:tid 955904] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/stripe.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJBgABaR4"]
[Thu Sep 17 15:07:30.249117 2026] [security2:error] [pid 955873:tid 955940] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/mail.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJCAABaUI"]
[Thu Sep 17 15:07:30.250788 2026] [security2:error] [pid 955873:tid 955879] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/config.inc.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJCQABaQU"]
[Thu Sep 17 15:07:30.260971 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-AABaUU"]
[Thu Sep 17 15:07:30.263372 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI9gABaTY"]
[Thu Sep 17 15:07:30.267190 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-QABaTM"]
[Thu Sep 17 15:07:30.268216 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI9wABaUk"]
[Thu Sep 17 15:07:30.272865 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-gABaUE"]
[Thu Sep 17 15:07:30.287918 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI_gABaUA"]
[Thu Sep 17 15:07:30.291870 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJDAAAATY"]
[Thu Sep 17 15:07:30.302496 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJDQAAASA"]
[Thu Sep 17 15:07:30.326232 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJBwABaQ8"]
[Thu Sep 17 15:07:30.361530 2026] [security2:error] [pid 955873:tid 955931] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/nexmo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJEgABVTk"]
[Thu Sep 17 15:07:30.391775 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJFAAAATU"]
[Thu Sep 17 15:07:30.425739 2026] [security2:error] [pid 955873:tid 955963] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJGAABVVk"]
[Thu Sep 17 15:07:30.426510 2026] [security2:error] [pid 955873:tid 955942] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php.bak"] [unique_id "aqxWkhFTPRVSLOsRVhoJGQABVUQ"]
[Thu Sep 17 15:07:30.428806 2026] [security2:error] [pid 955873:tid 955959] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php.old"] [unique_id "aqxWkhFTPRVSLOsRVhoJGwABVVU"]
[Thu Sep 17 15:07:30.428806 2026] [security2:error] [pid 955873:tid 955956] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php.new"] [unique_id "aqxWkhFTPRVSLOsRVhoJGgABVVI"]
[Thu Sep 17 15:07:30.431047 2026] [security2:error] [pid 955873:tid 955962] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/.wp-config.php.swp"] [unique_id "aqxWkhFTPRVSLOsRVhoJHAABVVg"]
[Thu Sep 17 15:07:30.436564 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJEQABVSc"]
[Thu Sep 17 15:07:30.438059 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJEAABVSw"]
[Thu Sep 17 15:07:30.441738 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJDwABVUM"]
[Thu Sep 17 15:07:30.447292 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHwAAAUY"]
[Thu Sep 17 15:07:30.447385 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:43972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHwAAAUY"]
[Thu Sep 17 15:07:30.447907 2026] [security2:error] [pid 955873:tid 955948] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/wp-content/mysql.sql"] [unique_id "aqxWkhFTPRVSLOsRVhoJIAABVUo"]
[Thu Sep 17 15:07:30.475363 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJJQAAAS0"]
[Thu Sep 17 15:07:30.515234 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHQABVVE"]
[Thu Sep 17 15:07:30.520925 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHgABVT4"]
[Thu Sep 17 15:07:30.533428 2026] [security2:error] [pid 955873:tid 956106] [client 34.166.228.3:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJJwAAAXE"]
[Thu Sep 17 15:07:30.613241 2026] [security2:error] [pid 955873:tid 955966] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/terraform.tfstate.backup"] [unique_id "aqxWkhFTPRVSLOsRVhoJMQABhlw"]
[Thu Sep 17 15:07:30.622137 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJOAAAAQo"]
[Thu Sep 17 15:07:30.626768 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJOQAAAXQ"]
[Thu Sep 17 15:07:30.698842 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJNAABhnk"]
[Thu Sep 17 15:07:30.699064 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJMgABhmM"]
[Thu Sep 17 15:07:30.699905 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJQwAAASw"]
[Thu Sep 17 15:07:30.700447 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJNgABhmI"]
[Thu Sep 17 15:07:30.704039 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJNwABhnI"]
[Thu Sep 17 15:07:30.705497 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJMAABhl4"]
[Thu Sep 17 15:07:30.714241 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJOgABhm8"]
[Thu Sep 17 15:07:30.738548 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:43986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJRgAAAUI"]
[Thu Sep 17 15:07:30.738700 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:43986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJRgAAAUI"]
[Thu Sep 17 15:07:30.766047 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJPQABhnE"]
[Thu Sep 17 15:07:30.771948 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJRwAAARE"]
[Thu Sep 17 15:07:30.774379 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJQgABhnY"]
[Thu Sep 17 15:07:30.780218 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJQAABhnA"]
[Thu Sep 17 15:07:30.783588 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJRAABhmY"]
[Thu Sep 17 15:07:30.851013 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.221.252:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJTAAAAUo"]
[Thu Sep 17 15:07:30.862835 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJSQABEHg"]
[Thu Sep 17 15:07:30.862933 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJSAABEGg"]
[Thu Sep 17 15:07:30.888361 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJVAAAAT4"]
[Thu Sep 17 15:07:30.930464 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJTQABEG4"]
[Thu Sep 17 15:07:30.930545 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJTgABEGQ"]
[Thu Sep 17 15:07:30.964835 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJXgAAARI"]
[Thu Sep 17 15:07:30.971775 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJUwABEF8"]
[Thu Sep 17 15:07:30.993504 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJYAAAARk"]
[Thu Sep 17 15:07:31.022296 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJYQAAAVk"]
[Thu Sep 17 15:07:31.022415 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:43998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJYQAAAVk"]
[Thu Sep 17 15:07:31.023553 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJWgABEGw"]
[Thu Sep 17 15:07:31.041254 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJYgAAAXs"]
[Thu Sep 17 15:07:31.067236 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJagAAATA"]
[Thu Sep 17 15:07:31.067356 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJagAAATA"]
[Thu Sep 17 15:07:31.132054 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJaQABOxw"]
[Thu Sep 17 15:07:31.133506 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJZgABOwQ"]
[Thu Sep 17 15:07:31.135026 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJZwABOxs"]
[Thu Sep 17 15:07:31.147471 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJbQABOwE"]
[Thu Sep 17 15:07:31.157776 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJdQAAAQs"]
[Thu Sep 17 15:07:31.218419 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.228.3:33454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJegAAAXw"]
[Thu Sep 17 15:07:31.224639 2026] [security2:error] [pid 955873:tid 955914] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJfAABOyg"]
[Thu Sep 17 15:07:31.240042 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJfQAAAYA"]
[Thu Sep 17 15:07:31.267161 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJbgABO3M"]
[Thu Sep 17 15:07:31.291788 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJbwABOxQ"]
[Thu Sep 17 15:07:31.293976 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWkxFTPRVSLOsRVhoJfwAAARM"]
[Thu Sep 17 15:07:31.295573 2026] [security2:error] [pid 955873:tid 955997] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/info.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJgAABO3s"]
[Thu Sep 17 15:07:31.309731 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJcQABOwg"]
[Thu Sep 17 15:07:31.312345 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJcgABOwc"]
[Thu Sep 17 15:07:31.313522 2026] [security2:error] [pid 955873:tid 955971] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/php_info.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJgQABO2E"]
[Thu Sep 17 15:07:31.313546 2026] [security2:error] [pid 955873:tid 955993] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/infos.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJggABO3c"]
[Thu Sep 17 15:07:31.314124 2026] [security2:error] [pid 955873:tid 955915] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/php.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJgwABOyk"]
[Thu Sep 17 15:07:31.319181 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJdAABOxE"]
[Thu Sep 17 15:07:31.320656 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhAAAAUk"]
[Thu Sep 17 15:07:31.320764 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhAAAAUk"]
[Thu Sep 17 15:07:31.328254 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJdgABOxY"]
[Thu Sep 17 15:07:31.329418 2026] [security2:error] [pid 955873:tid 955909] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/php-info.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhgABOyM"]
[Thu Sep 17 15:07:31.329447 2026] [security2:error] [pid 955873:tid 955908] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/infophp.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhwABOyI"]
[Thu Sep 17 15:07:31.332462 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJewABOwI"]
[Thu Sep 17 15:07:31.332914 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJeQABOxA"]
[Thu Sep 17 15:07:31.336096 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJfgABOwM"]
[Thu Sep 17 15:07:31.343848 2026] [security2:error] [pid 955873:tid 956089] [client 104.28.198.244:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJiAAAAWA"]
[Thu Sep 17 15:07:31.343951 2026] [security2:error] [pid 955873:tid 956089] [client 104.28.198.244:22919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJiAAAAWA"]
[Thu Sep 17 15:07:31.387299 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJigAAAUE"]
[Thu Sep 17 15:07:31.448683 2026] [security2:error] [pid 955873:tid 955899] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJjwABZRk"]
[Thu Sep 17 15:07:31.457502 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJkAAAAU8"]
[Thu Sep 17 15:07:31.472071 2026] [security2:error] [pid 955873:tid 955906] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/admin/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJkQABZSA"]
[Thu Sep 17 15:07:31.475840 2026] [security2:error] [pid 955873:tid 955888] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/admin_phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJkgABZQ4"]
[Thu Sep 17 15:07:31.488775 2026] [security2:error] [pid 955873:tid 956094] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJiwABZR0"]
[Thu Sep 17 15:07:31.489779 2026] [security2:error] [pid 955873:tid 955880] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/api/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJkwABOAY"]
[Thu Sep 17 15:07:31.491820 2026] [security2:error] [pid 955873:tid 955898] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/public/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJlAABHRg"]
[Thu Sep 17 15:07:31.514205 2026] [security2:error] [pid 955873:tid 955917] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/database.sql"] [unique_id "aqxWkxFTPRVSLOsRVhoJnQABdSs"]
[Thu Sep 17 15:07:31.526674 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJnwAAASQ"]
[Thu Sep 17 15:07:31.542965 2026] [security2:error] [pid 955873:tid 956035] [client 34.166.221.252:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJogAAASo"]
[Thu Sep 17 15:07:31.576425 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJlwABdRM"]
[Thu Sep 17 15:07:31.579324 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJlQABdSU"]
[Thu Sep 17 15:07:31.583037 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmAABdTA"]
[Thu Sep 17 15:07:31.586434 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmwABdSo"]
[Thu Sep 17 15:07:31.588235 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmQABdRo"]
[Thu Sep 17 15:07:31.589728 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJnAABdSE"]
[Thu Sep 17 15:07:31.592261 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJngABdS0"]
[Thu Sep 17 15:07:31.592378 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmgABdTE"]
[Thu Sep 17 15:07:31.597222 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJpgAAAR8"]
[Thu Sep 17 15:07:31.613468 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:44018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJpwAAATc"]
[Thu Sep 17 15:07:31.613561 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:44018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJpwAAATc"]
[Thu Sep 17 15:07:31.638041 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.224.217:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWkxFTPRVSLOsRVhoJqQAAAWw"]
[Thu Sep 17 15:07:31.703460 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJrQAAAU4"]
[Thu Sep 17 15:07:31.710176 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJqAABSEc"]
[Thu Sep 17 15:07:31.734823 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJqgABSDo"]
[Thu Sep 17 15:07:31.736286 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJrAABSDg"]
[Thu Sep 17 15:07:31.752396 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJrgABSDQ"]
[Thu Sep 17 15:07:31.763451 2026] [security2:error] [pid 955873:tid 955933] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.backup.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtwABgTs"]
[Thu Sep 17 15:07:31.793537 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJvQAAAU0"]
[Thu Sep 17 15:07:31.840083 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtAABgTc"]
[Thu Sep 17 15:07:31.840228 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtQABgSY"]
[Thu Sep 17 15:07:31.840297 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJuAABgR4"]
[Thu Sep 17 15:07:31.843739 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtgABgS8"]
[Thu Sep 17 15:07:31.847618 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJuQABgUY"]
[Thu Sep 17 15:07:31.851678 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJugABgUI"]
[Thu Sep 17 15:07:31.876639 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJwAAAARQ"]
[Thu Sep 17 15:07:31.912841 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.228.3:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJwwAAAXA"]
[Thu Sep 17 15:07:31.923339 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:44020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxWkxFTPRVSLOsRVhoJxgAAAS0"]
[Thu Sep 17 15:07:31.952644 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJygAAAWI"]
[Thu Sep 17 15:07:31.993954 2026] [security2:error] [pid 955873:tid 956027] [client 4.240.114.86:57759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJzQAAASI"], referer: binance.com
[Thu Sep 17 15:07:32.021484 2026] [authz_core:error] [pid 955873:tid 955963] [remote 45.138.12.28:59012] AH01630: client denied by server configuration: /home3/sherrym6/public_html/.htpasswd
[Thu Sep 17 15:07:32.021560 2026] [security2:error] [pid 955873:tid 955952] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/vendor/.env"] [unique_id "aqxWlBFTPRVSLOsRVhoJzwABY04"]
[Thu Sep 17 15:07:32.060074 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php~"] [unique_id "aqxWlBFTPRVSLOsRVhoJ1gAAAXE"]
[Thu Sep 17 15:07:32.074409 2026] [security2:error] [pid 955873:tid 955962] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/sites/default/settings.local.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ2QABY1g"]
[Thu Sep 17 15:07:32.085023 2026] [authz_core:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Poly1305/error_log
[Thu Sep 17 15:07:32.086295 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ2AAAAV8"]
[Thu Sep 17 15:07:32.148151 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ1wAAAXQ"]
[Thu Sep 17 15:07:32.182569 2026] [security2:error] [pid 955873:tid 956010] [client 34.74.242.206:41744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4AAAARE"]
[Thu Sep 17 15:07:32.182682 2026] [security2:error] [pid 955873:tid 956010] [client 34.74.242.206:41744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4AAAARE"]
[Thu Sep 17 15:07:32.202977 2026] [security2:error] [pid 955873:tid 955948] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/panel/.env"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4QABY0o"]
[Thu Sep 17 15:07:32.203337 2026] [security2:error] [pid 955873:tid 955950] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.local.swp"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4wABY0w"]
[Thu Sep 17 15:07:32.232196 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:44020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ5AAAAYY"]
[Thu Sep 17 15:07:32.256691 2026] [security2:error] [pid 955873:tid 956079] [client 34.166.221.252:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ5wAAAVY"]
[Thu Sep 17 15:07:32.290568 2026] [security2:error] [pid 955873:tid 956075] [client 34.74.242.206:41728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stevenreedcollins.com"] [uri "/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ6AAAAVI"]
[Thu Sep 17 15:07:32.290738 2026] [security2:error] [pid 955873:tid 956075] [client 34.74.242.206:41728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stevenreedcollins.com"] [uri "/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ6AAAAVI"]
[Thu Sep 17 15:07:32.293734 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJvgABYzY"]
[Thu Sep 17 15:07:32.298543 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJvwABYzM"]
[Thu Sep 17 15:07:32.322912 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJwQABY0k"]
[Thu Sep 17 15:07:32.337687 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJyQABYzk"]
[Thu Sep 17 15:07:32.338619 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ0wABY1I"]
[Thu Sep 17 15:07:32.339079 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJywABY0g"]
[Thu Sep 17 15:07:32.339439 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJzAABY08"]
[Thu Sep 17 15:07:32.339552 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJxQABYy4"]
[Thu Sep 17 15:07:32.342337 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ0gABY1U"]
[Thu Sep 17 15:07:32.364814 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ3QABY0M"]
[Thu Sep 17 15:07:32.367277 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4gABY1Y"]
[Thu Sep 17 15:07:32.422871 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/info.php.bak"] [unique_id "aqxWlBFTPRVSLOsRVhoJ7wAAAX0"]
[Thu Sep 17 15:07:32.591307 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ8AAAAUA"]
[Thu Sep 17 15:07:32.607411 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.228.3:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ9AAAAS4"]
[Thu Sep 17 15:07:32.618395 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ7QAAAYc"]
[Thu Sep 17 15:07:32.618426 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ7QAAAYc"]
[Thu Sep 17 15:07:32.662267 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWlBFTPRVSLOsRVhoJ9wAAAVg"]
[Thu Sep 17 15:07:32.701028 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWlBFTPRVSLOsRVhoJ-wAAARM"]
[Thu Sep 17 15:07:32.762721 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ_wAAATE"]
[Thu Sep 17 15:07:32.762841 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:44020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ_wAAATE"]
[Thu Sep 17 15:07:32.953618 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.221.252:40360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoKAgAAATs"]
[Thu Sep 17 15:07:32.984917 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoKAwAAAVo"]
[Thu Sep 17 15:07:33.009614 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKBAAAAVQ"]
[Thu Sep 17 15:07:33.091234 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKBQAAAXY"]
[Thu Sep 17 15:07:33.162154 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKCgAAAYQ"]
[Thu Sep 17 15:07:33.162252 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:44036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKCgAAAYQ"]
[Thu Sep 17 15:07:33.199292 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKDAAAAR8"]
[Thu Sep 17 15:07:33.292387 2026] [security2:error] [pid 955873:tid 956072] [client 34.166.228.3:55126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKDQAAAU8"]
[Thu Sep 17 15:07:33.300252 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKDwAAARc"]
[Thu Sep 17 15:07:33.304290 2026] [cgid:error] [pid 955873:tid 955970] [remote 172.225.228.23:37424] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:07:33.327046 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKEAAAATc"]
[Thu Sep 17 15:07:33.371739 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKEQAAAUg"]
[Thu Sep 17 15:07:33.458781 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKEwAAAVs"]
[Thu Sep 17 15:07:33.465556 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:44044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxWlRFTPRVSLOsRVhoKFAAAAYE"]
[Thu Sep 17 15:07:33.528274 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKFwAAAXA"]
[Thu Sep 17 15:07:33.622541 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKHQAAASw"]
[Thu Sep 17 15:07:33.639469 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxWlRFTPRVSLOsRVhoKHgAAAQ0"]
[Thu Sep 17 15:07:33.693792 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKIQAAAXQ"]
[Thu Sep 17 15:07:33.764080 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:50262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKJQAAAV4"]
[Thu Sep 17 15:07:33.765069 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKJAAAAXg"]
[Thu Sep 17 15:07:33.786771 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:44044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWlRFTPRVSLOsRVhoKJgAAAYY"]
[Thu Sep 17 15:07:33.833052 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKKQAAAWQ"]
[Thu Sep 17 15:07:33.899549 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKLQAAARA"]
[Thu Sep 17 15:07:33.973979 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKMwAAARs"]
[Thu Sep 17 15:07:33.984874 2026] [security2:error] [pid 955873:tid 956010] [client 34.166.228.3:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKNAAAARE"]
[Thu Sep 17 15:07:34.037148 2026] [security2:error] [pid 955873:tid 956102] [client 185.55.149.49:56378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKNgAAAW0"]
[Thu Sep 17 15:07:34.037301 2026] [security2:error] [pid 955873:tid 956102] [client 185.55.149.49:56378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKNgAAAW0"]
[Thu Sep 17 15:07:34.042811 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKNwAAARY"]
[Thu Sep 17 15:07:34.094783 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:50266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKOgAAASM"]
[Thu Sep 17 15:07:34.127993 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKPQAAAUo"]
[Thu Sep 17 15:07:34.159211 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKMAAAAV0"]
[Thu Sep 17 15:07:34.159235 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKMAAAAV0"]
[Thu Sep 17 15:07:34.253249 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKQgAAATE"]
[Thu Sep 17 15:07:34.305190 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKQwAAAUk"]
[Thu Sep 17 15:07:34.305295 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKQwAAAUk"]
[Thu Sep 17 15:07:34.331475 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKRgAAAQw"]
[Thu Sep 17 15:07:34.366842 2026] [security2:error] [pid 955873:tid 956064] [client 74.7.244.19:42578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azclassicbronco.org"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhQABRxU"]
[Thu Sep 17 15:07:34.419528 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKVAAAAVo"]
[Thu Sep 17 15:07:34.447880 2026] [security2:error] [pid 955873:tid 956069] [client 138.0.33.64:7854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKRAABTAo"]
[Thu Sep 17 15:07:34.451942 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:50270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKYwAAASg"]
[Thu Sep 17 15:07:34.507741 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKZQAAAXU"]
[Thu Sep 17 15:07:34.587762 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKZwAAAWU"]
[Thu Sep 17 15:07:34.602919 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:44060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKaQAAAVE"]
[Thu Sep 17 15:07:34.603026 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:44060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKaQAAAVE"]
[Thu Sep 17 15:07:34.677088 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKbQAAAVU"]
[Thu Sep 17 15:07:34.732736 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKdAAAAUU"]
[Thu Sep 17 15:07:34.750013 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKdQAAAV8"]
[Thu Sep 17 15:07:34.844357 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKegAAASY"]
[Thu Sep 17 15:07:34.898110 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:44066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKfQAAAUs"]
[Thu Sep 17 15:07:34.898218 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:44066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKfQAAAUs"]
[Thu Sep 17 15:07:34.918602 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKfwAAATM"]
[Thu Sep 17 15:07:34.960831 2026] [security2:error] [pid 955873:tid 956011] [client 34.166.228.3:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKgwAAARI"]
[Thu Sep 17 15:07:34.988062 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKhAAAARw"]
[Thu Sep 17 15:07:35.055643 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKhQAAAUI"]
[Thu Sep 17 15:07:35.100362 2026] [security2:error] [pid 955873:tid 956109] [client 74.125.212.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKdgAAAXQ"]
[Thu Sep 17 15:07:35.141253 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKkgAAAWI"]
[Thu Sep 17 15:07:35.149805 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKlAAAARs"]
[Thu Sep 17 15:07:35.196737 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:44082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKmQAAAQ8"]
[Thu Sep 17 15:07:35.196854 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:44082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKmQAAAQ8"]
[Thu Sep 17 15:07:35.211992 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKmgAAATI"]
[Thu Sep 17 15:07:35.279379 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKowAAARo"]
[Thu Sep 17 15:07:35.337231 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKpgAAAXw"]
[Thu Sep 17 15:07:35.339494 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.224.217:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKpwAAATE"]
[Thu Sep 17 15:07:35.411255 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKqgAAAT4"]
[Thu Sep 17 15:07:35.486264 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:44094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKrQAAAYA"]
[Thu Sep 17 15:07:35.486373 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:44094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKrQAAAYA"]
[Thu Sep 17 15:07:35.494108 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKrgAAAVo"]
[Thu Sep 17 15:07:35.499824 2026] [security2:error] [pid 955873:tid 956054] [client 4.240.114.86:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKrwAAAT0"], referer: binance.com
[Thu Sep 17 15:07:35.565298 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKsQAAAQ4"]
[Thu Sep 17 15:07:35.626103 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKuAAAATo"]
[Thu Sep 17 15:07:35.645452 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.228.3:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKuQAAAS8"]
[Thu Sep 17 15:07:35.649104 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKugAAAVQ"]
[Thu Sep 17 15:07:35.710105 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKuwAAAWw"]
[Thu Sep 17 15:07:35.764490 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKwAAAASk"]
[Thu Sep 17 15:07:35.764586 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:44102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKwAAAASk"]
[Thu Sep 17 15:07:35.794368 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKwwAAAVE"]
[Thu Sep 17 15:07:35.880771 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKxwAAAXE"]
[Thu Sep 17 15:07:35.963363 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKyQAAAUU"]
[Thu Sep 17 15:07:36.045984 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoKywAAASU"]
[Thu Sep 17 15:07:36.060188 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxWmBFTPRVSLOsRVhoKzQAAASA"]
[Thu Sep 17 15:07:36.060279 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:44114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxWmBFTPRVSLOsRVhoKzQAAASA"]
[Thu Sep 17 15:07:36.104013 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK0gAAAUs"]
[Thu Sep 17 15:07:36.171716 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK2AAAAWM"]
[Thu Sep 17 15:07:36.257783 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK2wAAAVA"]
[Thu Sep 17 15:07:36.332034 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK3wAAARQ"]
[Thu Sep 17 15:07:36.337938 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.228.3:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4AAAAV4"]
[Thu Sep 17 15:07:36.351440 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4QAAASI"]
[Thu Sep 17 15:07:36.351513 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:44118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4QAAASI"]
[Thu Sep 17 15:07:36.396211 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK5AAAAWE"]
[Thu Sep 17 15:07:36.446466 2026] [security2:error] [pid 955873:tid 956109] [client 45.169.98.18:58968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK5gAAAXQ"]
[Thu Sep 17 15:07:36.446578 2026] [security2:error] [pid 955873:tid 956109] [client 45.169.98.18:58968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK5gAAAXQ"]
[Thu Sep 17 15:07:36.454577 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK5wAAARY"]
[Thu Sep 17 15:07:36.456610 2026] [security2:error] [pid 955873:tid 956123] [client 103.99.250.210:59974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4wABgns"]
[Thu Sep 17 15:07:36.529293 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK6wAAASM"]
[Thu Sep 17 15:07:36.633418 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK8AAAAVw"]
[Thu Sep 17 15:07:36.666930 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK8gAAASc"]
[Thu Sep 17 15:07:36.667023 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:44124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK8gAAASc"]
[Thu Sep 17 15:07:36.715951 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK9gAAAXw"]
[Thu Sep 17 15:07:36.794998 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK_gAAAVc"]
[Thu Sep 17 15:07:36.853369 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoLAgAAAUc"]
[Thu Sep 17 15:07:36.915679 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoLBQAAAQ4"]
[Thu Sep 17 15:07:36.965558 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:44130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxWmBFTPRVSLOsRVhoLBwAAAXU"]
[Thu Sep 17 15:07:36.974441 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoLCAAAATo"]
[Thu Sep 17 15:07:37.022267 2026] [security2:error] [pid 955873:tid 956023] [client 34.166.228.3:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLCgAAAR4"]
[Thu Sep 17 15:07:37.032894 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLCwAAASQ"]
[Thu Sep 17 15:07:37.107427 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLDwAAAXs"]
[Thu Sep 17 15:07:37.133918 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxWmRFTPRVSLOsRVhoLEQAAAUM"]
[Thu Sep 17 15:07:37.213481 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLFgAAAXM"]
[Thu Sep 17 15:07:37.279437 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:44130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/wp-includes/sodium_compat/src/"] [unique_id "aqxWmRFTPRVSLOsRVhoLFwAAAUg"]
[Thu Sep 17 15:07:37.290974 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLGQAAAUY"]
[Thu Sep 17 15:07:37.405146 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLIgAAASA"]
[Thu Sep 17 15:07:37.490677 2026] [security2:error] [pid 955873:tid 956100] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLKAAAAWs"]
[Thu Sep 17 15:07:37.553018 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLKgAAAWM"]
[Thu Sep 17 15:07:37.620749 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLMQAAAXc"]
[Thu Sep 17 15:07:37.647986 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLIwAAASY"]
[Thu Sep 17 15:07:37.648016 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLIwAAASY"]
[Thu Sep 17 15:07:37.692858 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLNAAAARQ"]
[Thu Sep 17 15:07:37.710199 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.228.3:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLNgAAATM"]
[Thu Sep 17 15:07:37.792179 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLOgAAARE"]
[Thu Sep 17 15:07:37.792273 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:44130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLOgAAARE"]
[Thu Sep 17 15:07:37.824802 2026] [security2:error] [pid 955873:tid 956102] [client 2.139.26.243:53223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mtbclubdecampo.com"] [uri "/ruta.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLOQAAAW0"]
[Thu Sep 17 15:07:37.948915 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLQgAAARg"]
[Thu Sep 17 15:07:37.973413 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLRAAAARI"]
[Thu Sep 17 15:07:37.973499 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:52992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLRAAAARI"]
[Thu Sep 17 15:07:38.070558 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLRwAAAT4"]
[Thu Sep 17 15:07:38.070656 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:44134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLRwAAAT4"]
[Thu Sep 17 15:07:38.243214 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLTwAAAUE"]
[Thu Sep 17 15:07:38.373418 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLVwAAASQ"]
[Thu Sep 17 15:07:38.373539 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:44146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLVwAAASQ"]
[Thu Sep 17 15:07:38.432084 2026] [security2:error] [pid 955873:tid 956119] [client 34.166.228.3:55198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLWQAAAX4"]
[Thu Sep 17 15:07:38.531216 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.195.25:46108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLXQAAARc"]
[Thu Sep 17 15:07:38.669349 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLYgAAAUk"]
[Thu Sep 17 15:07:38.669469 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLYgAAAUk"]
[Thu Sep 17 15:07:38.771554 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:46114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLZQAAATA"]
[Thu Sep 17 15:07:38.847213 2026] [security2:error] [pid 955873:tid 956116] [client 154.190.208.131:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLaAAAAXs"]
[Thu Sep 17 15:07:38.847309 2026] [security2:error] [pid 955873:tid 956116] [client 154.190.208.131:42083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLaAAAAXs"]
[Thu Sep 17 15:07:38.965790 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:44156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxWmhFTPRVSLOsRVhoLawAAAWM"]
[Thu Sep 17 15:07:39.025093 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLbAAAAU0"]
[Thu Sep 17 15:07:39.142591 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxWmxFTPRVSLOsRVhoLcAAAAVk"]
[Thu Sep 17 15:07:39.287628 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:44156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/wp-includes/"] [unique_id "aqxWmxFTPRVSLOsRVhoLdgAAAVs"]
[Thu Sep 17 15:07:39.321013 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLeAAAAS0"]
[Thu Sep 17 15:07:39.604701 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.228.3:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWmxFTPRVSLOsRVhoLhwAAARg"]
[Thu Sep 17 15:07:39.638473 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLfAAAAXk"]
[Thu Sep 17 15:07:39.638498 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLfAAAAXk"]
[Thu Sep 17 15:07:39.715203 2026] [security2:error] [pid 955873:tid 956076] [client 5.189.145.112:60320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLjAAAAVM"], referer: binance.com
[Thu Sep 17 15:07:39.751825 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLjgAAARI"]
[Thu Sep 17 15:07:39.786087 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLkQAAAQw"]
[Thu Sep 17 15:07:39.786197 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:44156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLkQAAAQw"]
[Thu Sep 17 15:07:39.809671 2026] [security2:error] [pid 955873:tid 956123] [client 47.79.200.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLfQAAAYI"], referer: https://www.google.com/
[Thu Sep 17 15:07:39.865196 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:46146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLkwAAATs"]
[Thu Sep 17 15:07:39.920067 2026] [security2:error] [pid 955873:tid 956115] [client 4.240.114.86:62072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLlgAAAXo"], referer: binance.com
[Thu Sep 17 15:07:40.073440 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLngAAAVQ"]
[Thu Sep 17 15:07:40.073572 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLngAAAVQ"]
[Thu Sep 17 15:07:40.085091 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLnwAAAXU"]
[Thu Sep 17 15:07:40.293787 2026] [security2:error] [pid 955873:tid 956023] [client 34.166.228.3:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLpgAAAR4"]
[Thu Sep 17 15:07:40.367629 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLqAAAAWA"]
[Thu Sep 17 15:07:40.367742 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:40794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLqAAAAWA"]
[Thu Sep 17 15:07:40.381153 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLqgAAASo"]
[Thu Sep 17 15:07:40.645514 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:40802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLuQAAAWQ"]
[Thu Sep 17 15:07:40.645614 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:40802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLuQAAAWQ"]
[Thu Sep 17 15:07:40.654105 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLugAAAU0"]
[Thu Sep 17 15:07:40.858247 2026] [security2:error] [pid 955873:tid 956054] [client 104.207.47.59:24523] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWnBFTPRVSLOsRVhoLvwAAAT0"]
[Thu Sep 17 15:07:40.888531 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLwQAAAWI"]
[Thu Sep 17 15:07:40.982278 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.228.3:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLxAAAAV4"]
[Thu Sep 17 15:07:41.026158 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxWnRFTPRVSLOsRVhoLyAAAAWc"]
[Thu Sep 17 15:07:41.026278 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxWnRFTPRVSLOsRVhoLyAAAAWc"]
[Thu Sep 17 15:07:41.077515 2026] [security2:error] [pid 955873:tid 956061] [client 205.217.233.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLggAAAUQ"], referer: https://instagram.com/
[Thu Sep 17 15:07:41.163863 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoLzAAAARY"]
[Thu Sep 17 15:07:41.313510 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL0gAAAWk"]
[Thu Sep 17 15:07:41.313601 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:40812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL0gAAAWk"]
[Thu Sep 17 15:07:41.441476 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.195.25:53858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL1AAAAYY"]
[Thu Sep 17 15:07:41.599515 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:40816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxWnRFTPRVSLOsRVhoL2QAAAYk"]
[Thu Sep 17 15:07:41.645363 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:53868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL2gAAATk"]
[Thu Sep 17 15:07:41.672807 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.228.3:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL2wAAAQo"]
[Thu Sep 17 15:07:41.759640 2026] [authz_core:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/theme-compat/error_log
[Thu Sep 17 15:07:41.765869 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxWnRFTPRVSLOsRVhoL3wAAAXU"]
[Thu Sep 17 15:07:41.924162 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:40816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/wp-includes/"] [unique_id "aqxWnRFTPRVSLOsRVhoL5QAAAUM"]
[Thu Sep 17 15:07:42.053768 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL6AAAAUg"]
[Thu Sep 17 15:07:42.070021 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:55337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL6wAAASQ"]
[Thu Sep 17 15:07:42.071045 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:55337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL6wAAASQ"]
[Thu Sep 17 15:07:42.204059 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL9wAAATg"]
[Thu Sep 17 15:07:42.273013 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL7AAAAV8"]
[Thu Sep 17 15:07:42.273037 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL7AAAAV8"]
[Thu Sep 17 15:07:42.304818 2026] [security2:error] [pid 955873:tid 955926] [remote 216.73.217.142:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWnhFTPRVSLOsRVhoL-QABPDQ"]
[Thu Sep 17 15:07:42.371350 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.228.3:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL-wAAAW8"]
[Thu Sep 17 15:07:42.416995 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/comments.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL_AAAAWo"]
[Thu Sep 17 15:07:42.417099 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:40816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/comments.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL_AAAAWo"]
[Thu Sep 17 15:07:42.461923 2026] [security2:error] [pid 955873:tid 956105] [client 47.79.200.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL9QAAAXA"], referer: https://www.google.com/
[Thu Sep 17 15:07:42.468172 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.195.25:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL_gAAAYU"]
[Thu Sep 17 15:07:42.680856 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:53900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMAwAAAT0"]
[Thu Sep 17 15:07:42.709358 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:40824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-404.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMCAAAAXc"]
[Thu Sep 17 15:07:42.709481 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:40824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-404.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMCAAAAXc"]
[Thu Sep 17 15:07:42.890831 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMEAAAATI"]
[Thu Sep 17 15:07:43.058111 2026] [security2:error] [pid 955873:tid 956012] [client 34.166.228.3:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFAAAARM"]
[Thu Sep 17 15:07:43.062976 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-content.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFQAAATE"]
[Thu Sep 17 15:07:43.063069 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:40830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-content.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFQAAATE"]
[Thu Sep 17 15:07:43.211505 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:53926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFwAAAQw"]
[Thu Sep 17 15:07:43.281822 2026] [security2:error] [pid 955873:tid 956004] [client 44.239.144.77:50821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL1QAAAQs"], referer: http://worthtranslations.com/OLD
[Thu Sep 17 15:07:43.370540 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:40840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMHAAAAXo"]
[Thu Sep 17 15:07:43.370671 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:40840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMHAAAAXo"]
[Thu Sep 17 15:07:43.665263 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:40844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer-embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMJwAAAUM"]
[Thu Sep 17 15:07:43.665356 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:40844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer-embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMJwAAAUM"]
[Thu Sep 17 15:07:43.757230 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.228.3:42648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWnxFTPRVSLOsRVhoMKQAAAW4"]
[Thu Sep 17 15:07:43.892143 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:53940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMMgAAAVw"]
[Thu Sep 17 15:07:43.958803 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMNQAAAVk"]
[Thu Sep 17 15:07:43.958889 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:40854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMNQAAAVk"]
[Thu Sep 17 15:07:44.000960 2026] [security2:error] [pid 955873:tid 956068] [client 4.240.114.86:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMNgAAAUs"], referer: binance.com
[Thu Sep 17 15:07:44.076549 2026] [security2:error] [pid 955873:tid 956062] [client 104.207.47.59:55109] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWoBFTPRVSLOsRVhoMOQAAAUU"]
[Thu Sep 17 15:07:44.242744 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header-embed.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMQAAAAUk"]
[Thu Sep 17 15:07:44.242846 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header-embed.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMQAAAAUk"]
[Thu Sep 17 15:07:44.339211 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMQQAAAWQ"]
[Thu Sep 17 15:07:44.422544 2026] [access_compat:error] [pid 955873:tid 956091] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/alice-behind-the-mirror
[Thu Sep 17 15:07:44.439311 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.228.3:42652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWoBFTPRVSLOsRVhoMSwAAAWU"]
[Thu Sep 17 15:07:44.536231 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:40880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMUgAAAX0"]
[Thu Sep 17 15:07:44.536319 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:40880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMUgAAAX0"]
[Thu Sep 17 15:07:44.606019 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMUQAAARs"]
[Thu Sep 17 15:07:44.718625 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWoBFTPRVSLOsRVhoMWwAAAWk"]
[Thu Sep 17 15:07:44.821204 2026] [security2:error] [pid 955873:tid 956032] [client 185.55.149.49:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYQAAASc"]
[Thu Sep 17 15:07:44.821315 2026] [security2:error] [pid 955873:tid 956032] [client 185.55.149.49:57092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYQAAASc"]
[Thu Sep 17 15:07:44.826691 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:40886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/sidebar.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYgAAAQs"]
[Thu Sep 17 15:07:44.826781 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:40886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/sidebar.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYgAAAQs"]
[Thu Sep 17 15:07:44.941308 2026] [security2:error] [pid 955873:tid 956064] [client 24.163.167.215:42134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYAABR0Y"]
[Thu Sep 17 15:07:44.941788 2026] [security2:error] [pid 955873:tid 956011] [client 210.222.43.21:52971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMXQAAARI"], referer: http://talent-in-borders.com/demo
[Thu Sep 17 15:07:45.022043 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.195.25:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMZwAAAXo"]
[Thu Sep 17 15:07:45.103769 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMcwAAAT4"]
[Thu Sep 17 15:07:45.103859 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMcwAAAT4"]
[Thu Sep 17 15:07:45.126228 2026] [security2:error] [pid 955873:tid 956121] [client 34.166.228.3:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWoRFTPRVSLOsRVhoMdAAAAYA"]
[Thu Sep 17 15:07:45.342382 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.195.25:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMiQAAASg"]
[Thu Sep 17 15:07:45.389749 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMjQAAAU4"]
[Thu Sep 17 15:07:45.389843 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMjQAAAU4"]
[Thu Sep 17 15:07:45.595076 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMkQAAATg"]
[Thu Sep 17 15:07:45.693217 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMkwAAASU"]
[Thu Sep 17 15:07:45.693312 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:40916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMkwAAASU"]
[Thu Sep 17 15:07:45.810445 2026] [security2:error] [pid 955873:tid 956062] [client 34.166.228.3:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWoRFTPRVSLOsRVhoMmQAAAUU"]
[Thu Sep 17 15:07:45.815203 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMmgAAAXI"]
[Thu Sep 17 15:07:45.980456 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:40930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMoAAAAVs"]
[Thu Sep 17 15:07:45.980556 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:40930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMoAAAAVs"]
[Thu Sep 17 15:07:46.069368 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWohFTPRVSLOsRVhoMpQAAAS0"]
[Thu Sep 17 15:07:46.192295 2026] [security2:error] [pid 955873:tid 956088] [client 192.81.217.115:37842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMnwAAAV8"], referer: https://www.thevagabondhiker.com/
[Thu Sep 17 15:07:46.276889 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxWohFTPRVSLOsRVhoMsQAAARY"]
[Thu Sep 17 15:07:46.276995 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:40946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxWohFTPRVSLOsRVhoMsQAAARY"]
[Thu Sep 17 15:07:46.291881 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.195.25:53984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWohFTPRVSLOsRVhoMsgAAAVM"]
[Thu Sep 17 15:07:46.303463 2026] [security2:error] [pid 955873:tid 956104] [client 24.163.167.215:42135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWohFTPRVSLOsRVhoMqwABbyc"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726062022&hideanons=1&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:07:46.491421 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.228.3:42686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWohFTPRVSLOsRVhoMuwAAARg"]
[Thu Sep 17 15:07:46.521318 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWohFTPRVSLOsRVhoMvAAAAXg"]
[Thu Sep 17 15:07:46.574874 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:40956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxWohFTPRVSLOsRVhoMvQAAARo"]
[Thu Sep 17 15:07:46.748353 2026] [authz_core:error] [pid 955873:tid 956022] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/widgets/error_log
[Thu Sep 17 15:07:46.751936 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxWohFTPRVSLOsRVhoMwgAAAR0"]
[Thu Sep 17 15:07:46.762100 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:54012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWohFTPRVSLOsRVhoMwwAAAT4"]
[Thu Sep 17 15:07:46.842515 2026] [security2:error] [pid 955873:tid 956075] [client 57.141.14.31:27414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWohFTPRVSLOsRVhoMwQABUj4"]
[Thu Sep 17 15:07:46.900316 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:40956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/wp-includes/"] [unique_id "aqxWohFTPRVSLOsRVhoMzAAAAXM"]
[Thu Sep 17 15:07:46.904786 2026] [security2:error] [pid 955873:tid 956034] [client 45.169.98.18:59529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWohFTPRVSLOsRVhoMzQAAASk"]
[Thu Sep 17 15:07:46.904872 2026] [security2:error] [pid 955873:tid 956034] [client 45.169.98.18:59529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWohFTPRVSLOsRVhoMzQAAASk"]
[Thu Sep 17 15:07:47.012527 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWoxFTPRVSLOsRVhoM0AAAAV0"]
[Thu Sep 17 15:07:47.187142 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.228.3:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM2gAAAU4"]
[Thu Sep 17 15:07:47.262312 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWoxFTPRVSLOsRVhoM2wAAAXs"]
[Thu Sep 17 15:07:47.344092 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM0wAAAVU"]
[Thu Sep 17 15:07:47.344114 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM0wAAAVU"]
[Thu Sep 17 15:07:47.485298 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-nav-menu-widget.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM6wAAAUI"]
[Thu Sep 17 15:07:47.485407 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:40956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-nav-menu-widget.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM6wAAAUI"]
[Thu Sep 17 15:07:47.526460 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:54038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM7AAAAUQ"]
[Thu Sep 17 15:07:47.760761 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:40972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-archives.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM-wAAAYk"]
[Thu Sep 17 15:07:47.760889 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:40972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-archives.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM-wAAAYk"]
[Thu Sep 17 15:07:47.787238 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.195.25:54050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM_gAAAUc"]
[Thu Sep 17 15:07:47.883933 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.228.3:42700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoNBAAAAQs"]
[Thu Sep 17 15:07:47.948699 2026] [security2:error] [pid 955873:tid 956113] [client 162.241.226.11:10908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM-AAAAXg"]
[Thu Sep 17 15:07:48.061468 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNCgAAAT4"]
[Thu Sep 17 15:07:48.061602 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNCgAAAT4"]
[Thu Sep 17 15:07:48.086110 2026] [security2:error] [pid 955873:tid 956052] [client 104.207.47.59:49135] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWpBFTPRVSLOsRVhoNDAAAATs"]
[Thu Sep 17 15:07:48.109681 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNDgAAAR0"]
[Thu Sep 17 15:07:48.201224 2026] [security2:error] [pid 955873:tid 956048] [client 162.241.226.11:10918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNCQAAATc"]
[Thu Sep 17 15:07:48.339640 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-calendar.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNFwAAAS8"]
[Thu Sep 17 15:07:48.339785 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-calendar.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNFwAAAS8"]
[Thu Sep 17 15:07:48.360880 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNGgAAAV0"]
[Thu Sep 17 15:07:48.394690 2026] [security2:error] [pid 955873:tid 956089] [client 185.104.184.228:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.184.104.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNGwAAAWA"]
[Thu Sep 17 15:07:48.394791 2026] [security2:error] [pid 955873:tid 956089] [client 185.104.184.228:54802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNGwAAAWA"]
[Thu Sep 17 15:07:48.589294 2026] [security2:error] [pid 955873:tid 956124] [client 34.166.228.3:42710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIAAAAYM"]
[Thu Sep 17 15:07:48.593381 2026] [security2:error] [pid 955873:tid 956065] [client 115.244.164.14:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIQAAAUg"]
[Thu Sep 17 15:07:48.593453 2026] [security2:error] [pid 955873:tid 956065] [client 115.244.164.14:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIQAAAUg"]
[Thu Sep 17 15:07:48.623437 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.195.25:54062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIwAAATw"]
[Thu Sep 17 15:07:48.628180 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:40988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-categories.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNJAAAAXs"]
[Thu Sep 17 15:07:48.628266 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:40988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-categories.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNJAAAAXs"]
[Thu Sep 17 15:07:48.642847 2026] [security2:error] [pid 955873:tid 956118] [client 200.8.108.97:48402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNHAAAAX0"], referer: https://www.thevagabondhiker.com/
[Thu Sep 17 15:07:48.890643 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNLAAAAQ0"]
[Thu Sep 17 15:07:48.915534 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:41004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-custom-html.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNMAAAAWU"]
[Thu Sep 17 15:07:48.915624 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:41004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-custom-html.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNMAAAAWU"]
[Thu Sep 17 15:07:49.020784 2026] [security2:error] [pid 955873:tid 956119] [client 4.240.114.86:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNNAAAAX4"], referer: binance.com
[Thu Sep 17 15:07:49.126492 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNOgAAAUQ"]
[Thu Sep 17 15:07:49.201508 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:41014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-links.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNPAAAAWg"]
[Thu Sep 17 15:07:49.201587 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:41014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-links.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNPAAAAWg"]
[Thu Sep 17 15:07:49.291188 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.228.3:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNPwAAASI"]
[Thu Sep 17 15:07:49.318997 2026] [security2:error] [pid 955873:tid 956045] [client 154.190.208.131:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNQAAAATQ"]
[Thu Sep 17 15:07:49.323675 2026] [security2:error] [pid 955873:tid 956045] [client 154.190.208.131:41320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNQAAAATQ"]
[Thu Sep 17 15:07:49.410873 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:54086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNRAAAARE"]
[Thu Sep 17 15:07:49.498229 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:41018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-audio.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNSAAAAXg"]
[Thu Sep 17 15:07:49.498309 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:41018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-audio.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNSAAAAXg"]
[Thu Sep 17 15:07:49.700602 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNUgAAATU"]
[Thu Sep 17 15:07:49.780936 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:41030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-gallery.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNVAAAAS4"]
[Thu Sep 17 15:07:49.781026 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:41030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-gallery.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNVAAAAS4"]
[Thu Sep 17 15:07:49.906124 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.195.25:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNWAAAAVI"]
[Thu Sep 17 15:07:49.974484 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.228.3:42730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNWgAAATE"]
[Thu Sep 17 15:07:50.057801 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-image.php"] [unique_id "aqxWphFTPRVSLOsRVhoNXwAAAXE"]
[Thu Sep 17 15:07:50.057904 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:35508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-image.php"] [unique_id "aqxWphFTPRVSLOsRVhoNXwAAAXE"]
[Thu Sep 17 15:07:50.060083 2026] [security2:error] [pid 955873:tid 956023] [client 47.79.206.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNTwAAAR4"], referer: https://www.google.com/
[Thu Sep 17 15:07:50.209652 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.195.25:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNZQAAAWA"]
[Thu Sep 17 15:07:50.214979 2026] [authz_core:error] [pid 955873:tid 956099] [client 20.244.34.24:60285] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:07:50.363053 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-video.php"] [unique_id "aqxWphFTPRVSLOsRVhoNagAAAVQ"]
[Thu Sep 17 15:07:50.363174 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:35518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-video.php"] [unique_id "aqxWphFTPRVSLOsRVhoNagAAAVQ"]
[Thu Sep 17 15:07:50.502530 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.195.25:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNbgAAARw"]
[Thu Sep 17 15:07:50.667327 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.228.3:42734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNcwAAAX0"]
[Thu Sep 17 15:07:50.678800 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media.php"] [unique_id "aqxWphFTPRVSLOsRVhoNdAAAAWU"]
[Thu Sep 17 15:07:50.678892 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:35520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media.php"] [unique_id "aqxWphFTPRVSLOsRVhoNdAAAAWU"]
[Thu Sep 17 15:07:50.805084 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNegAAATI"]
[Thu Sep 17 15:07:50.971285 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-meta.php"] [unique_id "aqxWphFTPRVSLOsRVhoNfwAAASM"]
[Thu Sep 17 15:07:50.971377 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:35528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-meta.php"] [unique_id "aqxWphFTPRVSLOsRVhoNfwAAASM"]
[Thu Sep 17 15:07:51.049929 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNggAAAS0"]
[Thu Sep 17 15:07:51.261918 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-pages.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNiAAAAXY"]
[Thu Sep 17 15:07:51.262018 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-pages.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNiAAAAXY"]
[Thu Sep 17 15:07:51.353792 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.228.3:42740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNiwAAAW8"]
[Thu Sep 17 15:07:51.520666 2026] [security2:error] [pid 955873:tid 956112] [client 104.207.47.59:11721] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWpxFTPRVSLOsRVhoNkAAAAXc"]
[Thu Sep 17 15:07:51.549720 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-comments.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNkwAAAYg"]
[Thu Sep 17 15:07:51.549821 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-comments.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNkwAAAYg"]
[Thu Sep 17 15:07:51.826493 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-posts.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNogAAAYk"]
[Thu Sep 17 15:07:51.826575 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-posts.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNogAAAYk"]
[Thu Sep 17 15:07:52.052041 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.228.3:42746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNqwAAATE"]
[Thu Sep 17 15:07:52.103742 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-rss.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNsQAAAWo"]
[Thu Sep 17 15:07:52.103829 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:35580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-rss.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNsQAAAWo"]
[Thu Sep 17 15:07:52.387450 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-search.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNvgAAARw"]
[Thu Sep 17 15:07:52.387621 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:35584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-search.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNvgAAARw"]
[Thu Sep 17 15:07:52.675288 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-tag-cloud.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNzQAAARk"]
[Thu Sep 17 15:07:52.675377 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-tag-cloud.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNzQAAARk"]
[Thu Sep 17 15:07:52.737277 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.228.3:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN0QAAARg"]
[Thu Sep 17 15:07:52.979309 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:35598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-text.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1QAAAXk"]
[Thu Sep 17 15:07:52.979407 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:35598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-text.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1QAAAXk"]
[Thu Sep 17 15:07:52.988450 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1wAAAVU"]
[Thu Sep 17 15:07:52.989632 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:55986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1wAAAVU"]
[Thu Sep 17 15:07:53.268470 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/"] [unique_id "aqxWqRFTPRVSLOsRVhoN4AAAAUM"]
[Thu Sep 17 15:07:53.367777 2026] [security2:error] [pid 955873:tid 955892] [remote 57.141.14.91:47582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "timalba.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN4gABDhI"], referer: https://timalba.com/?i=88029249987600
[Thu Sep 17 15:07:53.431190 2026] [security2:error] [pid 955873:tid 956085] [client 34.166.228.3:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN5gAAAVw"]
[Thu Sep 17 15:07:53.520388 2026] [security2:error] [pid 955873:tid 956011] [client 104.28.198.244:22539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN6QAAARI"]
[Thu Sep 17 15:07:53.520527 2026] [security2:error] [pid 955873:tid 956011] [client 104.28.198.244:22539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN6QAAARI"]
[Thu Sep 17 15:07:53.658797 2026] [security2:error] [pid 955873:tid 956123] [client 4.240.114.86:53239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN6wAAAYI"], referer: binance.com
[Thu Sep 17 15:07:53.763918 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/"] [unique_id "aqxWqRFTPRVSLOsRVhoN7AAAAWw"]
[Thu Sep 17 15:07:53.904165 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/"] [unique_id "aqxWqRFTPRVSLOsRVhoN8wAAAYY"]
[Thu Sep 17 15:07:54.139408 2026] [security2:error] [pid 955873:tid 956016] [client 34.166.228.3:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWqhFTPRVSLOsRVhoN-QAAARc"]
[Thu Sep 17 15:07:54.175453 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/"] [unique_id "aqxWqhFTPRVSLOsRVhoN9wAAAQo"]
[Thu Sep 17 15:07:54.318957 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/wp-includes/css/"] [unique_id "aqxWqhFTPRVSLOsRVhoN_wAAAVg"]
[Thu Sep 17 15:07:54.532532 2026] [security2:error] [pid 955873:tid 956088] [client 104.207.47.59:46981] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWqhFTPRVSLOsRVhoOBQAAAV8"]
[Thu Sep 17 15:07:54.675122 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqhFTPRVSLOsRVhoOAAAAAWA"]
[Thu Sep 17 15:07:54.675147 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqhFTPRVSLOsRVhoOAAAAAWA"]
[Thu Sep 17 15:07:54.852093 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.228.3:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWqhFTPRVSLOsRVhoOFAAAARA"]
[Thu Sep 17 15:07:54.954697 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/base-styles/"] [unique_id "aqxWqhFTPRVSLOsRVhoOGAAAAWk"]
[Thu Sep 17 15:07:55.111218 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/base-styles/"] [unique_id "aqxWqxFTPRVSLOsRVhoOGgAAAXo"]
[Thu Sep 17 15:07:55.170426 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOIgAAATA"]
[Thu Sep 17 15:07:55.257698 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/base-styles/wp-includes/css/dist/"] [unique_id "aqxWqxFTPRVSLOsRVhoOJwAAAW8"]
[Thu Sep 17 15:07:55.521748 2026] [security2:error] [pid 955873:tid 956067] [client 57.141.14.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "timalba.com"] [uri "/index.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOJQAAAUo"], referer: https://timalba.com/?i=88029249987600
[Thu Sep 17 15:07:55.529567 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.228.3:55210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOMAAAASI"]
[Thu Sep 17 15:07:55.531692 2026] [security2:error] [pid 955873:tid 956076] [client 185.55.149.49:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOMQAAAVM"]
[Thu Sep 17 15:07:55.531790 2026] [security2:error] [pid 955873:tid 956076] [client 185.55.149.49:50062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOMQAAAVM"]
[Thu Sep 17 15:07:55.587522 2026] [security2:error] [pid 955873:tid 956024] [client 4.240.114.86:52349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.paltals.com"] [uri "/index.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNuwAAAR8"], referer: binance.com
[Thu Sep 17 15:07:55.672715 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOKgAAAX8"]
[Thu Sep 17 15:07:55.672739 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOKgAAAX8"]
[Thu Sep 17 15:07:55.820460 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-directory/"] [unique_id "aqxWqxFTPRVSLOsRVhoOPAAAAVY"]
[Thu Sep 17 15:07:55.978575 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-directory/"] [unique_id "aqxWqxFTPRVSLOsRVhoOQAAAAUY"]
[Thu Sep 17 15:07:56.121583 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-directory/wp-includes/css/dist/"] [unique_id "aqxWrBFTPRVSLOsRVhoORQAAAVk"]
[Thu Sep 17 15:07:56.205696 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.228.3:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOSwAAAT4"]
[Thu Sep 17 15:07:56.457165 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOUQAAAR0"]
[Thu Sep 17 15:07:56.457187 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOUQAAAR0"]
[Thu Sep 17 15:07:56.598078 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-editor/"] [unique_id "aqxWrBFTPRVSLOsRVhoOWQAAAWU"]
[Thu Sep 17 15:07:56.641151 2026] [security2:error] [pid 955873:tid 956017] [client 192.178.6.3:46297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOXAAAARg"]
[Thu Sep 17 15:07:56.770913 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-editor/"] [unique_id "aqxWrBFTPRVSLOsRVhoOYwAAAWI"]
[Thu Sep 17 15:07:56.920265 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-editor/wp-includes/css/dist/"] [unique_id "aqxWrBFTPRVSLOsRVhoOaQAAAWg"]
[Thu Sep 17 15:07:57.094966 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOcAAAAVc"]
[Thu Sep 17 15:07:57.185111 2026] [security2:error] [pid 955873:tid 956111] [client 104.238.222.26:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centerforfederaljusticereform.org"] [uri "/wp-login.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOdgAAAXY"]
[Thu Sep 17 15:07:57.258006 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoObwAAAUM"]
[Thu Sep 17 15:07:57.258035 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoObwAAAUM"]
[Thu Sep 17 15:07:57.378806 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:60077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOggAAAQw"]
[Thu Sep 17 15:07:57.378942 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:60077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOggAAAQw"]
[Thu Sep 17 15:07:57.402150 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "aqxWrRFTPRVSLOsRVhoOhgAAAYk"]
[Thu Sep 17 15:07:57.421546 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOiAAAAR8"]
[Thu Sep 17 15:07:57.576003 2026] [security2:error] [pid 955873:tid 956014] [client 104.207.47.59:65213] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWrRFTPRVSLOsRVhoOkAAAARU"]
[Thu Sep 17 15:07:57.579172 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "aqxWrRFTPRVSLOsRVhoOjgAAAU8"]
[Thu Sep 17 15:07:57.588439 2026] [security2:error] [pid 955873:tid 956121] [client 4.240.114.86:55460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOkQAAAYA"], referer: binance.com
[Thu Sep 17 15:07:57.708613 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:54930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOoQAAATg"]
[Thu Sep 17 15:07:57.721399 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-library/wp-includes/css/dist/"] [unique_id "aqxWrRFTPRVSLOsRVhoOogAAAV8"]
[Thu Sep 17 15:07:58.062301 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOpgAAATI"]
[Thu Sep 17 15:07:58.062322 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOpgAAATI"]
[Thu Sep 17 15:07:58.113619 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.224.217:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWrhFTPRVSLOsRVhoOrgAAARw"]
[Thu Sep 17 15:07:58.204946 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/commands/"] [unique_id "aqxWrhFTPRVSLOsRVhoOswAAAYU"]
[Thu Sep 17 15:07:58.358409 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/commands/"] [unique_id "aqxWrhFTPRVSLOsRVhoOuAAAAWc"]
[Thu Sep 17 15:07:58.499411 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/commands/wp-includes/css/dist/"] [unique_id "aqxWrhFTPRVSLOsRVhoOvQAAAXw"]
[Thu Sep 17 15:07:58.816547 2026] [security2:error] [pid 955873:tid 956111] [client 179.125.154.246:40555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWrhFTPRVSLOsRVhoOyQABdhk"]
[Thu Sep 17 15:07:59.063647 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrhFTPRVSLOsRVhoO0QAAAVM"]
[Thu Sep 17 15:07:59.063688 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrhFTPRVSLOsRVhoO0QAAAVM"]
[Thu Sep 17 15:07:59.233509 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/components/"] [unique_id "aqxWrxFTPRVSLOsRVhoO6QAAAXg"]
[Thu Sep 17 15:07:59.348836 2026] [security2:error] [pid 955873:tid 956129] [client 115.244.164.14:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO7gAAAYg"]
[Thu Sep 17 15:07:59.348910 2026] [security2:error] [pid 955873:tid 956129] [client 115.244.164.14:54280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO7gAAAYg"]
[Thu Sep 17 15:07:59.392543 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/components/"] [unique_id "aqxWrxFTPRVSLOsRVhoO8AAAASQ"]
[Thu Sep 17 15:07:59.533785 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/components/wp-includes/css/dist/"] [unique_id "aqxWrxFTPRVSLOsRVhoO9wAAAV8"]
[Thu Sep 17 15:07:59.802182 2026] [security2:error] [pid 955873:tid 956040] [client 154.190.208.131:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoPAwAAAS8"]
[Thu Sep 17 15:07:59.805052 2026] [security2:error] [pid 955873:tid 956040] [client 154.190.208.131:41908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoPAwAAAS8"]
[Thu Sep 17 15:07:59.861610 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO_wAAASA"]
[Thu Sep 17 15:07:59.861630 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO_wAAASA"]
[Thu Sep 17 15:08:00.022476 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/customize-widgets/"] [unique_id "aqxWsBFTPRVSLOsRVhoPCwAAATI"]
[Thu Sep 17 15:08:00.180627 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/customize-widgets/"] [unique_id "aqxWsBFTPRVSLOsRVhoPEQAAAQ0"]
[Thu Sep 17 15:08:00.330569 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/customize-widgets/wp-includes/css/dist/"] [unique_id "aqxWsBFTPRVSLOsRVhoPGAAAARA"]
[Thu Sep 17 15:08:00.674553 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsBFTPRVSLOsRVhoPIAAAAW4"]
[Thu Sep 17 15:08:00.674574 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsBFTPRVSLOsRVhoPIAAAAW4"]
[Thu Sep 17 15:08:00.780930 2026] [security2:error] [pid 955873:tid 956115] [client 104.207.47.59:53203] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWsBFTPRVSLOsRVhoPLQAAAXo"]
[Thu Sep 17 15:08:00.825864 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "aqxWsBFTPRVSLOsRVhoPLgAAASg"]
[Thu Sep 17 15:08:00.928346 2026] [security2:error] [pid 955873:tid 956106] [client 34.94.67.131:55458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWsBFTPRVSLOsRVhoPMwAAAXE"]
[Thu Sep 17 15:08:00.985929 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "aqxWsBFTPRVSLOsRVhoPNAAAAXg"]
[Thu Sep 17 15:08:01.128145 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-post/wp-includes/css/dist/"] [unique_id "aqxWsRFTPRVSLOsRVhoPNwAAARc"]
[Thu Sep 17 15:08:01.290587 2026] [security2:error] [pid 955873:tid 956082] [client 34.94.67.131:38740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPQQAAAVk"]
[Thu Sep 17 15:08:01.371628 2026] [security2:error] [pid 955873:tid 956077] [client 177.100.7.127:48418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPPgABVBM"]
[Thu Sep 17 15:08:01.537376 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPPwAAAUg"]
[Thu Sep 17 15:08:01.537403 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPPwAAAUg"]
[Thu Sep 17 15:08:01.678732 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-site/"] [unique_id "aqxWsRFTPRVSLOsRVhoPRgAAAUs"]
[Thu Sep 17 15:08:01.733108 2026] [security2:error] [pid 955873:tid 956049] [client 34.94.67.131:38742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPSwAAATg"]
[Thu Sep 17 15:08:01.846504 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-site/"] [unique_id "aqxWsRFTPRVSLOsRVhoPTgAAAUk"]
[Thu Sep 17 15:08:01.865271 2026] [security2:error] [pid 955873:tid 956022] [client 145.239.10.137:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxshee.com"] [uri "/wsunch.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPTwAAAR0"], referer: http://foxshee.com/wsunch.php
[Thu Sep 17 15:08:01.987133 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-site/wp-includes/css/dist/"] [unique_id "aqxWsRFTPRVSLOsRVhoPUgAAASA"]
[Thu Sep 17 15:08:02.091098 2026] [security2:error] [pid 955873:tid 956017] [client 4.240.114.86:57867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxWshFTPRVSLOsRVhoPVQAAARg"], referer: binance.com
[Thu Sep 17 15:08:02.244216 2026] [security2:error] [pid 955873:tid 956098] [client 34.94.67.131:38748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWshFTPRVSLOsRVhoPXQAAAWk"]
[Thu Sep 17 15:08:02.355440 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPVgAAARw"]
[Thu Sep 17 15:08:02.355464 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPVgAAARw"]
[Thu Sep 17 15:08:02.520004 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-widgets/"] [unique_id "aqxWshFTPRVSLOsRVhoPZAAAAU0"]
[Thu Sep 17 15:08:02.677977 2026] [security2:error] [pid 955873:tid 956052] [client 34.94.67.131:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWshFTPRVSLOsRVhoPbgAAATs"]
[Thu Sep 17 15:08:02.678549 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-widgets/"] [unique_id "aqxWshFTPRVSLOsRVhoPbAAAARY"]
[Thu Sep 17 15:08:02.821585 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-widgets/wp-includes/css/dist/"] [unique_id "aqxWshFTPRVSLOsRVhoPdgAAAXY"]
[Thu Sep 17 15:08:03.162801 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPeAAAAR8"]
[Thu Sep 17 15:08:03.162824 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPeAAAAR8"]
[Thu Sep 17 15:08:03.220190 2026] [security2:error] [pid 955873:tid 956100] [client 34.94.67.131:38758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPggAAAWs"]
[Thu Sep 17 15:08:03.303967 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/editor/"] [unique_id "aqxWsxFTPRVSLOsRVhoPhQAAAYE"]
[Thu Sep 17 15:08:03.457893 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/editor/"] [unique_id "aqxWsxFTPRVSLOsRVhoPigAAAUU"]
[Thu Sep 17 15:08:03.557774 2026] [security2:error] [pid 955873:tid 956071] [client 34.94.67.131:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPjQAAAU4"]
[Thu Sep 17 15:08:03.598731 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/editor/wp-includes/css/dist/"] [unique_id "aqxWsxFTPRVSLOsRVhoPkAAAATg"]
[Thu Sep 17 15:08:03.793903 2026] [security2:error] [pid 955873:tid 956116] [client 104.207.47.59:54493] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWsxFTPRVSLOsRVhoPmQAAAXs"]
[Thu Sep 17 15:08:03.817011 2026] [security2:error] [pid 955873:tid 956089] [client 34.94.67.131:38770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPmgAAAWA"]
[Thu Sep 17 15:08:03.932883 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPlwAAAVI"]
[Thu Sep 17 15:08:03.932906 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPlwAAAVI"]
[Thu Sep 17 15:08:04.069540 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:56587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPngAAAWU"]
[Thu Sep 17 15:08:04.069646 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:56587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPngAAAWU"]
[Thu Sep 17 15:08:04.073441 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/format-library/"] [unique_id "aqxWtBFTPRVSLOsRVhoPoAAAATI"]
[Thu Sep 17 15:08:04.239182 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/format-library/"] [unique_id "aqxWtBFTPRVSLOsRVhoPpgAAARA"]
[Thu Sep 17 15:08:04.380033 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/format-library/wp-includes/css/dist/"] [unique_id "aqxWtBFTPRVSLOsRVhoPqgAAAU0"]
[Thu Sep 17 15:08:04.724655 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPrAAAAVo"]
[Thu Sep 17 15:08:04.724690 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPrAAAAVo"]
[Thu Sep 17 15:08:04.865804 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/list-reusable-blocks/"] [unique_id "aqxWtBFTPRVSLOsRVhoPuAAAAXo"]
[Thu Sep 17 15:08:04.980056 2026] [security2:error] [pid 955873:tid 956085] [client 34.94.67.131:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPugAAAVw"]
[Thu Sep 17 15:08:05.019914 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/list-reusable-blocks/"] [unique_id "aqxWtRFTPRVSLOsRVhoPvAAAAQ4"]
[Thu Sep 17 15:08:05.168468 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/list-reusable-blocks/wp-includes/css/dist/"] [unique_id "aqxWtRFTPRVSLOsRVhoPwAAAAUQ"]
[Thu Sep 17 15:08:05.284914 2026] [security2:error] [pid 955873:tid 956103] [client 34.94.67.131:38794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWtRFTPRVSLOsRVhoPxAAAAW4"]
[Thu Sep 17 15:08:05.518230 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtRFTPRVSLOsRVhoPxQAAARU"]
[Thu Sep 17 15:08:05.518259 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtRFTPRVSLOsRVhoPxQAAARU"]
[Thu Sep 17 15:08:05.664251 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/media-utils/"] [unique_id "aqxWtRFTPRVSLOsRVhoPzAAAAVM"]
[Thu Sep 17 15:08:05.724623 2026] [security2:error] [pid 955873:tid 956064] [client 4.240.114.86:59728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxWtRFTPRVSLOsRVhoP0AAAAUc"], referer: binance.com
[Thu Sep 17 15:08:05.790464 2026] [security2:error] [pid 955873:tid 956023] [client 34.94.67.131:38802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWtRFTPRVSLOsRVhoP1AAAAR4"]
[Thu Sep 17 15:08:05.828419 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/media-utils/"] [unique_id "aqxWtRFTPRVSLOsRVhoP1QAAAQ8"]
[Thu Sep 17 15:08:05.968798 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/media-utils/wp-includes/css/dist/"] [unique_id "aqxWtRFTPRVSLOsRVhoP1wAAAUo"]
[Thu Sep 17 15:08:06.182273 2026] [security2:error] [pid 955873:tid 956051] [client 185.55.149.49:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP4AAAATo"]
[Thu Sep 17 15:08:06.182415 2026] [security2:error] [pid 955873:tid 956051] [client 185.55.149.49:50670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP4AAAATo"]
[Thu Sep 17 15:08:06.220939 2026] [security2:error] [pid 955873:tid 956109] [client 34.94.67.131:38806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWthFTPRVSLOsRVhoP5QAAAXQ"]
[Thu Sep 17 15:08:06.314354 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP3QAAAR0"]
[Thu Sep 17 15:08:06.314375 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP3QAAAR0"]
[Thu Sep 17 15:08:06.454426 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/notices/"] [unique_id "aqxWthFTPRVSLOsRVhoP6gAAAX4"]
[Thu Sep 17 15:08:06.600218 2026] [security2:error] [pid 955873:tid 956021] [client 34.94.67.131:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWthFTPRVSLOsRVhoP7gAAARw"]
[Thu Sep 17 15:08:06.609444 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/notices/"] [unique_id "aqxWthFTPRVSLOsRVhoP7QAAARs"]
[Thu Sep 17 15:08:06.754303 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/notices/wp-includes/css/dist/"] [unique_id "aqxWthFTPRVSLOsRVhoP9wAAASM"]
[Thu Sep 17 15:08:06.771617 2026] [security2:error] [pid 955873:tid 956006] [client 104.207.47.59:13915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/wp-ticket/readme.txt"] [unique_id "aqxWthFTPRVSLOsRVhoP-AAAAQ0"]
[Thu Sep 17 15:08:06.792567 2026] [security2:error] [pid 955873:tid 956124] [client 104.28.198.244:22877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP-QAAAYM"]
[Thu Sep 17 15:08:06.973351 2026] [security2:error] [pid 955873:tid 956124] [client 104.28.198.244:22877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP-QAAAYM"]
[Thu Sep 17 15:08:07.082788 2026] [security2:error] [pid 955873:tid 956007] [client 34.94.67.131:38832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQCQAAAQ4"]
[Thu Sep 17 15:08:07.104999 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP_QAAASg"]
[Thu Sep 17 15:08:07.105021 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP_QAAASg"]
[Thu Sep 17 15:08:07.245841 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/nux/"] [unique_id "aqxWtxFTPRVSLOsRVhoQDwAAAVY"]
[Thu Sep 17 15:08:07.275696 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env"] [unique_id "aqxWtxFTPRVSLOsRVhoQEQAAAV4"]
[Thu Sep 17 15:08:07.399742 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/nux/"] [unique_id "aqxWtxFTPRVSLOsRVhoQFgAAAWQ"]
[Thu Sep 17 15:08:07.448440 2026] [security2:error] [pid 955873:tid 956016] [client 34.94.67.131:38840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQGQAAARc"]
[Thu Sep 17 15:08:07.540436 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/nux/wp-includes/css/dist/"] [unique_id "aqxWtxFTPRVSLOsRVhoQHQAAAQ8"]
[Thu Sep 17 15:08:07.804109 2026] [security2:error] [pid 955873:tid 956113] [client 45.76.255.99:60918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQJAABeEs"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:08:07.864880 2026] [security2:error] [pid 955873:tid 956035] [client 45.169.98.18:60636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQLQAAASo"]
[Thu Sep 17 15:08:07.865003 2026] [security2:error] [pid 955873:tid 956035] [client 45.169.98.18:60636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQLQAAASo"]
[Thu Sep 17 15:08:07.866671 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWtxFTPRVSLOsRVhoQLAAAAUk"]
[Thu Sep 17 15:08:07.873628 2026] [security2:error] [pid 955873:tid 956032] [client 78.47.98.55:48074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQJwAAASc"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:08:07.892542 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQIwAAAU4"]
[Thu Sep 17 15:08:07.892567 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQIwAAAU4"]
[Thu Sep 17 15:08:07.936483 2026] [security2:error] [pid 955873:tid 956109] [client 34.94.67.131:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQMAAAAXQ"]
[Thu Sep 17 15:08:07.937693 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWtxFTPRVSLOsRVhoQLwAAASA"]
[Thu Sep 17 15:08:08.034583 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/patterns/"] [unique_id "aqxWuBFTPRVSLOsRVhoQMwAAAWo"]
[Thu Sep 17 15:08:08.063009 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWuBFTPRVSLOsRVhoQNQAAAT0"]
[Thu Sep 17 15:08:08.106505 2026] [security2:error] [pid 955873:tid 956119] [client 34.94.67.131:38854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQNwAAAX4"]
[Thu Sep 17 15:08:08.153193 2026] [security2:error] [pid 955873:tid 956125] [client 45.76.255.99:60924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQNgABhEo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821171306&hideliu=1&hidemyself=1&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:08.193199 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/patterns/"] [unique_id "aqxWuBFTPRVSLOsRVhoQPAAAAWg"]
[Thu Sep 17 15:08:08.334374 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/patterns/wp-includes/css/dist/"] [unique_id "aqxWuBFTPRVSLOsRVhoQQQAAAVo"]
[Thu Sep 17 15:08:08.452272 2026] [security2:error] [pid 955873:tid 956078] [client 34.94.67.131:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQSAAAAVU"]
[Thu Sep 17 15:08:08.508790 2026] [security2:error] [pid 955873:tid 956017] [client 78.47.98.55:48076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQQgAAARg"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:08:08.692784 2026] [security2:error] [pid 955873:tid 956124] [client 34.94.67.131:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQUwAAAYM"]
[Thu Sep 17 15:08:08.711899 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQSQAAAUM"]
[Thu Sep 17 15:08:08.711926 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQSQAAAUM"]
[Thu Sep 17 15:08:08.857863 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/preferences/"] [unique_id "aqxWuBFTPRVSLOsRVhoQVwAAAVY"]
[Thu Sep 17 15:08:08.989179 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWuBFTPRVSLOsRVhoQWwAAAYI"]
[Thu Sep 17 15:08:09.018650 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/preferences/"] [unique_id "aqxWuBFTPRVSLOsRVhoQXQAAAWQ"]
[Thu Sep 17 15:08:09.049609 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWuRFTPRVSLOsRVhoQXgAAAUE"]
[Thu Sep 17 15:08:09.084222 2026] [security2:error] [pid 955873:tid 956112] [client 68.55.134.110:41523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQWgABd1g"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:08:09.110097 2026] [security2:error] [pid 955873:tid 956003] [client 34.94.67.131:38888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQYAAAAQo"]
[Thu Sep 17 15:08:09.158846 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/preferences/wp-includes/css/dist/"] [unique_id "aqxWuRFTPRVSLOsRVhoQYgAAAT8"]
[Thu Sep 17 15:08:09.433039 2026] [security2:error] [pid 955873:tid 956130] [client 4.240.114.86:61306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.paltals.com"] [uri "/index.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQaQAAAYk"], referer: binance.com
[Thu Sep 17 15:08:09.523568 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQagAAAS4"]
[Thu Sep 17 15:08:09.523596 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQagAAAS4"]
[Thu Sep 17 15:08:09.541847 2026] [security2:error] [pid 955873:tid 956067] [client 34.94.67.131:38890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQcgAAAUo"]
[Thu Sep 17 15:08:09.655887 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQdwAAAXs"]
[Thu Sep 17 15:08:09.662725 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQeQAAAX0"]
[Thu Sep 17 15:08:09.662819 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQeQAAAX0"]
[Thu Sep 17 15:08:09.745513 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQgAAAAVI"]
[Thu Sep 17 15:08:09.749965 2026] [security2:error] [pid 955873:tid 956113] [client 104.207.47.59:27023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/wp-automatic/readme.txt"] [unique_id "aqxWuRFTPRVSLOsRVhoQgQAAAXg"]
[Thu Sep 17 15:08:09.771045 2026] [security2:error] [pid 955873:tid 956068] [client 115.244.164.14:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQggAAAUs"]
[Thu Sep 17 15:08:09.771136 2026] [security2:error] [pid 955873:tid 956068] [client 115.244.164.14:54916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQggAAAUs"]
[Thu Sep 17 15:08:09.819491 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQhwAAAX4"]
[Thu Sep 17 15:08:09.893403 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQjAAAAWI"]
[Thu Sep 17 15:08:09.941424 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "aqxWuRFTPRVSLOsRVhoQjgAAARA"]
[Thu Sep 17 15:08:09.956392 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQjwAAAXY"]
[Thu Sep 17 15:08:09.967161 2026] [security2:error] [pid 955873:tid 956059] [client 4.240.114.86:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQkAAAAUI"], referer: binance.com
[Thu Sep 17 15:08:10.023849 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQkgAAAWc"]
[Thu Sep 17 15:08:10.084936 2026] [security2:error] [pid 955873:tid 956115] [client 68.55.134.110:45351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQkQABelo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821171306&hideliu=1&hidemyself=1&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:10.103534 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "aqxWuhFTPRVSLOsRVhoQlAAAAVU"]
[Thu Sep 17 15:08:10.160004 2026] [security2:error] [pid 955873:tid 956050] [client 34.94.67.131:37016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWuhFTPRVSLOsRVhoQlwAAATk"]
[Thu Sep 17 15:08:10.176972 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQmAAAAVA"]
[Thu Sep 17 15:08:10.238704 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQnQAAAQw"]
[Thu Sep 17 15:08:10.249603 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/reusable-blocks/wp-includes/css/dist/"] [unique_id "aqxWuhFTPRVSLOsRVhoQngAAARI"]
[Thu Sep 17 15:08:10.304759 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQowAAAV4"]
[Thu Sep 17 15:08:10.363244 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQpgAAAYE"]
[Thu Sep 17 15:08:10.456263 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQrAAAAVw"]
[Thu Sep 17 15:08:10.556655 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQrgAAATg"]
[Thu Sep 17 15:08:10.572623 2026] [security2:error] [pid 955873:tid 956120] [client 34.94.67.131:37032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQrwAAAX8"]
[Thu Sep 17 15:08:10.589654 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQqAAAAXU"]
[Thu Sep 17 15:08:10.589689 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQqAAAAXU"]
[Thu Sep 17 15:08:10.665165 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQtwAAAUo"]
[Thu Sep 17 15:08:10.701873 2026] [security2:error] [pid 955873:tid 956092] [client 154.190.208.131:42500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQvAAAAWM"]
[Thu Sep 17 15:08:10.714651 2026] [security2:error] [pid 955873:tid 956092] [client 154.190.208.131:42500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQvAAAAWM"]
[Thu Sep 17 15:08:10.724508 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQvQAAAUg"]
[Thu Sep 17 15:08:10.747231 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/theme/"] [unique_id "aqxWuhFTPRVSLOsRVhoQvgAAAVI"]
[Thu Sep 17 15:08:10.799484 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQvwAAAUs"]
[Thu Sep 17 15:08:10.829911 2026] [security2:error] [pid 955873:tid 956071] [client 34.94.67.131:37038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQwQAAAU4"]
[Thu Sep 17 15:08:10.863589 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQwwAAAYU"]
[Thu Sep 17 15:08:10.900889 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/theme/"] [unique_id "aqxWuhFTPRVSLOsRVhoQxAAAAX4"]
[Thu Sep 17 15:08:10.978523 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQxgAAAWA"]
[Thu Sep 17 15:08:11.039388 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/theme/wp-includes/css/dist/"] [unique_id "aqxWuxFTPRVSLOsRVhoQyAAAARw"]
[Thu Sep 17 15:08:11.053390 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQyQAAAXM"]
[Thu Sep 17 15:08:11.135586 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQzQAAAQ0"]
[Thu Sep 17 15:08:11.210731 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ1AAAATI"]
[Thu Sep 17 15:08:11.256841 2026] [security2:error] [pid 955873:tid 956019] [client 34.94.67.131:37054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoQ1wAAARo"]
[Thu Sep 17 15:08:11.275908 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ2QAAATE"]
[Thu Sep 17 15:08:11.343185 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ4AAAAXI"]
[Thu Sep 17 15:08:11.392623 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoQ0gAAAXY"]
[Thu Sep 17 15:08:11.392651 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoQ0gAAAXY"]
[Thu Sep 17 15:08:11.430523 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ5AAAAXE"]
[Thu Sep 17 15:08:11.530499 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/widgets/"] [unique_id "aqxWuxFTPRVSLOsRVhoRAQAAAWQ"]
[Thu Sep 17 15:08:11.535558 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRAgAAAUE"]
[Thu Sep 17 15:08:11.582833 2026] [security2:error] [pid 955873:tid 956054] [client 34.94.67.131:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRBQAAAT0"]
[Thu Sep 17 15:08:11.602444 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRBgAAAVc"]
[Thu Sep 17 15:08:11.660944 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRCQAAAU0"]
[Thu Sep 17 15:08:11.684321 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/widgets/"] [unique_id "aqxWuxFTPRVSLOsRVhoRCgAAARE"]
[Thu Sep 17 15:08:11.724143 2026] [authz_core:error] [pid 955873:tid 956037] [client 20.244.34.24:51773] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:08:11.753362 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRDgAAAV8"]
[Thu Sep 17 15:08:11.786638 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.190.5:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRDwAAAYg"]
[Thu Sep 17 15:08:11.821699 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoREAAAAUA"]
[Thu Sep 17 15:08:11.822604 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/widgets/wp-includes/css/dist/"] [unique_id "aqxWuxFTPRVSLOsRVhoREQAAAXk"]
[Thu Sep 17 15:08:11.847302 2026] [security2:error] [pid 955873:tid 956008] [client 34.94.67.131:37066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRFAAAAQ8"]
[Thu Sep 17 15:08:11.913205 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRFgAAAXU"]
[Thu Sep 17 15:08:11.977456 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRGwAAAVk"]
[Thu Sep 17 15:08:12.040341 2026] [security2:error] [pid 955873:tid 956066] [client 34.94.67.131:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWvBFTPRVSLOsRVhoRHAAAAUk"]
[Thu Sep 17 15:08:12.060625 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRHgAAAWM"]
[Thu Sep 17 15:08:12.120490 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRIQAAAXg"]
[Thu Sep 17 15:08:12.164041 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRGQAAASc"]
[Thu Sep 17 15:08:12.164066 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRGQAAASc"]
[Thu Sep 17 15:08:12.194765 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRKAAAAWk"]
[Thu Sep 17 15:08:12.243291 2026] [security2:error] [pid 955873:tid 956022] [client 34.94.67.131:37072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWvBFTPRVSLOsRVhoRKgAAAR0"]
[Thu Sep 17 15:08:12.307648 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxWvBFTPRVSLOsRVhoRKwAAAXw"]
[Thu Sep 17 15:08:12.312724 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRLAAAAYQ"]
[Thu Sep 17 15:08:12.392656 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRMAAAAXM"]
[Thu Sep 17 15:08:12.468591 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxWvBFTPRVSLOsRVhoRNQAAAYY"]
[Thu Sep 17 15:08:12.472236 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.190.5:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWvBFTPRVSLOsRVhoRNgAAATY"]
[Thu Sep 17 15:08:12.495470 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRNwAAAXQ"]
[Thu Sep 17 15:08:12.574471 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoROQAAARQ"]
[Thu Sep 17 15:08:12.585200 2026] [core:error] [pid 955873:tid 955887] [remote 43.128.104.113:45748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:12.585218 2026] [core:error] [pid 955873:tid 955887] [remote 43.128.104.113:45748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:12.614479 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:42188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/module.tag.lyrics3.php"] [unique_id "aqxWvBFTPRVSLOsRVhoROwAAATA"]
[Thu Sep 17 15:08:12.614588 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/module.tag.lyrics3.php"] [unique_id "aqxWvBFTPRVSLOsRVhoROwAAATA"]
[Thu Sep 17 15:08:12.626553 2026] [security2:error] [pid 955873:tid 956018] [client 104.207.47.59:51133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxWvBFTPRVSLOsRVhoRPAAAARk"]
[Thu Sep 17 15:08:12.643900 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRPwAAAWI"]
[Thu Sep 17 15:08:12.704649 2026] [security2:error] [pid 955873:tid 956077] [client 34.94.67.131:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWvBFTPRVSLOsRVhoRQwAAAVQ"]
[Thu Sep 17 15:08:12.902542 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxWvBFTPRVSLOsRVhoRRwAAASE"]
[Thu Sep 17 15:08:12.932153 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRSAAAAVo"]
[Thu Sep 17 15:08:13.000166 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRSQAAAYI"]
[Thu Sep 17 15:08:13.054289 2026] [authz_core:error] [pid 955873:tid 956036] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/IXR/error_log
[Thu Sep 17 15:08:13.059406 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxWvRFTPRVSLOsRVhoRTAAAASs"]
[Thu Sep 17 15:08:13.066586 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRTQAAAUQ"]
[Thu Sep 17 15:08:13.082903 2026] [security2:error] [pid 955873:tid 956017] [client 34.94.67.131:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWvRFTPRVSLOsRVhoRTwAAARg"]
[Thu Sep 17 15:08:13.135381 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRUgAAAQo"]
[Thu Sep 17 15:08:13.160677 2026] [security2:error] [pid 955873:tid 956033] [client 34.166.190.5:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRVAAAASg"]
[Thu Sep 17 15:08:13.201738 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxWvRFTPRVSLOsRVhoRVgAAAT8"]
[Thu Sep 17 15:08:13.221418 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRVwAAAYc"]
[Thu Sep 17 15:08:13.300420 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRWgAAAR4"]
[Thu Sep 17 15:08:13.361213 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxWvRFTPRVSLOsRVhoRWwAAAS0"]
[Thu Sep 17 15:08:13.385311 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRXAAAASw"]
[Thu Sep 17 15:08:13.454818 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRXgAAAQ8"]
[Thu Sep 17 15:08:13.491868 2026] [security2:error] [pid 955873:tid 956049] [client 4.240.114.86:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRXwAAATg"], referer: binance.com
[Thu Sep 17 15:08:13.521407 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/"] [unique_id "aqxWvRFTPRVSLOsRVhoRYAAAAT4"]
[Thu Sep 17 15:08:13.523122 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRYQAAAVw"]
[Thu Sep 17 15:08:13.590800 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRYwAAAUc"]
[Thu Sep 17 15:08:13.623148 2026] [security2:error] [pid 955873:tid 956120] [client 34.94.67.131:37094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWvRFTPRVSLOsRVhoRZAAAAX8"]
[Thu Sep 17 15:08:13.650391 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRaAAAAUk"]
[Thu Sep 17 15:08:13.670992 2026] [authz_core:error] [pid 955873:tid 956092] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/library/error_log
[Thu Sep 17 15:08:13.672211 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/"] [unique_id "aqxWvRFTPRVSLOsRVhoRagAAAWM"]
[Thu Sep 17 15:08:13.711535 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRawAAAXg"]
[Thu Sep 17 15:08:13.794858 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRbQAAASo"]
[Thu Sep 17 15:08:13.827021 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/wp-includes/Requests/"] [unique_id "aqxWvRFTPRVSLOsRVhoRbgAAASQ"]
[Thu Sep 17 15:08:13.839865 2026] [security2:error] [pid 955873:tid 956012] [client 34.166.190.5:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRbwAAARM"]
[Thu Sep 17 15:08:13.855397 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRcAAAAWk"]
[Thu Sep 17 15:08:13.946683 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRdQAAATU"]
[Thu Sep 17 15:08:14.033265 2026] [security2:error] [pid 955873:tid 956089] [client 34.94.67.131:37100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRdwAAAWA"]
[Thu Sep 17 15:08:14.039222 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoReQAAARs"]
[Thu Sep 17 15:08:14.152538 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRfAAAASM"]
[Thu Sep 17 15:08:14.181374 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRdgAAARw"]
[Thu Sep 17 15:08:14.181403 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRdgAAARw"]
[Thu Sep 17 15:08:14.245533 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRfgAAAQ0"]
[Thu Sep 17 15:08:14.314618 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRgQAAARc"]
[Thu Sep 17 15:08:14.326746 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/Requests.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRggAAAWc"]
[Thu Sep 17 15:08:14.326829 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/Requests.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRggAAAWc"]
[Thu Sep 17 15:08:14.341236 2026] [security2:error] [pid 955873:tid 956013] [client 34.94.67.131:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRgwAAARQ"]
[Thu Sep 17 15:08:14.403059 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRhQAAATA"]
[Thu Sep 17 15:08:14.476344 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRhwAAAYA"]
[Thu Sep 17 15:08:14.522039 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.190.5:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRiQAAATQ"]
[Thu Sep 17 15:08:14.534040 2026] [core:error] [pid 955873:tid 955915] [remote 120.227.18.209:6693] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:14.534056 2026] [core:error] [pid 955873:tid 955915] [remote 120.227.18.209:6693] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:14.561402 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRiwAAAVY"]
[Thu Sep 17 15:08:14.612469 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/"] [unique_id "aqxWvhFTPRVSLOsRVhoRjgAAARo"]
[Thu Sep 17 15:08:14.621770 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRjwAAAV4"]
[Thu Sep 17 15:08:14.631692 2026] [security2:error] [pid 955873:tid 956111] [client 34.94.67.131:37116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRkAAAAXY"]
[Thu Sep 17 15:08:14.687782 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRkwAAAVo"]
[Thu Sep 17 15:08:14.771637 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRlwAAAV0"]
[Thu Sep 17 15:08:14.774571 2026] [authz_core:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/error_log
[Thu Sep 17 15:08:14.806251 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/"] [unique_id "aqxWvhFTPRVSLOsRVhoRlAAAAWQ"]
[Thu Sep 17 15:08:14.831324 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRmAAAAUQ"]
[Thu Sep 17 15:08:14.920920 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRmgAAAXc"]
[Thu Sep 17 15:08:14.948601 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:42210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/wp-includes/Requests/"] [unique_id "aqxWvhFTPRVSLOsRVhoRmwAAARg"]
[Thu Sep 17 15:08:14.995315 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRnwAAAVA"]
[Thu Sep 17 15:08:15.088397 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRpAAAAR4"]
[Thu Sep 17 15:08:15.099301 2026] [security2:error] [pid 955873:tid 956104] [client 186.105.232.15:57189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRpQAAAW8"]
[Thu Sep 17 15:08:15.099421 2026] [security2:error] [pid 955873:tid 956104] [client 186.105.232.15:57189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRpQAAAW8"]
[Thu Sep 17 15:08:15.119238 2026] [security2:error] [pid 955873:tid 956128] [client 87.110.34.78:55968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRngABhyM"]
[Thu Sep 17 15:08:15.187630 2026] [security2:error] [pid 955873:tid 956100] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRqAAAAWs"]
[Thu Sep 17 15:08:15.202511 2026] [security2:error] [pid 955873:tid 956054] [client 34.94.67.131:37122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRqQAAAT0"]
[Thu Sep 17 15:08:15.208317 2026] [security2:error] [pid 955873:tid 956056] [client 34.166.190.5:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRqgAAAT8"]
[Thu Sep 17 15:08:15.216410 2026] [security2:error] [pid 955873:tid 956103] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRoAAAAW4"]
[Thu Sep 17 15:08:15.278264 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRrgAAAQ8"]
[Thu Sep 17 15:08:15.289408 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRowAAAU0"]
[Thu Sep 17 15:08:15.289429 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRowAAAU0"]
[Thu Sep 17 15:08:15.359725 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRsAAAAXU"]
[Thu Sep 17 15:08:15.433469 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRtQAAAUg"]
[Thu Sep 17 15:08:15.433551 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRtQAAAUg"]
[Thu Sep 17 15:08:15.438392 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRtgAAAXg"]
[Thu Sep 17 15:08:15.524672 2026] [security2:error] [pid 955873:tid 956039] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRuQAAAS4"]
[Thu Sep 17 15:08:15.621067 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRvAAAATk"]
[Thu Sep 17 15:08:15.629169 2026] [security2:error] [pid 955873:tid 956130] [client 34.94.67.131:37126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRvwAAAYk"]
[Thu Sep 17 15:08:15.684631 2026] [security2:error] [pid 955873:tid 956029] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRuAABJAQ"], referer: http://heromakers.org/new/
[Thu Sep 17 15:08:15.705941 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRwgAAAWA"]
[Thu Sep 17 15:08:15.713282 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRxAAAAXM"]
[Thu Sep 17 15:08:15.714244 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:42216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "aqxWvxFTPRVSLOsRVhoRxQAAASk"]
[Thu Sep 17 15:08:15.794306 2026] [security2:error] [pid 955873:tid 956118] [client 104.207.47.59:37385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/gamipress/readme.txt"] [unique_id "aqxWvxFTPRVSLOsRVhoRzAAAAX0"]
[Thu Sep 17 15:08:15.819125 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRzgAAAWc"]
[Thu Sep 17 15:08:15.866906 2026] [authz_core:error] [pid 955873:tid 956013] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Auth/error_log
[Thu Sep 17 15:08:15.868029 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "aqxWvxFTPRVSLOsRVhoR0QAAARQ"]
[Thu Sep 17 15:08:15.909071 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.190.5:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWvxFTPRVSLOsRVhoR0wAAAXk"]
[Thu Sep 17 15:08:15.910281 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoR0gAAAXI"]
[Thu Sep 17 15:08:15.972182 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoR1QAAARI"]
[Thu Sep 17 15:08:16.027082 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:42216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/wp-includes/Requests/src/"] [unique_id "aqxWwBFTPRVSLOsRVhoR1gAAAYY"]
[Thu Sep 17 15:08:16.033338 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRzwAAAX4"]
[Thu Sep 17 15:08:16.052406 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR1wAAASA"]
[Thu Sep 17 15:08:16.141226 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR3AAAARo"]
[Thu Sep 17 15:08:16.236039 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR5AAAAWQ"]
[Thu Sep 17 15:08:16.268328 2026] [security2:error] [pid 955873:tid 956051] [client 34.94.67.131:37130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR5QAAATo"]
[Thu Sep 17 15:08:16.312960 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR6QAAAS8"]
[Thu Sep 17 15:08:16.381378 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR4gAAAQw"]
[Thu Sep 17 15:08:16.381399 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR4gAAAQw"]
[Thu Sep 17 15:08:16.400845 2026] [security2:error] [pid 955873:tid 956007] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR4wAAAQ4"]
[Thu Sep 17 15:08:16.434181 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR6wAAAVA"]
[Thu Sep 17 15:08:16.521000 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR8AAAAWg"]
[Thu Sep 17 15:08:16.522643 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/Basic.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8QAAAUA"]
[Thu Sep 17 15:08:16.522753 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:42216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/Basic.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8QAAAUA"]
[Thu Sep 17 15:08:16.561499 2026] [security2:error] [pid 955873:tid 956124] [client 162.241.226.11:35398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR6gAAAYM"]
[Thu Sep 17 15:08:16.582438 2026] [security2:error] [pid 955873:tid 956023] [client 34.94.67.131:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8wAAAR4"]
[Thu Sep 17 15:08:16.607789 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR-AAAAVw"]
[Thu Sep 17 15:08:16.667570 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR_AAAAVc"]
[Thu Sep 17 15:08:16.697567 2026] [security2:error] [pid 955873:tid 956030] [client 4.240.114.86:65534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR_gAAASU"], referer: binance.com
[Thu Sep 17 15:08:16.732783 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR_wAAAUE"]
[Thu Sep 17 15:08:16.767452 2026] [security2:error] [pid 955873:tid 956008] [client 162.241.226.11:35404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR9AAAAQ8"]
[Thu Sep 17 15:08:16.773442 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8gAAASw"]
[Thu Sep 17 15:08:16.802990 2026] [security2:error] [pid 955873:tid 956069] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoSAwAAAUw"]
[Thu Sep 17 15:08:16.812993 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBAAAAXU"]
[Thu Sep 17 15:08:16.813289 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:51340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBAAAAXU"]
[Thu Sep 17 15:08:16.815485 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Autoload.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBQAAASY"]
[Thu Sep 17 15:08:16.815559 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Autoload.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBQAAASY"]
[Thu Sep 17 15:08:16.834651 2026] [security2:error] [pid 955873:tid 956098] [client 34.166.190.5:35362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBgAAAWk"]
[Thu Sep 17 15:08:16.878514 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoSCAAAATM"]
[Thu Sep 17 15:08:16.917202 2026] [security2:error] [pid 955873:tid 956075] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSAQABUhg"], referer: http://heromakers.org/wordpress/
[Thu Sep 17 15:08:16.970454 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoSDQAAATw"]
[Thu Sep 17 15:08:16.984186 2026] [security2:error] [pid 955873:tid 956029] [client 34.94.67.131:37134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSDgAAASQ"]
[Thu Sep 17 15:08:17.055581 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSFAAAARs"]
[Thu Sep 17 15:08:17.103691 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:42236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Capability.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSFgAAATI"]
[Thu Sep 17 15:08:17.103780 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:42236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Capability.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSFgAAATI"]
[Thu Sep 17 15:08:17.106123 2026] [security2:error] [pid 955873:tid 956050] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSCwAAATk"]
[Thu Sep 17 15:08:17.154140 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSGQAAARI"]
[Thu Sep 17 15:08:17.227780 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSIgAAARY"]
[Thu Sep 17 15:08:17.300560 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSJgAAARU"]
[Thu Sep 17 15:08:17.362484 2026] [security2:error] [pid 955873:tid 955916] [remote 216.73.217.142:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWwRFTPRVSLOsRVhoSJwABOio"]
[Thu Sep 17 15:08:17.363027 2026] [security2:error] [pid 955873:tid 956028] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSHgABIxM"], referer: http://heromakers.org/old/
[Thu Sep 17 15:08:17.395146 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:42250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSKAAAAUQ"]
[Thu Sep 17 15:08:17.395232 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:42250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSKAAAAUQ"]
[Thu Sep 17 15:08:17.397860 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSKQAAAS8"]
[Thu Sep 17 15:08:17.439235 2026] [security2:error] [pid 955873:tid 956086] [client 34.94.67.131:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSKgAAAV0"]
[Thu Sep 17 15:08:17.454082 2026] [security2:error] [pid 955873:tid 956087] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSIwAAAV4"]
[Thu Sep 17 15:08:17.484763 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSLwAAASs"]
[Thu Sep 17 15:08:17.525252 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.190.5:35378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSMQAAAVo"]
[Thu Sep 17 15:08:17.562666 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSNQAAAW4"]
[Thu Sep 17 15:08:17.650796 2026] [security2:error] [pid 955873:tid 956124] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSOwAAAYM"]
[Thu Sep 17 15:08:17.687988 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:42258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/"] [unique_id "aqxWwRFTPRVSLOsRVhoSPAAAAU8"]
[Thu Sep 17 15:08:17.706192 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSPgAAAR4"]
[Thu Sep 17 15:08:17.780474 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSQAAAASE"]
[Thu Sep 17 15:08:17.792840 2026] [security2:error] [pid 955873:tid 956038] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSNgAAAS0"]
[Thu Sep 17 15:08:17.803064 2026] [security2:error] [pid 955873:tid 956003] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSOgABCho"], referer: http://heromakers.org/backup/
[Thu Sep 17 15:08:17.832513 2026] [security2:error] [pid 955873:tid 956052] [client 45.137.215.217:60729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.215.137.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seandaviddeezyn.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSQwAAATs"], referer: https://seandaviddeezyn.com/
[Thu Sep 17 15:08:17.834029 2026] [security2:error] [pid 955873:tid 956085] [client 34.94.67.131:37148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSRAAAAVw"]
[Thu Sep 17 15:08:17.839987 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/"] [unique_id "aqxWwRFTPRVSLOsRVhoSQgAAAVc"]
[Thu Sep 17 15:08:17.845647 2026] [security2:error] [pid 955873:tid 956033] [client 177.55.205.211:8006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSPwABKCE"]
[Thu Sep 17 15:08:17.847160 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.bak"] [unique_id "aqxWwRFTPRVSLOsRVhoSRQAAAUo"]
[Thu Sep 17 15:08:17.854485 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSRgAAASU"]
[Thu Sep 17 15:08:17.907850 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.backup"] [unique_id "aqxWwRFTPRVSLOsRVhoSRwAAAQ8"]
[Thu Sep 17 15:08:17.962357 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSSwAAAU4"]
[Thu Sep 17 15:08:17.979848 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/wp-includes/Requests/src/"] [unique_id "aqxWwRFTPRVSLOsRVhoSTQAAAYc"]
[Thu Sep 17 15:08:18.024207 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSTgAAAWk"]
[Thu Sep 17 15:08:18.085329 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSUAAAATc"]
[Thu Sep 17 15:08:18.173375 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSVwAAASk"]
[Thu Sep 17 15:08:18.225325 2026] [security2:error] [pid 955873:tid 956035] [client 34.166.190.5:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSWQAAASo"]
[Thu Sep 17 15:08:18.251282 2026] [security2:error] [pid 955873:tid 956066] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSTwABSTE"], referer: http://heromakers.org/wp/
[Thu Sep 17 15:08:18.252167 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSWgAAAX0"]
[Thu Sep 17 15:08:18.265194 2026] [security2:error] [pid 955873:tid 956109] [client 34.94.67.131:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSWwAAAXQ"]
[Thu Sep 17 15:08:18.313969 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSUQAAATM"]
[Thu Sep 17 15:08:18.313990 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSUQAAATM"]
[Thu Sep 17 15:08:18.329858 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSXQAAAWE"]
[Thu Sep 17 15:08:18.344345 2026] [security2:error] [pid 955873:tid 956130] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSVQAAAYk"]
[Thu Sep 17 15:08:18.349254 2026] [security2:error] [pid 955873:tid 956029] [client 45.169.98.18:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSXgAAASQ"]
[Thu Sep 17 15:08:18.349680 2026] [security2:error] [pid 955873:tid 956029] [client 45.169.98.18:61202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSXgAAASQ"]
[Thu Sep 17 15:08:18.416095 2026] [security2:error] [pid 955873:tid 956043] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.old"] [unique_id "aqxWwhFTPRVSLOsRVhoSXwAAATI"]
[Thu Sep 17 15:08:18.422438 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSYAAAAWI"]
[Thu Sep 17 15:08:18.453719 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:42258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/Jar.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSYQAAATE"]
[Thu Sep 17 15:08:18.453795 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:42258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/Jar.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSYQAAATE"]
[Thu Sep 17 15:08:18.501671 2026] [security2:error] [pid 955873:tid 956024] [client 77.232.40.141:61786] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ojorojomusic.com"] [uri "/why-did-rock-music-get-popular/"] [unique_id "aqxWwhFTPRVSLOsRVhoSZwAAAR8"]
[Thu Sep 17 15:08:18.513189 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSaAAAAVY"]
[Thu Sep 17 15:08:18.583320 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSbAAAATY"]
[Thu Sep 17 15:08:18.672517 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoScgAAAQ4"]
[Thu Sep 17 15:08:18.696607 2026] [security2:error] [pid 955873:tid 956121] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSZQAAAYA"]
[Thu Sep 17 15:08:18.717461 2026] [security2:error] [pid 955873:tid 956127] [client 104.207.47.59:52579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/userswp/readme.txt"] [unique_id "aqxWwhFTPRVSLOsRVhoScwAAAYY"]
[Thu Sep 17 15:08:18.742362 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSdAAAARg"]
[Thu Sep 17 15:08:18.757002 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSdQAAAUU"]
[Thu Sep 17 15:08:18.757079 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSdQAAAUU"]
[Thu Sep 17 15:08:18.892157 2026] [security2:error] [pid 955873:tid 956097] [client 34.94.67.131:37170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSfwAAAWg"]
[Thu Sep 17 15:08:18.910235 2026] [security2:error] [pid 955873:tid 956086] [client 34.166.190.5:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSgAAAAV0"]
[Thu Sep 17 15:08:19.037564 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/"] [unique_id "aqxWwxFTPRVSLOsRVhoSiAAAAVw"]
[Thu Sep 17 15:08:19.051981 2026] [security2:error] [pid 955873:tid 956103] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSfQAAAW4"]
[Thu Sep 17 15:08:19.052626 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSiQAAAVc"]
[Thu Sep 17 15:08:19.190563 2026] [security2:error] [pid 955873:tid 956052] [client 104.154.81.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoShwAAATs"]
[Thu Sep 17 15:08:19.194000 2026] [authz_core:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Exception/error_log
[Thu Sep 17 15:08:19.210478 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/"] [unique_id "aqxWwxFTPRVSLOsRVhoSkgAAAXU"]
[Thu Sep 17 15:08:19.311446 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSlgAAAXw"]
[Thu Sep 17 15:08:19.328010 2026] [security2:error] [pid 955873:tid 956032] [client 34.94.67.131:37172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSmAAAASc"]
[Thu Sep 17 15:08:19.349914 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:42284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/wp-includes/Requests/src/"] [unique_id "aqxWwxFTPRVSLOsRVhoSmQAAARs"]
[Thu Sep 17 15:08:19.384418 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSmgAAAXM"]
[Thu Sep 17 15:08:19.385536 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSjwAAASw"]
[Thu Sep 17 15:08:19.476654 2026] [security2:error] [pid 955873:tid 956099] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSoAAAAWo"]
[Thu Sep 17 15:08:19.591780 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSpwAAAR0"]
[Thu Sep 17 15:08:19.595679 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.190.5:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSqAAAATM"]
[Thu Sep 17 15:08:19.601214 2026] [security2:error] [pid 955873:tid 956009] [client 4.240.114.86:50832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSqQAAARA"], referer: binance.com
[Thu Sep 17 15:08:19.664481 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSrQAAAVY"]
[Thu Sep 17 15:08:19.705870 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSoQAAASQ"]
[Thu Sep 17 15:08:19.705896 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSoQAAASQ"]
[Thu Sep 17 15:08:19.733680 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSsAAAATY"]
[Thu Sep 17 15:08:19.743110 2026] [security2:error] [pid 955873:tid 956064] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSpQAAAUc"]
[Thu Sep 17 15:08:19.819930 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSswAAAWQ"]
[Thu Sep 17 15:08:19.843685 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/ArgumentCount.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStgAAAXk"]
[Thu Sep 17 15:08:19.843774 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/ArgumentCount.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStgAAAXk"]
[Thu Sep 17 15:08:19.866616 2026] [security2:error] [pid 955873:tid 956051] [client 34.94.67.131:58794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStwAAATo"]
[Thu Sep 17 15:08:19.894128 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSuAAAAQs"]
[Thu Sep 17 15:08:19.963348 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSuQAAARg"]
[Thu Sep 17 15:08:20.036903 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSvAAAARM"]
[Thu Sep 17 15:08:20.060504 2026] [security2:error] [pid 955873:tid 956011] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStQAAARI"]
[Thu Sep 17 15:08:20.113978 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSvQAAAWw"]
[Thu Sep 17 15:08:20.124452 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSvwAAARo"]
[Thu Sep 17 15:08:20.124533 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSvwAAARo"]
[Thu Sep 17 15:08:20.219962 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSxgAAAYE"]
[Thu Sep 17 15:08:20.278715 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.190.5:35406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSxwAAAW8"]
[Thu Sep 17 15:08:20.297283 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSyAAAAQo"]
[Thu Sep 17 15:08:20.347929 2026] [security2:error] [pid 955873:tid 956023] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSwQAAAR4"]
[Thu Sep 17 15:08:20.365702 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSywAAASg"]
[Thu Sep 17 15:08:20.374433 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.188.156:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSyQAAAVw"]
[Thu Sep 17 15:08:20.379540 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSzQAAAWU"]
[Thu Sep 17 15:08:20.379605 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:55532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSzQAAAWU"]
[Thu Sep 17 15:08:20.415565 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:53648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/"] [unique_id "aqxWxBFTPRVSLOsRVhoSzgAAAQ8"]
[Thu Sep 17 15:08:20.459739 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS0gAAASY"]
[Thu Sep 17 15:08:20.543058 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS1QAAATc"]
[Thu Sep 17 15:08:20.580719 2026] [authz_core:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Exception/Http/error_log
[Thu Sep 17 15:08:20.596084 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/"] [unique_id "aqxWxBFTPRVSLOsRVhoS1gAAAXU"]
[Thu Sep 17 15:08:20.602995 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS1wAAASo"]
[Thu Sep 17 15:08:20.668371 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS0wAAARE"]
[Thu Sep 17 15:08:20.674523 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS3QAAAXQ"]
[Thu Sep 17 15:08:20.739581 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:53648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/wp-includes/Requests/src/Exception/"] [unique_id "aqxWxBFTPRVSLOsRVhoS4gAAAVg"]
[Thu Sep 17 15:08:20.740595 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS4wAAAUA"]
[Thu Sep 17 15:08:20.859739 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.188.156:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/info.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS6AAAAUM"]
[Thu Sep 17 15:08:20.869862 2026] [security2:error] [pid 955873:tid 956039] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS6QAAAS4"]
[Thu Sep 17 15:08:20.959453 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS7AAAAR0"]
[Thu Sep 17 15:08:20.967575 2026] [security2:error] [pid 955873:tid 956130] [client 34.166.190.5:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS7QAAAYk"]
[Thu Sep 17 15:08:20.980625 2026] [security2:error] [pid 955873:tid 956125] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS5AAAAYQ"]
[Thu Sep 17 15:08:21.058808 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoS9AAAAXs"]
[Thu Sep 17 15:08:21.112231 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS6gAAATE"]
[Thu Sep 17 15:08:21.112256 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS6gAAATE"]
[Thu Sep 17 15:08:21.132239 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoS-AAAAWQ"]
[Thu Sep 17 15:08:21.191352 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoS_QAAAT4"]
[Thu Sep 17 15:08:21.225284 2026] [security2:error] [pid 955873:tid 956099] [client 154.190.208.131:41747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS_gAAAWo"]
[Thu Sep 17 15:08:21.225472 2026] [security2:error] [pid 955873:tid 956099] [client 154.190.208.131:41747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS_gAAAWo"]
[Thu Sep 17 15:08:21.252578 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status304.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTAAAAATo"]
[Thu Sep 17 15:08:21.252727 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:53648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status304.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTAAAAATo"]
[Thu Sep 17 15:08:21.283133 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTAwAAATQ"]
[Thu Sep 17 15:08:21.317862 2026] [security2:error] [pid 955873:tid 956040] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS9gAAAS8"]
[Thu Sep 17 15:08:21.332580 2026] [security2:error] [pid 955873:tid 956029] [client 40.77.167.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS8QAAASQ"]
[Thu Sep 17 15:08:21.349416 2026] [security2:error] [pid 955873:tid 956087] [client 34.95.188.156:55200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/php.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTBwAAAV4"]
[Thu Sep 17 15:08:21.354219 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTCQAAARI"]
[Thu Sep 17 15:08:21.500466 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTCwAAAR4"]
[Thu Sep 17 15:08:21.530059 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:53662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status305.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTDQAAAVc"]
[Thu Sep 17 15:08:21.530155 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:53662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status305.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTDQAAAVc"]
[Thu Sep 17 15:08:21.573458 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTEgAAAWU"]
[Thu Sep 17 15:08:21.663911 2026] [security2:error] [pid 955873:tid 956070] [client 34.166.190.5:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTGQAAAU0"]
[Thu Sep 17 15:08:21.676950 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTGgAAASY"]
[Thu Sep 17 15:08:21.731322 2026] [security2:error] [pid 955873:tid 956082] [client 104.207.47.59:12363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/bookingpress-appointment-booking/readme.txt"] [unique_id "aqxWxRFTPRVSLOsRVhoTHgAAAVk"]
[Thu Sep 17 15:08:21.775411 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTEQAAAT0"]
[Thu Sep 17 15:08:21.787469 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTIAAAARE"]
[Thu Sep 17 15:08:21.816148 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:53664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status306.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTIQAAASc"]
[Thu Sep 17 15:08:21.816272 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:53664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status306.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTIQAAASc"]
[Thu Sep 17 15:08:21.842447 2026] [security2:error] [pid 955873:tid 956052] [client 34.95.188.156:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/i.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTIgAAATs"]
[Thu Sep 17 15:08:21.886139 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTJAAAAYg"]
[Thu Sep 17 15:08:21.993342 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTKgAAAXc"]
[Thu Sep 17 15:08:22.099383 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:53670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status400.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTOQAAAR8"]
[Thu Sep 17 15:08:22.099516 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:53670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status400.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTOQAAAR8"]
[Thu Sep 17 15:08:22.100961 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTOgAAAUI"]
[Thu Sep 17 15:08:22.179118 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTQQAAAUE"]
[Thu Sep 17 15:08:22.193526 2026] [security2:error] [pid 955873:tid 956111] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTKQAAAXY"]
[Thu Sep 17 15:08:22.277864 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTRQAAARM"]
[Thu Sep 17 15:08:22.319022 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.swp"] [unique_id "aqxWxhFTPRVSLOsRVhoTRwAAAXI"]
[Thu Sep 17 15:08:22.339172 2026] [security2:error] [pid 955873:tid 956096] [client 34.95.188.156:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/pi.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTSAAAAWc"]
[Thu Sep 17 15:08:22.371120 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env~"] [unique_id "aqxWxhFTPRVSLOsRVhoTTAAAATY"]
[Thu Sep 17 15:08:22.374004 2026] [security2:error] [pid 955873:tid 956021] [client 134.185.85.61:49969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "ppfc.net"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxWxhFTPRVSLOsRVhoTTQAAARw"]
[Thu Sep 17 15:08:22.374886 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTTgAAAWw"]
[Thu Sep 17 15:08:22.383326 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status401.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTTwAAARo"]
[Thu Sep 17 15:08:22.383399 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status401.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTTwAAARo"]
[Thu Sep 17 15:08:22.500553 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTVAAAAYE"]
[Thu Sep 17 15:08:22.587437 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTWQAAAW4"]
[Thu Sep 17 15:08:22.610528 2026] [security2:error] [pid 955873:tid 956080] [client 34.166.190.5:35430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTWgAAAVc"]
[Thu Sep 17 15:08:22.666429 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status402.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTXQAAAUo"]
[Thu Sep 17 15:08:22.666566 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status402.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTXQAAAUo"]
[Thu Sep 17 15:08:22.676531 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTXgAAASU"]
[Thu Sep 17 15:08:22.716896 2026] [security2:error] [pid 955873:tid 956104] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTVQAAAW8"]
[Thu Sep 17 15:08:22.752758 2026] [security2:error] [pid 955873:tid 956120] [client 134.185.85.61:62432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "ppfc.net"] [uri "/media/system/js/core.js"] [unique_id "aqxWxhFTPRVSLOsRVhoTYAAAAX8"]
[Thu Sep 17 15:08:22.781161 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTYgAAATc"]
[Thu Sep 17 15:08:22.824291 2026] [security2:error] [pid 955873:tid 956094] [client 34.95.188.156:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/pinfo.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTZAAAAWU"]
[Thu Sep 17 15:08:22.874921 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTZQAAASo"]
[Thu Sep 17 15:08:22.955173 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status403.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTaQAAAUk"]
[Thu Sep 17 15:08:22.955268 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:53700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status403.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTaQAAAUk"]
[Thu Sep 17 15:08:22.958908 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTawAAARE"]
[Thu Sep 17 15:08:22.980634 2026] [security2:error] [pid 955873:tid 956078] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTRgABVVo"], referer: http://eco-tech.vn/wp/
[Thu Sep 17 15:08:23.048762 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTbwAAATs"]
[Thu Sep 17 15:08:23.095383 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTZgAAAT0"]
[Thu Sep 17 15:08:23.167376 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTdQAAAXo"]
[Thu Sep 17 15:08:23.252955 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status404.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTeAAAAWI"]
[Thu Sep 17 15:08:23.253055 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:53704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status404.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTeAAAAWI"]
[Thu Sep 17 15:08:23.305461 2026] [security2:error] [pid 955873:tid 956036] [client 34.95.188.156:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/test.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTfAAAASs"]
[Thu Sep 17 15:08:23.308886 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.190.5:56038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTfgAAAX0"]
[Thu Sep 17 15:08:23.326606 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTgAAAAXM"]
[Thu Sep 17 15:08:23.414773 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTgwAAAR8"]
[Thu Sep 17 15:08:23.509458 2026] [core:error] [pid 955873:tid 956000] [remote 180.153.197.114:47586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.509475 2026] [core:error] [pid 955873:tid 956000] [remote 180.153.197.114:47586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.510981 2026] [core:error] [pid 955873:tid 955991] [remote 180.153.197.67:35940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.510992 2026] [core:error] [pid 955873:tid 955991] [remote 180.153.197.67:35940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.516091 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTiAAAATo"]
[Thu Sep 17 15:08:23.530618 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status405.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTiQAAAR0"]
[Thu Sep 17 15:08:23.530723 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:53714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status405.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTiQAAAR0"]
[Thu Sep 17 15:08:23.585290 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTiwAAATI"]
[Thu Sep 17 15:08:23.597680 2026] [security2:error] [pid 955873:tid 956079] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTggAAAVY"]
[Thu Sep 17 15:08:23.721997 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTkAAAAVo"]
[Thu Sep 17 15:08:23.812331 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTlAAAAYA"]
[Thu Sep 17 15:08:23.816561 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:53720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status406.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTlQAAAXI"]
[Thu Sep 17 15:08:23.816640 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:53720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status406.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTlQAAAXI"]
[Thu Sep 17 15:08:23.890099 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTmAAAAX4"]
[Thu Sep 17 15:08:23.923609 2026] [security2:error] [pid 955873:tid 956106] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTjwABcVs"], referer: http://eco-tech.vn/wordpress/
[Thu Sep 17 15:08:23.965259 2026] [security2:error] [pid 955873:tid 956019] [client 34.95.188.156:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/p.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTmQAAARo"]
[Thu Sep 17 15:08:23.982933 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTnQAAAS0"]
[Thu Sep 17 15:08:24.006359 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.190.5:56040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTngAAASQ"]
[Thu Sep 17 15:08:24.086543 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTowAAAW8"]
[Thu Sep 17 15:08:24.108850 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status407.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTpAAAAU0"]
[Thu Sep 17 15:08:24.108960 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status407.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTpAAAAU0"]
[Thu Sep 17 15:08:24.174830 2026] [security2:error] [pid 955873:tid 956021] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTmgAAARw"]
[Thu Sep 17 15:08:24.217440 2026] [security2:error] [pid 955873:tid 956124] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTqwAAAYM"]
[Thu Sep 17 15:08:24.289978 2026] [security2:error] [pid 955873:tid 956114] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTrQAAAXk"]
[Thu Sep 17 15:08:24.354322 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTrgAAAXg"]
[Thu Sep 17 15:08:24.397023 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:53730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status408.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTrwAAATs"]
[Thu Sep 17 15:08:24.397124 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:53730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status408.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTrwAAATs"]
[Thu Sep 17 15:08:24.442432 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:38278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTrAAAASo"]
[Thu Sep 17 15:08:24.464975 2026] [security2:error] [pid 955873:tid 956010] [client 34.95.188.156:39846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/debug.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTsgAAARE"]
[Thu Sep 17 15:08:24.511422 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTswAAAXQ"]
[Thu Sep 17 15:08:24.606902 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTtgAAASE"]
[Thu Sep 17 15:08:24.686606 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.190.5:56054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTvAAAAVk"]
[Thu Sep 17 15:08:24.695159 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status409.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTvgAAARQ"]
[Thu Sep 17 15:08:24.695247 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status409.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTvgAAARQ"]
[Thu Sep 17 15:08:24.712521 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTvwAAAYk"]
[Thu Sep 17 15:08:24.833420 2026] [security2:error] [pid 955873:tid 956128] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTuAAAAYc"]
[Thu Sep 17 15:08:24.864527 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTwQAAASw"]
[Thu Sep 17 15:08:24.948410 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.195.25:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTxAAAASk"]
[Thu Sep 17 15:08:24.974644 2026] [security2:error] [pid 955873:tid 956006] [client 34.95.188.156:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTxgAAAQ0"]
[Thu Sep 17 15:08:25.045450 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status410.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTyAAAAWQ"]
[Thu Sep 17 15:08:25.045560 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status410.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTyAAAAWQ"]
[Thu Sep 17 15:08:25.172348 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTxQAAAUA"]
[Thu Sep 17 15:08:25.277642 2026] [security2:error] [pid 955873:tid 956017] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/app/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoTzgAAARg"]
[Thu Sep 17 15:08:25.279719 2026] [security2:error] [pid 955873:tid 956027] [client 40.77.167.67:1721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kimleightpc.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS5wABIkY"]
[Thu Sep 17 15:08:25.331969 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTzwAAAWM"]
[Thu Sep 17 15:08:25.334521 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:53756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status411.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT0AAAAUg"]
[Thu Sep 17 15:08:25.334644 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:53756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status411.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT0AAAAUg"]
[Thu Sep 17 15:08:25.339064 2026] [security2:error] [pid 955873:tid 956075] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/apps/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT0QAAAVI"]
[Thu Sep 17 15:08:25.387011 2026] [security2:error] [pid 955873:tid 956116] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT0wAAAXs"]
[Thu Sep 17 15:08:25.393664 2026] [security2:error] [pid 955873:tid 956022] [client 34.166.190.5:56058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT1AAAAR0"]
[Thu Sep 17 15:08:25.414074 2026] [security2:error] [pid 955873:tid 956051] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTyQABOmY"], referer: http://eco-tech.vn/backup/
[Thu Sep 17 15:08:25.471776 2026] [security2:error] [pid 955873:tid 956004] [client 34.95.188.156:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/test/phpinfo.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT1QAAAQs"]
[Thu Sep 17 15:08:25.484630 2026] [security2:error] [pid 955873:tid 956101] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/web/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT1gAAAWw"]
[Thu Sep 17 15:08:25.547979 2026] [security2:error] [pid 955873:tid 956042] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/site/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT1wAAATE"]
[Thu Sep 17 15:08:25.633618 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status412.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT2wAAAYE"]
[Thu Sep 17 15:08:25.633735 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:53758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status412.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT2wAAAYE"]
[Thu Sep 17 15:08:25.687553 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT3QAAAS0"]
[Thu Sep 17 15:08:25.693018 2026] [security2:error] [pid 955873:tid 956029] [client 23.120.8.137:54163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT2QABJAo"]
[Thu Sep 17 15:08:25.710408 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/public/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT3wAAAQ8"]
[Thu Sep 17 15:08:25.931039 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:53764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status413.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT5AAAAX8"]
[Thu Sep 17 15:08:25.931141 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:53764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status413.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT5AAAAX8"]
[Thu Sep 17 15:08:25.980954 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.188.156:39876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT5gAAAUU"]
[Thu Sep 17 15:08:26.042307 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT4wAAAUs"]
[Thu Sep 17 15:08:26.062343 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT5wAAATc"]
[Thu Sep 17 15:08:26.098197 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.190.5:56064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT6wAAAUo"]
[Thu Sep 17 15:08:26.144462 2026] [security2:error] [pid 955873:tid 956127] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/backend/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT7gAAAYY"]
[Thu Sep 17 15:08:26.224938 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:53770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status414.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT8QAAAYI"]
[Thu Sep 17 15:08:26.225048 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:53770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status414.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT8QAAAYI"]
[Thu Sep 17 15:08:26.257681 2026] [security2:error] [pid 955873:tid 956113] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/server/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT8wAAAXg"]
[Thu Sep 17 15:08:26.338631 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/frontend/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT9QAAARE"]
[Thu Sep 17 15:08:26.371387 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT9gAAATs"]
[Thu Sep 17 15:08:26.422012 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/src/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT-QAAAYg"]
[Thu Sep 17 15:08:26.422499 2026] [security2:error] [pid 955873:tid 956089] [client 186.105.232.15:57791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT-gAAAWA"]
[Thu Sep 17 15:08:26.422604 2026] [security2:error] [pid 955873:tid 956089] [client 186.105.232.15:57791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT-gAAAWA"]
[Thu Sep 17 15:08:26.455597 2026] [security2:error] [pid 955873:tid 956114] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT7AABeVQ"], referer: http://eco-tech.vn/new/
[Thu Sep 17 15:08:26.483182 2026] [security2:error] [pid 955873:tid 956013] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/core/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT_AAAARQ"]
[Thu Sep 17 15:08:26.486891 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.188.156:39882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/old/phpinfo.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT_QAAAV0"]
[Thu Sep 17 15:08:26.513385 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:53784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status415.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT_gAAAYk"]
[Thu Sep 17 15:08:26.513505 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:53784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status415.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT_gAAAYk"]
[Thu Sep 17 15:08:26.554259 2026] [security2:error] [pid 955873:tid 956125] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/core/app/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT_wAAAYQ"]
[Thu Sep 17 15:08:26.655358 2026] [security2:error] [pid 955873:tid 956049] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/config/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUAQAAATg"]
[Thu Sep 17 15:08:26.737589 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.195.25:54222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUBAAAASs"]
[Thu Sep 17 15:08:26.775871 2026] [security2:error] [pid 955873:tid 956006] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/private/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUBQAAAQ0"]
[Thu Sep 17 15:08:26.805162 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status416.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUBwAAAWQ"]
[Thu Sep 17 15:08:26.805328 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status416.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUBwAAAWQ"]
[Thu Sep 17 15:08:26.895285 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/application/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUCAAAAUA"]
[Thu Sep 17 15:08:26.983420 2026] [security2:error] [pid 955873:tid 956079] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/bootstrap/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUCQAAAVY"]
[Thu Sep 17 15:08:26.994082 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUCgAAATI"]
[Thu Sep 17 15:08:26.994891 2026] [security2:error] [pid 955873:tid 956058] [client 34.95.188.156:39894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUCwAAAUE"]
[Thu Sep 17 15:08:27.072758 2026] [security2:error] [pid 955873:tid 956045] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/database/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUDQAAATQ"]
[Thu Sep 17 15:08:27.100433 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status417.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUDgAAAVo"]
[Thu Sep 17 15:08:27.100560 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:53802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status417.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUDgAAAVo"]
[Thu Sep 17 15:08:27.133332 2026] [security2:error] [pid 955873:tid 956087] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/storage/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUEAAAAV4"]
[Thu Sep 17 15:08:27.209154 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/var/www/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUEQAAAQw"]
[Thu Sep 17 15:08:27.294960 2026] [security2:error] [pid 955873:tid 956060] [client 34.166.190.5:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWyxFTPRVSLOsRVhoUFQAAAUM"]
[Thu Sep 17 15:08:27.368361 2026] [security2:error] [pid 955873:tid 956106] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/var/www/html/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUGAAAAXE"]
[Thu Sep 17 15:08:27.369891 2026] [security2:error] [pid 955873:tid 955983] [remote 216.73.217.142:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWyxFTPRVSLOsRVhoUGQABdm0"]
[Thu Sep 17 15:08:27.395535 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUGgAAAT4"]
[Thu Sep 17 15:08:27.397719 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status418.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUGwAAAQs"]
[Thu Sep 17 15:08:27.397817 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:53808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status418.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUGwAAAQs"]
[Thu Sep 17 15:08:27.492243 2026] [security2:error] [pid 955873:tid 956042] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/current/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUHQAAATE"]
[Thu Sep 17 15:08:27.495189 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.188.156:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/public/phpinfo.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUHgAAAWs"]
[Thu Sep 17 15:08:27.558312 2026] [security2:error] [pid 955873:tid 956116] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUEwABe38"], referer: http://eco-tech.vn/old/
[Thu Sep 17 15:08:27.575962 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:56115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUIAAAAVA"]
[Thu Sep 17 15:08:27.576072 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:56115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUIAAAAVA"]
[Thu Sep 17 15:08:27.581465 2026] [security2:error] [pid 955873:tid 956011] [client 23.120.8.137:38047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUHwABEj0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821160102&hideanons=1&hidebots=0&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:27.584433 2026] [security2:error] [pid 955873:tid 956038] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/release/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUIQAAAS0"]
[Thu Sep 17 15:08:27.643834 2026] [security2:error] [pid 955873:tid 956029] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/releases/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUIgAAASQ"]
[Thu Sep 17 15:08:27.649175 2026] [security2:error] [pid 955873:tid 956008] [client 4.240.114.86:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUIwAAAQ8"], referer: binance.com
[Thu Sep 17 15:08:27.665637 2026] [security2:error] [pid 955873:tid 956047] [client 40.77.167.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUHAAAATY"]
[Thu Sep 17 15:08:27.686678 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status428.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUJAAAAU0"]
[Thu Sep 17 15:08:27.686760 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status428.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUJAAAAU0"]
[Thu Sep 17 15:08:27.711915 2026] [security2:error] [pid 955873:tid 956120] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/shared/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUJgAAAX8"]
[Thu Sep 17 15:08:27.798531 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/deploy/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUKAAAAUs"]
[Thu Sep 17 15:08:27.871940 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.195.25:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUKQAAAUU"]
[Thu Sep 17 15:08:27.916753 2026] [security2:error] [pid 955873:tid 956061] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/build/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUKgAAAUQ"]
[Thu Sep 17 15:08:27.969265 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status429.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUKwAAAUo"]
[Thu Sep 17 15:08:27.969359 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status429.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUKwAAAUo"]
[Thu Sep 17 15:08:27.985814 2026] [security2:error] [pid 955873:tid 956069] [client 34.166.190.5:56088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWyxFTPRVSLOsRVhoULAAAAUw"]
[Thu Sep 17 15:08:28.007138 2026] [security2:error] [pid 955873:tid 956127] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/dist/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoULgAAAYY"]
[Thu Sep 17 15:08:28.106356 2026] [security2:error] [pid 955873:tid 956109] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/public_html/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUNQAAAXQ"]
[Thu Sep 17 15:08:28.157011 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/htdocs/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUOAAAAYg"]
[Thu Sep 17 15:08:28.179230 2026] [security2:error] [pid 955873:tid 956114] [client 34.95.188.156:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/php-info.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUOQAAAXk"]
[Thu Sep 17 15:08:28.225023 2026] [security2:error] [pid 955873:tid 956082] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/www/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUOgAAAVk"]
[Thu Sep 17 15:08:28.247541 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUPAAAASE"]
[Thu Sep 17 15:08:28.251860 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status431.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUPQAAARQ"]
[Thu Sep 17 15:08:28.251958 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status431.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUPQAAARQ"]
[Thu Sep 17 15:08:28.311194 2026] [security2:error] [pid 955873:tid 956115] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/html/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUPgAAAXo"]
[Thu Sep 17 15:08:28.403051 2026] [security2:error] [pid 955873:tid 956117] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/live/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUQQAAAXw"]
[Thu Sep 17 15:08:28.471973 2026] [security2:error] [pid 955873:tid 956030] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUOwABJWA"], referer: http://eco-tech.vn/blog/
[Thu Sep 17 15:08:28.507255 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/prod/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoURQAAATA"]
[Thu Sep 17 15:08:28.533985 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status500.php"] [unique_id "aqxWzBFTPRVSLOsRVhoURgAAAX0"]
[Thu Sep 17 15:08:28.534064 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:53826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status500.php"] [unique_id "aqxWzBFTPRVSLOsRVhoURgAAAX0"]
[Thu Sep 17 15:08:28.578438 2026] [security2:error] [pid 955873:tid 956014] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/dev/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoURwAAARU"]
[Thu Sep 17 15:08:28.637966 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUSQAAATg"]
[Thu Sep 17 15:08:28.675506 2026] [security2:error] [pid 955873:tid 956081] [client 34.95.188.156:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpversion.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUSgAAAVg"]
[Thu Sep 17 15:08:28.679418 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.190.5:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUSwAAAV8"]
[Thu Sep 17 15:08:28.760273 2026] [security2:error] [pid 955873:tid 956093] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/staging/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUTAAAAWQ"]
[Thu Sep 17 15:08:28.822247 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status501.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTQAAAUA"]
[Thu Sep 17 15:08:28.822348 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:53842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status501.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTQAAAUA"]
[Thu Sep 17 15:08:28.847099 2026] [security2:error] [pid 955873:tid 956016] [client 45.169.98.18:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTgAAARc"]
[Thu Sep 17 15:08:28.847192 2026] [security2:error] [pid 955873:tid 956016] [client 45.169.98.18:61773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTgAAARc"]
[Thu Sep 17 15:08:28.858847 2026] [security2:error] [pid 955873:tid 956059] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/opt/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUTwAAAUI"]
[Thu Sep 17 15:08:28.901075 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUUgAAAXM"]
[Thu Sep 17 15:08:28.913263 2026] [security2:error] [pid 955873:tid 956017] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/laravel/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUVAAAARg"]
[Thu Sep 17 15:08:28.980631 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/symfony/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUVQAAAQw"]
[Thu Sep 17 15:08:29.106624 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:53846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status502.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUVgAAAXE"]
[Thu Sep 17 15:08:29.106727 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:53846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status502.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUVgAAAXE"]
[Thu Sep 17 15:08:29.159278 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.188.156:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/_phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUVwAAAUM"]
[Thu Sep 17 15:08:29.196371 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUWAAAAXY"]
[Thu Sep 17 15:08:29.315782 2026] [security2:error] [pid 955873:tid 956042] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/wordpress/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUXgAAATE"]
[Thu Sep 17 15:08:29.361841 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.190.5:56116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUYAAAAT4"]
[Thu Sep 17 15:08:29.386631 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/wp/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUYgAAATY"]
[Thu Sep 17 15:08:29.393120 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status503.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUYwAAAQ4"]
[Thu Sep 17 15:08:29.393207 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:53862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status503.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUYwAAAQ4"]
[Thu Sep 17 15:08:29.485568 2026] [security2:error] [pid 955873:tid 956051] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cms/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUZQAAATo"]
[Thu Sep 17 15:08:29.577454 2026] [security2:error] [pid 955873:tid 956021] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/drupal/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUZgAAARw"]
[Thu Sep 17 15:08:29.579158 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.195.25:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUZwAAAWc"]
[Thu Sep 17 15:08:29.653233 2026] [security2:error] [pid 955873:tid 956053] [client 34.95.188.156:39904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/old_phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUaAAAATw"]
[Thu Sep 17 15:08:29.678865 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status504.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUaQAAAWg"]
[Thu Sep 17 15:08:29.678958 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:53876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status504.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUaQAAAWg"]
[Thu Sep 17 15:08:29.688645 2026] [security2:error] [pid 955873:tid 956062] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/joomla/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUagAAAUU"]
[Thu Sep 17 15:08:29.774560 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/magento/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUawAAAUo"]
[Thu Sep 17 15:08:29.827732 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/shopify/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUbwAAASo"]
[Thu Sep 17 15:08:29.880981 2026] [security2:error] [pid 955873:tid 956071] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/prestashop/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUcgAAAU4"]
[Thu Sep 17 15:08:29.918903 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.195.25:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUdAAAAVE"]
[Thu Sep 17 15:08:29.959944 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:39508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status505.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUdQAAAS4"]
[Thu Sep 17 15:08:29.960055 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:39508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status505.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUdQAAAS4"]
[Thu Sep 17 15:08:29.973058 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/codeigniter/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUdgAAASw"]
[Thu Sep 17 15:08:30.021546 2026] [security2:error] [pid 955873:tid 956006] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cakephp/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUdwAAAQ0"]
[Thu Sep 17 15:08:30.057652 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.190.5:56120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUeAAAAXg"]
[Thu Sep 17 15:08:30.067768 2026] [security2:error] [pid 955873:tid 956129] [client 45.115.26.203:48800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUegAAAYg"]
[Thu Sep 17 15:08:30.133645 2026] [security2:error] [pid 955873:tid 956082] [client 45.115.26.203:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/i.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUhgAAAVk"]
[Thu Sep 17 15:08:30.133672 2026] [security2:error] [pid 955873:tid 956015] [client 45.115.26.203:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/php_info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUhwAAARY"]
[Thu Sep 17 15:08:30.134115 2026] [security2:error] [pid 955873:tid 956013] [client 45.115.26.203:48950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/app/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUggAAARQ"]
[Thu Sep 17 15:08:30.134801 2026] [security2:error] [pid 955873:tid 956086] [client 45.115.26.203:48956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.bak"] [unique_id "aqxWzhFTPRVSLOsRVhoUiQAAAV0"]
[Thu Sep 17 15:08:30.135813 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/zend/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUigAAAXI"]
[Thu Sep 17 15:08:30.136871 2026] [security2:error] [pid 955873:tid 956102] [client 45.115.26.203:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/php-info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUkgAAAW0"]
[Thu Sep 17 15:08:30.137570 2026] [security2:error] [pid 955873:tid 956030] [client 45.115.26.203:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/test.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUlAAAASU"]
[Thu Sep 17 15:08:30.138417 2026] [security2:error] [pid 955873:tid 956118] [client 45.115.26.203:48980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUlQAAAX0"]
[Thu Sep 17 15:08:30.138503 2026] [security2:error] [pid 955873:tid 956041] [client 45.115.26.203:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUlwAAATA"]
[Thu Sep 17 15:08:30.138917 2026] [security2:error] [pid 955873:tid 956101] [client 45.115.26.203:49054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.backup"] [unique_id "aqxWzhFTPRVSLOsRVhoUlgAAAWw"]
[Thu Sep 17 15:08:30.139183 2026] [security2:error] [pid 955873:tid 956072] [client 45.115.26.203:48994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/pi.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUnQAAAU8"]
[Thu Sep 17 15:08:30.147650 2026] [security2:error] [pid 955873:tid 956125] [client 45.115.26.203:49010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/api/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUoQAAAYQ"]
[Thu Sep 17 15:08:30.149645 2026] [security2:error] [pid 955873:tid 956084] [client 34.95.188.156:39916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/server-info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUpgAAAVs"]
[Thu Sep 17 15:08:30.151622 2026] [security2:error] [pid 955873:tid 956049] [client 45.115.26.203:48928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/src/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUqwAAATg"]
[Thu Sep 17 15:08:30.151957 2026] [security2:error] [pid 955873:tid 956105] [client 45.115.26.203:49024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env~"] [unique_id "aqxWzhFTPRVSLOsRVhoUrAAAAXA"]
[Thu Sep 17 15:08:30.152442 2026] [security2:error] [pid 955873:tid 956128] [client 45.115.26.203:48834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUrQAAAYc"]
[Thu Sep 17 15:08:30.185617 2026] [security2:error] [pid 955873:tid 956088] [client 45.115.26.203:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/_phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUswAAAV8"]
[Thu Sep 17 15:08:30.193324 2026] [security2:error] [pid 955873:tid 956073] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/yii/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUtAAAAVA"]
[Thu Sep 17 15:08:30.220657 2026] [security2:error] [pid 955873:tid 956029] [client 45.115.26.203:48800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.old"] [unique_id "aqxWzhFTPRVSLOsRVhoUvAAAASQ"]
[Thu Sep 17 15:08:30.221364 2026] [security2:error] [pid 955873:tid 956093] [client 45.115.26.203:49062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.swp"] [unique_id "aqxWzhFTPRVSLOsRVhoUvQAAAWQ"]
[Thu Sep 17 15:08:30.229006 2026] [security2:error] [pid 955873:tid 956059] [client 45.115.26.203:49076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/backend/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUwQAAAUI"]
[Thu Sep 17 15:08:30.242904 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status511.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUyQAAAWU"]
[Thu Sep 17 15:08:30.243043 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status511.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUyQAAAWU"]
[Thu Sep 17 15:08:30.296502 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/laravel5/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU0wAAASo"]
[Thu Sep 17 15:08:30.361280 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.195.25:54316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU1gAAAVk"]
[Thu Sep 17 15:08:30.388202 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/v1/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU2AAAAW0"]
[Thu Sep 17 15:08:30.404951 2026] [security2:error] [pid 955873:tid 956121] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUowAAAYA"]
[Thu Sep 17 15:08:30.410254 2026] [security2:error] [pid 955873:tid 956116] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUsgAAAXs"]
[Thu Sep 17 15:08:30.425003 2026] [security2:error] [pid 955873:tid 956024] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUuAAAAR8"]
[Thu Sep 17 15:08:30.449569 2026] [security2:error] [pid 955873:tid 956087] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUogAAAV4"]
[Thu Sep 17 15:08:30.524436 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/StatusUnknown.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU3QAAAWU"]
[Thu Sep 17 15:08:30.524541 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/StatusUnknown.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU3QAAAWU"]
[Thu Sep 17 15:08:30.533000 2026] [security2:error] [pid 955873:tid 956021] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/v2/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU3gAAARw"]
[Thu Sep 17 15:08:30.574398 2026] [access_compat:error] [pid 955873:tid 956117] [client 45.115.26.203:48936] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Thu Sep 17 15:08:30.633874 2026] [security2:error] [pid 955873:tid 956007] [client 34.95.188.156:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/server-status.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU4wAAAQ4"]
[Thu Sep 17 15:08:30.721768 2026] [security2:error] [pid 955873:tid 956009] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/v3/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU5gAAARA"]
[Thu Sep 17 15:08:30.729878 2026] [authz_core:error] [pid 955873:tid 956023] [client 20.244.34.24:51045] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:08:30.784955 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.195.25:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU5wAAAUk"]
[Thu Sep 17 15:08:30.800553 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:39526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/InvalidArgument.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6AAAAXg"]
[Thu Sep 17 15:08:30.800620 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:39526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/InvalidArgument.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6AAAAXg"]
[Thu Sep 17 15:08:30.810534 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.190.5:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6QAAAUI"]
[Thu Sep 17 15:08:30.814199 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/v1/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU6gAAARc"]
[Thu Sep 17 15:08:30.856168 2026] [security2:error] [pid 955873:tid 956096] [client 115.244.164.14:56166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6wAAAWc"]
[Thu Sep 17 15:08:30.856246 2026] [security2:error] [pid 955873:tid 956096] [client 115.244.164.14:56166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6wAAAWc"]
[Thu Sep 17 15:08:30.947439 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/v2/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU7gAAAXI"]
[Thu Sep 17 15:08:31.056843 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/rest/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU8QAAATA"]
[Thu Sep 17 15:08:31.072961 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:47512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU8wAAASU"]
[Thu Sep 17 15:08:31.078998 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU9QAAAWw"]
[Thu Sep 17 15:08:31.079080 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:39538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU9QAAAWw"]
[Thu Sep 17 15:08:31.251505 2026] [security2:error] [pid 955873:tid 956060] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/graphql/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU-AAAAUM"]
[Thu Sep 17 15:08:31.257864 2026] [security2:error] [pid 955873:tid 956011] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUugAAARI"]
[Thu Sep 17 15:08:31.275569 2026] [security2:error] [pid 955873:tid 956126] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUtQAAAYU"]
[Thu Sep 17 15:08:31.279750 2026] [security2:error] [pid 955873:tid 956003] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUvwAAAQo"]
[Thu Sep 17 15:08:31.294085 2026] [security2:error] [pid 955873:tid 956051] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUxwAAATo"]
[Thu Sep 17 15:08:31.298218 2026] [security2:error] [pid 955873:tid 956012] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUzQAAARM"]
[Thu Sep 17 15:08:31.301959 2026] [security2:error] [pid 955873:tid 956070] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUxQAAAU0"]
[Thu Sep 17 15:08:31.315704 2026] [security2:error] [pid 955873:tid 956104] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUxgAAAW8"]
[Thu Sep 17 15:08:31.320082 2026] [security2:error] [pid 955873:tid 956038] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUwwAAAS0"]
[Thu Sep 17 15:08:31.322830 2026] [security2:error] [pid 955873:tid 956064] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUywAAAUc"]
[Thu Sep 17 15:08:31.325572 2026] [security2:error] [pid 955873:tid 956111] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/gateway/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU-gAAAXY"]
[Thu Sep 17 15:08:31.325607 2026] [security2:error] [pid 955873:tid 956047] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUwgAAATY"]
[Thu Sep 17 15:08:31.326811 2026] [security2:error] [pid 955873:tid 956008] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUzAAAAQ8"]
[Thu Sep 17 15:08:31.372499 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "aqxWzxFTPRVSLOsRVhoU-wAAAWk"]
[Thu Sep 17 15:08:31.379863 2026] [security2:error] [pid 955873:tid 956062] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU0gAAAUU"]
[Thu Sep 17 15:08:31.383115 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.195.25:47524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU_QAAASg"]
[Thu Sep 17 15:08:31.398507 2026] [security2:error] [pid 955873:tid 956085] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU1QAAAVw"]
[Thu Sep 17 15:08:31.403503 2026] [security2:error] [pid 955873:tid 956031] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/microservice/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU_wAAASY"]
[Thu Sep 17 15:08:31.481239 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/service/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVAAAAARc"]
[Thu Sep 17 15:08:31.497049 2026] [security2:error] [pid 955873:tid 956101] [client 34.95.188.156:39938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWzxFTPRVSLOsRVhoVAQAAAWw"]
[Thu Sep 17 15:08:31.498394 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.190.5:56134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWzxFTPRVSLOsRVhoVAgAAATk"]
[Thu Sep 17 15:08:31.599494 2026] [security2:error] [pid 955873:tid 956060] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/v3/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVEwAAAUM"]
[Thu Sep 17 15:08:31.653509 2026] [security2:error] [pid 955873:tid 956105] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/dev/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVFAAAAXA"]
[Thu Sep 17 15:08:31.713267 2026] [security2:error] [pid 955873:tid 956087] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/staging/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVFgAAAV4"]
[Thu Sep 17 15:08:31.727764 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:47538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWzxFTPRVSLOsRVhoVFwAAAXM"]
[Thu Sep 17 15:08:31.780600 2026] [security2:error] [pid 955873:tid 956029] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/vendor/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVGAAAASQ"]
[Thu Sep 17 15:08:31.819696 2026] [authz_core:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Exception/Transport/error_log
[Thu Sep 17 15:08:31.821803 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "aqxWzxFTPRVSLOsRVhoVGQAAAUE"]
[Thu Sep 17 15:08:31.878424 2026] [core:error] [pid 955873:tid 956032] [client 173.252.70.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:31.878446 2026] [core:error] [pid 955873:tid 956032] [client 173.252.70.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:31.944451 2026] [security2:error] [pid 955873:tid 956040] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/lib/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVJAAAAS8"]
[Thu Sep 17 15:08:31.962244 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/wp-includes/Requests/src/Exception/"] [unique_id "aqxWzxFTPRVSLOsRVhoVJgAAAUs"]
[Thu Sep 17 15:08:31.983524 2026] [security2:error] [pid 955873:tid 956005] [client 162.62.213.165:35108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.213.62.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzxFTPRVSLOsRVhoVIwAAAQw"]
[Thu Sep 17 15:08:31.999100 2026] [security2:error] [pid 955873:tid 956104] [client 34.95.188.156:39952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxWzxFTPRVSLOsRVhoVJwAAAW8"]
[Thu Sep 17 15:08:32.029419 2026] [security2:error] [pid 955873:tid 956025] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/resources/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVKAAAASA"]
[Thu Sep 17 15:08:32.116833 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/assets/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVKwAAAUo"]
[Thu Sep 17 15:08:32.181546 2026] [security2:error] [pid 955873:tid 956046] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/uploads/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVLAAAATU"]
[Thu Sep 17 15:08:32.197193 2026] [security2:error] [pid 955873:tid 956111] [client 34.166.190.5:56138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxW0BFTPRVSLOsRVhoVLQAAAXY"]
[Thu Sep 17 15:08:32.227586 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:47540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVLgAAAQ8"]
[Thu Sep 17 15:08:32.274281 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/internal/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVMAAAAX4"]
[Thu Sep 17 15:08:32.309523 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVKgAAAUQ"]
[Thu Sep 17 15:08:32.309552 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVKgAAAUQ"]
[Thu Sep 17 15:08:32.373054 2026] [security2:error] [pid 955873:tid 956074] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/tools/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVMQAAAVE"]
[Thu Sep 17 15:08:32.422974 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVMgAAATc"]
[Thu Sep 17 15:08:32.423068 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVMgAAATc"]
[Thu Sep 17 15:08:32.482905 2026] [security2:error] [pid 955873:tid 956006] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/scripts/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVNQAAAQ0"]
[Thu Sep 17 15:08:32.495573 2026] [security2:error] [pid 955873:tid 956054] [client 34.95.188.156:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVNwAAAT0"]
[Thu Sep 17 15:08:32.535504 2026] [security2:error] [pid 955873:tid 956023] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/bin/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVOgAAAR4"]
[Thu Sep 17 15:08:32.617335 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:39544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/Curl.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVQQAAATQ"]
[Thu Sep 17 15:08:32.617475 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/Curl.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVQQAAATQ"]
[Thu Sep 17 15:08:32.668499 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sbin/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVRAAAAW0"]
[Thu Sep 17 15:08:32.728929 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/local/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVRwAAAWA"]
[Thu Sep 17 15:08:32.799368 2026] [security2:error] [pid 955873:tid 956011] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/portal/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVSQAAARI"]
[Thu Sep 17 15:08:32.842651 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxW0BFTPRVSLOsRVhoVSgAAASw"]
[Thu Sep 17 15:08:32.882350 2026] [security2:error] [pid 955873:tid 956125] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/dashboard/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVSwAAAYQ"]
[Thu Sep 17 15:08:32.896341 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.190.5:56148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxW0BFTPRVSLOsRVhoVTQAAAXI"]
[Thu Sep 17 15:08:32.899967 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/HookManager.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVTgAAAXM"]
[Thu Sep 17 15:08:32.900074 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:39560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/HookManager.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVTgAAAXM"]
[Thu Sep 17 15:08:32.988264 2026] [security2:error] [pid 955873:tid 956055] [client 4.240.114.86:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVUwAAAT4"], referer: binance.com
[Thu Sep 17 15:08:32.989844 2026] [security2:error] [pid 955873:tid 956114] [client 34.95.188.156:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVVAAAAXk"]
[Thu Sep 17 15:08:33.021204 2026] [security2:error] [pid 955873:tid 956084] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/panel/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVVQAAAVs"]
[Thu Sep 17 15:08:33.108787 2026] [security2:error] [pid 955873:tid 956032] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/crm/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVVwAAASc"]
[Thu Sep 17 15:08:33.162737 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:47554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVWQAAAYc"]
[Thu Sep 17 15:08:33.208204 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:39568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Hooks.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVWwAAAWY"]
[Thu Sep 17 15:08:33.208299 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:39568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Hooks.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVWwAAAWY"]
[Thu Sep 17 15:08:33.227683 2026] [security2:error] [pid 955873:tid 956019] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/erp/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVXAAAARo"]
[Thu Sep 17 15:08:33.301362 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/shop/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVXQAAAUs"]
[Thu Sep 17 15:08:33.366101 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/store/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVXgAAAUo"]
[Thu Sep 17 15:08:33.474195 2026] [security2:error] [pid 955873:tid 956007] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/saas/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVYgAAAQ4"]
[Thu Sep 17 15:08:33.496391 2026] [security2:error] [pid 955873:tid 956104] [client 34.95.188.156:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVYwAAAW8"]
[Thu Sep 17 15:08:33.503961 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/IdnaEncoder.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVZAAAAWU"]
[Thu Sep 17 15:08:33.504025 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/IdnaEncoder.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVZAAAAWU"]
[Thu Sep 17 15:08:33.514779 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:47568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVZQAAAQ8"]
[Thu Sep 17 15:08:33.565085 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/client/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVZwAAAX4"]
[Thu Sep 17 15:08:33.602190 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.190.5:48094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxW0RFTPRVSLOsRVhoVaQAAAVM"]
[Thu Sep 17 15:08:33.684807 2026] [security2:error] [pid 955873:tid 956061] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/project/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVagAAAUQ"]
[Thu Sep 17 15:08:33.798504 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ipv6.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVbAAAATI"]
[Thu Sep 17 15:08:33.798580 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:39588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ipv6.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVbAAAATI"]
[Thu Sep 17 15:08:33.878494 2026] [security2:error] [pid 955873:tid 956048] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/admin-panel/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVbQAAATc"]
[Thu Sep 17 15:08:33.926493 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:47570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVbgAAAWk"]
[Thu Sep 17 15:08:33.953384 2026] [security2:error] [pid 955873:tid 956031] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/control-panel/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVbwAAASY"]
[Thu Sep 17 15:08:34.005993 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.188.156:32884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVcgAAAUU"]
[Thu Sep 17 15:08:34.013738 2026] [security2:error] [pid 955873:tid 956109] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/user-panel/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVcwAAAXQ"]
[Thu Sep 17 15:08:34.088114 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:39604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Iri.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVdQAAAX8"]
[Thu Sep 17 15:08:34.088199 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:39604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Iri.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVdQAAAX8"]
[Thu Sep 17 15:08:34.119206 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/node/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVdgAAAYg"]
[Thu Sep 17 15:08:34.233188 2026] [security2:error] [pid 955873:tid 956009] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/express/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVdwAAARA"]
[Thu Sep 17 15:08:34.250481 2026] [autoindex:error] [pid 955873:tid 956066] [client 169.58.43.159:59256] AH01276: Cannot serve directory /home1/kolindco/public_html/t2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:08:34.300481 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.190.5:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxW0hFTPRVSLOsRVhoVegAAASs"]
[Thu Sep 17 15:08:34.340926 2026] [security2:error] [pid 955873:tid 956112] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/next/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVewAAAXc"]
[Thu Sep 17 15:08:34.351128 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.195.25:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVfAAAAVg"]
[Thu Sep 17 15:08:34.385213 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Port.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVfQAAAUM"]
[Thu Sep 17 15:08:34.385283 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Port.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVfQAAAUM"]
[Thu Sep 17 15:08:34.421916 2026] [security2:error] [pid 955873:tid 956028] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/nuxt/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVfgAAASM"]
[Thu Sep 17 15:08:34.513026 2026] [security2:error] [pid 955873:tid 956078] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/nest/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVfwAAAVU"]
[Thu Sep 17 15:08:34.525103 2026] [security2:error] [pid 955873:tid 956089] [client 34.95.188.156:32888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxW0hFTPRVSLOsRVhoVggAAAWA"]
[Thu Sep 17 15:08:34.577471 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/react/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVgwAAAXI"]
[Thu Sep 17 15:08:34.671855 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVhgAAASQ"]
[Thu Sep 17 15:08:34.671943 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:39616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVhgAAASQ"]
[Thu Sep 17 15:08:34.701756 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:47592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxW0hFTPRVSLOsRVhoViQAAATo"]
[Thu Sep 17 15:08:34.773520 2026] [security2:error] [pid 955873:tid 956118] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/vue/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVigAAAX0"]
[Thu Sep 17 15:08:34.863050 2026] [security2:error] [pid 955873:tid 956012] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/angular/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVjAAAARM"]
[Thu Sep 17 15:08:34.913022 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxW0hFTPRVSLOsRVhoVjQAAASc"]
[Thu Sep 17 15:08:34.919704 2026] [security2:error] [pid 955873:tid 956128] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/svelte/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVjgAAAYc"]
[Thu Sep 17 15:08:34.974143 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/"] [unique_id "aqxW0hFTPRVSLOsRVhoVkgAAAXU"]
[Thu Sep 17 15:08:34.976321 2026] [security2:error] [pid 955873:tid 956095] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/vite/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVkwAAAWY"]
[Thu Sep 17 15:08:35.002394 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.190.5:48112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVlgAAAUE"]
[Thu Sep 17 15:08:35.038796 2026] [security2:error] [pid 955873:tid 956057] [client 34.95.188.156:32900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php.old"] [unique_id "aqxW0xFTPRVSLOsRVhoVlwAAAUA"]
[Thu Sep 17 15:08:35.051043 2026] [security2:error] [pid 955873:tid 956040] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/backup/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVmAAAAS8"]
[Thu Sep 17 15:08:35.133425 2026] [authz_core:error] [pid 955873:tid 956101] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Proxy/error_log
[Thu Sep 17 15:08:35.134690 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/"] [unique_id "aqxW0xFTPRVSLOsRVhoVmQAAAWw"]
[Thu Sep 17 15:08:35.157139 2026] [security2:error] [pid 955873:tid 956103] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/backups/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVmgAAAW4"]
[Thu Sep 17 15:08:35.170777 2026] [security2:error] [pid 955873:tid 956004] [client 192.178.6.3:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVmwAAAQs"]
[Thu Sep 17 15:08:35.225963 2026] [security2:error] [pid 955873:tid 956094] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/old/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVnQAAAWU"]
[Thu Sep 17 15:08:35.284359 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/wp-includes/Requests/src/"] [unique_id "aqxW0xFTPRVSLOsRVhoVoAAAAVM"]
[Thu Sep 17 15:08:35.304559 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxW0xFTPRVSLOsRVhoVoQAAAV0"]
[Thu Sep 17 15:08:35.347096 2026] [security2:error] [pid 955873:tid 956061] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/tmp/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVogAAAUQ"]
[Thu Sep 17 15:08:35.476415 2026] [security2:error] [pid 955873:tid 956049] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/temp/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVpgAAATg"]
[Thu Sep 17 15:08:35.534762 2026] [security2:error] [pid 955873:tid 956085] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/lab/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVrAAAAVw"]
[Thu Sep 17 15:08:35.541375 2026] [security2:error] [pid 955873:tid 956071] [client 34.95.188.156:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php~"] [unique_id "aqxW0xFTPRVSLOsRVhoVrQAAAU4"]
[Thu Sep 17 15:08:35.604469 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxW0xFTPRVSLOsRVhoVsAAAAWk"]
[Thu Sep 17 15:08:35.631690 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVpQAAAVE"]
[Thu Sep 17 15:08:35.631717 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVpQAAAVE"]
[Thu Sep 17 15:08:35.649222 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cronlab/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVsQAAASo"]
[Thu Sep 17 15:08:35.649504 2026] [security2:error] [pid 955873:tid 955881] [remote 47.128.111.227:29896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.comicsutra.com"] [uri "/robots.txt"] [unique_id "aqxW0xFTPRVSLOsRVhoVsgABPQc"]
[Thu Sep 17 15:08:35.698632 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.190.5:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVtAAAATI"]
[Thu Sep 17 15:08:35.752899 2026] [security2:error] [pid 955873:tid 956100] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cron/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVtQAAAWs"]
[Thu Sep 17 15:08:35.772946 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/Http.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVtgAAASI"]
[Thu Sep 17 15:08:35.773057 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/Http.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVtgAAASI"]
[Thu Sep 17 15:08:35.816251 2026] [security2:error] [pid 955873:tid 956124] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/en/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVtwAAAYM"]
[Thu Sep 17 15:08:35.905652 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxW0xFTPRVSLOsRVhoVuQAAAQ0"]
[Thu Sep 17 15:08:35.954502 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/administrator/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVuAAAATA"]
[Thu Sep 17 15:08:36.007099 2026] [security2:error] [pid 955873:tid 956105] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/psnlink/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoVvQAAAXA"]
[Thu Sep 17 15:08:36.034883 2026] [security2:error] [pid 955873:tid 956009] [client 34.95.188.156:32930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/info.php.bak"] [unique_id "aqxW1BFTPRVSLOsRVhoVvwAAARA"]
[Thu Sep 17 15:08:36.062765 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/exapi/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoVwAAAASw"]
[Thu Sep 17 15:08:36.065507 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:39628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Requests.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVwQAAAWA"]
[Thu Sep 17 15:08:36.065581 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:39628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Requests.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVwQAAAWA"]
[Thu Sep 17 15:08:36.155474 2026] [security2:error] [pid 955873:tid 956113] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sitemaps/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoVwgAAAXg"]
[Thu Sep 17 15:08:36.212249 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxW1BFTPRVSLOsRVhoVwwAAAXI"]
[Thu Sep 17 15:08:36.358963 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:39642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVygAAAW0"]
[Thu Sep 17 15:08:36.359057 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:39642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVygAAAW0"]
[Thu Sep 17 15:08:36.411433 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.190.5:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVywAAASQ"]
[Thu Sep 17 15:08:36.505004 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxW1BFTPRVSLOsRVhoV0AAAASc"]
[Thu Sep 17 15:08:36.538870 2026] [security2:error] [pid 955873:tid 956042] [client 34.95.188.156:32944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php.save"] [unique_id "aqxW1BFTPRVSLOsRVhoV0QAAATE"]
[Thu Sep 17 15:08:36.557568 2026] [security2:error] [pid 955873:tid 956106] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVyQAAAXE"]
[Thu Sep 17 15:08:36.659314 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/"] [unique_id "aqxW1BFTPRVSLOsRVhoV0gAAAUs"]
[Thu Sep 17 15:08:36.757215 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:47672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxW1BFTPRVSLOsRVhoV1gAAAWw"]
[Thu Sep 17 15:08:36.815194 2026] [authz_core:error] [pid 955873:tid 956096] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Response/error_log
[Thu Sep 17 15:08:36.816024 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/"] [unique_id "aqxW1BFTPRVSLOsRVhoV2gAAAWc"]
[Thu Sep 17 15:08:36.937296 2026] [security2:error] [pid 955873:tid 956013] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW1BFTPRVSLOsRVhoV1QAAARQ"]
[Thu Sep 17 15:08:36.960165 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:39652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/wp-includes/Requests/src/"] [unique_id "aqxW1BFTPRVSLOsRVhoV2wAAAW8"]
[Thu Sep 17 15:08:36.995531 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/logs/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoV3AAAAQ8"]
[Thu Sep 17 15:08:37.027094 2026] [security2:error] [pid 955873:tid 956077] [client 4.240.114.86:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV4AAAAVQ"], referer: binance.com
[Thu Sep 17 15:08:37.035405 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:47678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV4QAAAWU"]
[Thu Sep 17 15:08:37.038546 2026] [security2:error] [pid 955873:tid 956067] [client 34.95.188.156:32958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV4gAAAUo"]
[Thu Sep 17 15:08:37.105412 2026] [security2:error] [pid 955873:tid 956127] [client 186.105.232.15:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5AAAAYY"]
[Thu Sep 17 15:08:37.105598 2026] [security2:error] [pid 955873:tid 956127] [client 186.105.232.15:58398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5AAAAYY"]
[Thu Sep 17 15:08:37.114453 2026] [security2:error] [pid 955873:tid 956015] [client 34.166.190.5:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5QAAARY"]
[Thu Sep 17 15:08:37.160092 2026] [security2:error] [pid 955873:tid 956014] [client 134.185.85.61:51231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxW1RFTPRVSLOsRVhoV5wAAARU"]
[Thu Sep 17 15:08:37.231841 2026] [security2:error] [pid 955873:tid 956020] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cache/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV6gAAARs"]
[Thu Sep 17 15:08:37.288207 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.195.25:47694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV6wAAAU4"]
[Thu Sep 17 15:08:37.326408 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5gAAAWM"]
[Thu Sep 17 15:08:37.326440 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5gAAAWM"]
[Thu Sep 17 15:08:37.341026 2026] [security2:error] [pid 955873:tid 956059] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailer/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV7AAAAUI"]
[Thu Sep 17 15:08:37.430081 2026] [security2:error] [pid 955873:tid 956045] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mail/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV8AAAATQ"]
[Thu Sep 17 15:08:37.479414 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:39652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/Headers.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV8gAAARc"]
[Thu Sep 17 15:08:37.479524 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:39652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/Headers.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV8gAAARc"]
[Thu Sep 17 15:08:37.489423 2026] [security2:error] [pid 955873:tid 956019] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/email/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV8wAAARo"]
[Thu Sep 17 15:08:37.533871 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:47706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV9AAAASE"]
[Thu Sep 17 15:08:37.537470 2026] [security2:error] [pid 955873:tid 956006] [client 134.185.85.61:58119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.com"] [uri "/media/system/js/core.js"] [unique_id "aqxW1RFTPRVSLOsRVhoV9QAAAQ0"]
[Thu Sep 17 15:08:37.540869 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.188.156:32966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV9gAAAWs"]
[Thu Sep 17 15:08:37.621178 2026] [security2:error] [pid 955873:tid 956063] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/smtp/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV-AAAAUY"]
[Thu Sep 17 15:08:37.692002 2026] [security2:error] [pid 955873:tid 956031] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailing/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV-QAAASY"]
[Thu Sep 17 15:08:37.754111 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:39660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Session.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_AAAATc"]
[Thu Sep 17 15:08:37.754171 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:39660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Session.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_AAAATc"]
[Thu Sep 17 15:08:37.772317 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/notifications/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV_QAAAWA"]
[Thu Sep 17 15:08:37.796081 2026] [security2:error] [pid 955873:tid 956066] [client 34.166.190.5:48148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_wAAAUk"]
[Thu Sep 17 15:08:37.861571 2026] [security2:error] [pid 955873:tid 956081] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/notify/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoWAgAAAVg"]
[Thu Sep 17 15:08:37.875046 2026] [security2:error] [pid 955873:tid 956087] [client 186.189.85.137:41528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_gABXgA"]
[Thu Sep 17 15:08:37.879107 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoWAwAAAVU"]
[Thu Sep 17 15:08:37.935088 2026] [security2:error] [pid 955873:tid 956130] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sender/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoWBQAAAYk"]
[Thu Sep 17 15:08:37.999946 2026] [security2:error] [pid 955873:tid 956122] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/campaign/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoWBwAAAYE"]
[Thu Sep 17 15:08:38.025994 2026] [security2:error] [pid 955873:tid 956018] [client 34.95.188.156:32972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWCAAAARk"]
[Thu Sep 17 15:08:38.029491 2026] [security2:error] [pid 955873:tid 956055] [client 114.119.140.115:61437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tab-funkenwerk.com"] [uri "/id79.html"] [unique_id "aqxW1hFTPRVSLOsRVhoWCQAAAT4"], referer: https://www.diyaudio.com/community/threads/john-curls-blowtorch-preamplifier-part-iii.318975/post-5601815
[Thu Sep 17 15:08:38.054373 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ssl.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWCgAAAUM"]
[Thu Sep 17 15:08:38.054457 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ssl.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWCgAAAUM"]
[Thu Sep 17 15:08:38.083392 2026] [security2:error] [pid 955873:tid 956072] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/newsletter/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWCwAAAU8"]
[Thu Sep 17 15:08:38.181122 2026] [security2:error] [pid 955873:tid 956012] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/ses/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWDAAAARM"]
[Thu Sep 17 15:08:38.187169 2026] [security2:error] [pid 955873:tid 956038] [client 185.55.149.49:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWDQAAAS0"]
[Thu Sep 17 15:08:38.187253 2026] [security2:error] [pid 955873:tid 956038] [client 185.55.149.49:56979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWDQAAAS0"]
[Thu Sep 17 15:08:38.268633 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.195.25:47718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWEQAAAW0"]
[Thu Sep 17 15:08:38.269554 2026] [security2:error] [pid 955873:tid 956108] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sendgrid/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWEgAAAXM"]
[Thu Sep 17 15:08:38.356116 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sparkpost/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWFAAAATY"]
[Thu Sep 17 15:08:38.362107 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWFQAAAUs"]
[Thu Sep 17 15:08:38.362202 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWFQAAAUs"]
[Thu Sep 17 15:08:38.440591 2026] [security2:error] [pid 955873:tid 956096] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/postmark/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWGAAAAWc"]
[Thu Sep 17 15:08:38.497384 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.190.5:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWGwAAARg"]
[Thu Sep 17 15:08:38.515516 2026] [security2:error] [pid 955873:tid 956040] [client 34.95.188.156:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWHAAAAS8"]
[Thu Sep 17 15:08:38.585089 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWHQAAARQ"]
[Thu Sep 17 15:08:38.609691 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailgun/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWHgAAAQ8"]
[Thu Sep 17 15:08:38.667515 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/"] [unique_id "aqxW1hFTPRVSLOsRVhoWIgAAAWU"]
[Thu Sep 17 15:08:38.738792 2026] [security2:error] [pid 955873:tid 956049] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mandrill/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWJQAAATg"]
[Thu Sep 17 15:08:38.818084 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailjet/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWKAAAARE"]
[Thu Sep 17 15:08:38.819775 2026] [authz_core:error] [pid 955873:tid 956035] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Transport/error_log
[Thu Sep 17 15:08:38.821220 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/"] [unique_id "aqxW1hFTPRVSLOsRVhoWJwAAASo"]
[Thu Sep 17 15:08:38.889299 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:47734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWLAAAAT0"]
[Thu Sep 17 15:08:38.939490 2026] [security2:error] [pid 955873:tid 956033] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/brevo/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWLQAAASg"]
[Thu Sep 17 15:08:38.958087 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:39704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/wp-includes/Requests/src/"] [unique_id "aqxW1hFTPRVSLOsRVhoWLgAAAX8"]
[Thu Sep 17 15:08:39.009149 2026] [security2:error] [pid 955873:tid 956023] [client 34.95.188.156:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWLwAAAR4"]
[Thu Sep 17 15:08:39.039027 2026] [security2:error] [pid 955873:tid 956059] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/transactional/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWMAAAAUI"]
[Thu Sep 17 15:08:39.117501 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.195.25:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWMQAAAYg"]
[Thu Sep 17 15:08:39.127265 2026] [security2:error] [pid 955873:tid 956019] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/bulk/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWMwAAARo"]
[Thu Sep 17 15:08:39.200373 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.190.5:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWNAAAAWM"]
[Thu Sep 17 15:08:39.205146 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/aws/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWNQAAATA"]
[Thu Sep 17 15:08:39.311147 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWMgAAARc"]
[Thu Sep 17 15:08:39.311172 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWMgAAARc"]
[Thu Sep 17 15:08:39.317188 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWNgAAAQ0"]
[Thu Sep 17 15:08:39.317268 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:62575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWNgAAAQ0"]
[Thu Sep 17 15:08:39.348477 2026] [security2:error] [pid 955873:tid 956082] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/azure/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWOAAAAVk"]
[Thu Sep 17 15:08:39.392435 2026] [security2:error] [pid 955873:tid 956084] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/gcp/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWOwAAAVs"]
[Thu Sep 17 15:08:39.427089 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.195.25:47754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWPwAAAUY"]
[Thu Sep 17 15:08:39.448050 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:39704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Curl.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWQAAAAQo"]
[Thu Sep 17 15:08:39.448127 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:39704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Curl.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWQAAAAQo"]
[Thu Sep 17 15:08:39.502128 2026] [security2:error] [pid 955873:tid 956126] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cloud/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWQgAAAYU"]
[Thu Sep 17 15:08:39.520108 2026] [security2:error] [pid 955873:tid 956050] [client 34.95.188.156:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/www/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWRAAAATk"]
[Thu Sep 17 15:08:39.572654 2026] [security2:error] [pid 955873:tid 956081] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/infrastructure/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWRQAAAVg"]
[Thu Sep 17 15:08:39.663840 2026] [security2:error] [pid 955873:tid 956114] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/docker/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWRgAAAXk"]
[Thu Sep 17 15:08:39.714017 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWRwAAAXc"]
[Thu Sep 17 15:08:39.732502 2026] [security2:error] [pid 955873:tid 956030] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/k8s/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWSAAAASU"]
[Thu Sep 17 15:08:39.758817 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:39708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Fsockopen.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWSQAAAYE"]
[Thu Sep 17 15:08:39.758922 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:39708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Fsockopen.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWSQAAAYE"]
[Thu Sep 17 15:08:39.799082 2026] [security2:error] [pid 955873:tid 956055] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/kubernetes/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWTAAAAT4"]
[Thu Sep 17 15:08:39.905453 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.190.5:48160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWTwAAASs"]
[Thu Sep 17 15:08:39.911682 2026] [security2:error] [pid 955873:tid 956097] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/terraform/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWUAAAAWg"]
[Thu Sep 17 15:08:40.007244 2026] [security2:error] [pid 955873:tid 956108] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/ansible/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWUwAAAXM"]
[Thu Sep 17 15:08:40.009939 2026] [security2:error] [pid 955873:tid 956113] [client 34.95.188.156:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWVAAAAXg"]
[Thu Sep 17 15:08:40.050899 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "aqxW2BFTPRVSLOsRVhoWVQAAATY"]
[Thu Sep 17 15:08:40.064562 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.195.25:47778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWVgAAAXE"]
[Thu Sep 17 15:08:40.083876 2026] [security2:error] [pid 955873:tid 956004] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.git/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWWAAAAQs"]
[Thu Sep 17 15:08:40.169406 2026] [security2:error] [pid 955873:tid 956091] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/ci/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWWQAAAWI"]
[Thu Sep 17 15:08:40.204825 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "aqxW2BFTPRVSLOsRVhoWWgAAAUA"]
[Thu Sep 17 15:08:40.285795 2026] [security2:error] [pid 955873:tid 956088] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cd/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWXQAAAV8"]
[Thu Sep 17 15:08:40.342599 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/wp-includes/Requests/src/"] [unique_id "aqxW2BFTPRVSLOsRVhoWYAAAAS8"]
[Thu Sep 17 15:08:40.350559 2026] [security2:error] [pid 955873:tid 956025] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/jenkins/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWYQAAASA"]
[Thu Sep 17 15:08:40.399644 2026] [security2:error] [pid 955873:tid 956077] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/gitlab/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWZAAAAVQ"]
[Thu Sep 17 15:08:40.428063 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:47790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWZwAAAQ8"]
[Thu Sep 17 15:08:40.491590 2026] [security2:error] [pid 955873:tid 956127] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/github/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWawAAAYY"]
[Thu Sep 17 15:08:40.497056 2026] [security2:error] [pid 955873:tid 956007] [client 34.95.188.156:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWbAAAAQ4"]
[Thu Sep 17 15:08:40.524809 2026] [security2:error] [pid 955873:tid 956117] [client 45.234.11.65:12969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWZQABfDU"]
[Thu Sep 17 15:08:40.567165 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/actions/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWbwAAAT0"]
[Thu Sep 17 15:08:40.587345 2026] [security2:error] [pid 955873:tid 956013] [client 34.166.190.5:48168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWcAAAARQ"]
[Thu Sep 17 15:08:40.621822 2026] [security2:error] [pid 955873:tid 956039] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/circleci/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWcwAAAS4"]
[Thu Sep 17 15:08:40.685444 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWagAAARw"]
[Thu Sep 17 15:08:40.685466 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWagAAARw"]
[Thu Sep 17 15:08:40.698101 2026] [security2:error] [pid 955873:tid 956092] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/travis/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWdgAAAWM"]
[Thu Sep 17 15:08:40.784061 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/buildkite/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWeQAAARc"]
[Thu Sep 17 15:08:40.832574 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:33910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/CaseInsensitiveDictionary.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWfQAAATc"]
[Thu Sep 17 15:08:40.832653 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/CaseInsensitiveDictionary.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWfQAAATc"]
[Thu Sep 17 15:08:40.837628 2026] [security2:error] [pid 955873:tid 956065] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mysql/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWfgAAAUg"]
[Thu Sep 17 15:08:40.950990 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/postgres/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWggAAAQw"]
[Thu Sep 17 15:08:40.988194 2026] [security2:error] [pid 955873:tid 956084] [client 34.95.188.156:33002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/site/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWhAAAAVs"]
[Thu Sep 17 15:08:41.092607 2026] [security2:error] [pid 955873:tid 956078] [client 4.240.114.86:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWhQAAAVU"], referer: binance.com
[Thu Sep 17 15:08:41.126032 2026] [security2:error] [pid 955873:tid 956051] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mongodb/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWhwAAATo"]
[Thu Sep 17 15:08:41.127710 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/FilteredIterator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWiAAAAXc"]
[Thu Sep 17 15:08:41.127783 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:33918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/FilteredIterator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWiAAAAXc"]
[Thu Sep 17 15:08:41.187868 2026] [security2:error] [pid 955873:tid 956018] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/redis/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWigAAARk"]
[Thu Sep 17 15:08:41.272513 2026] [security2:error] [pid 955873:tid 956089] [client 34.166.190.5:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWjAAAAWA"]
[Thu Sep 17 15:08:41.297028 2026] [security2:error] [pid 955873:tid 956072] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/elasticsearch/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWjgAAAU8"]
[Thu Sep 17 15:08:41.377893 2026] [security2:error] [pid 955873:tid 956038] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/rabbitmq/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWkwAAAS0"]
[Thu Sep 17 15:08:41.403748 2026] [security2:error] [pid 955873:tid 956031] [client 115.244.164.14:56794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlAAAASY"]
[Thu Sep 17 15:08:41.403855 2026] [security2:error] [pid 955873:tid 956031] [client 115.244.164.14:56794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlAAAASY"]
[Thu Sep 17 15:08:41.418885 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/InputValidator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlQAAAWg"]
[Thu Sep 17 15:08:41.418984 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/InputValidator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlQAAAWg"]
[Thu Sep 17 15:08:41.441790 2026] [security2:error] [pid 955873:tid 956058] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/kafka/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWlgAAAUE"]
[Thu Sep 17 15:08:41.475755 2026] [security2:error] [pid 955873:tid 956130] [client 34.95.188.156:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWmAAAAYk"]
[Thu Sep 17 15:08:41.526270 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/queue/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWmgAAATY"]
[Thu Sep 17 15:08:41.595326 2026] [security2:error] [pid 955873:tid 956004] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/worker/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWnAAAAQs"]
[Thu Sep 17 15:08:41.666789 2026] [security2:error] [pid 955873:tid 956096] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/job/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWnwAAAWc"]
[Thu Sep 17 15:08:41.701604 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:33928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxW2RFTPRVSLOsRVhoWowAAAV4"]
[Thu Sep 17 15:08:41.731210 2026] [security2:error] [pid 955873:tid 956052] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/test/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWpgAAATs"]
[Thu Sep 17 15:08:41.781165 2026] [security2:error] [pid 955873:tid 956025] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/qa/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWpwAAASA"]
[Thu Sep 17 15:08:41.865061 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxW2RFTPRVSLOsRVhoWqQAAAQ8"]
[Thu Sep 17 15:08:41.898798 2026] [security2:error] [pid 955873:tid 956085] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/preview/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWrwAAAVw"]
[Thu Sep 17 15:08:41.977355 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.190.5:48174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWswAAAS8"]
[Thu Sep 17 15:08:41.979538 2026] [security2:error] [pid 955873:tid 956077] [client 34.95.188.156:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWtAAAAVQ"]
[Thu Sep 17 15:08:42.005307 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:33928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/autoloader.php"] [unique_id "aqxW2hFTPRVSLOsRVhoWtQAAAWQ"]
[Thu Sep 17 15:08:42.005411 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:33928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/autoloader.php"] [unique_id "aqxW2hFTPRVSLOsRVhoWtQAAAWQ"]
[Thu Sep 17 15:08:42.006716 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/beta/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWtwAAARE"]
[Thu Sep 17 15:08:42.065641 2026] [security2:error] [pid 955873:tid 956033] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/uat/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWuQAAASg"]
[Thu Sep 17 15:08:42.161514 2026] [security2:error] [pid 955873:tid 956118] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/stage/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWvQAAAX0"]
[Thu Sep 17 15:08:42.226352 2026] [security2:error] [pid 955873:tid 956092] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/development/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWwwAAAWM"]
[Thu Sep 17 15:08:42.295702 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/"] [unique_id "aqxW2hFTPRVSLOsRVhoWyAAAAWY"]
[Thu Sep 17 15:08:42.309349 2026] [security2:error] [pid 955873:tid 956022] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/production/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWygAAAR0"]
[Thu Sep 17 15:08:42.426286 2026] [security2:error] [pid 955873:tid 956028] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/config/app/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoW0QAAASM"]
[Thu Sep 17 15:08:42.445476 2026] [authz_core:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/library/error_log
[Thu Sep 17 15:08:42.453038 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/"] [unique_id "aqxW2hFTPRVSLOsRVhoW0gAAAVU"]
[Thu Sep 17 15:08:42.484764 2026] [security2:error] [pid 955873:tid 956003] [client 34.95.188.156:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW1gAAAQo"]
[Thu Sep 17 15:08:42.525782 2026] [security2:error] [pid 955873:tid 956060] [client 35.222.223.233:44340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW1wAAAUM"]
[Thu Sep 17 15:08:42.544783 2026] [security2:error] [pid 955873:tid 956026] [client 47.79.200.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxW2hFTPRVSLOsRVhoWxgAAASE"], referer: https://www.google.com/
[Thu Sep 17 15:08:42.618934 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/wp-includes/SimplePie/"] [unique_id "aqxW2hFTPRVSLOsRVhoW2QAAAWg"]
[Thu Sep 17 15:08:42.676584 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.190.5:48186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW2wAAAXk"]
[Thu Sep 17 15:08:42.680047 2026] [security2:error] [pid 955873:tid 956048] [client 104.28.198.244:22781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3AAAATc"]
[Thu Sep 17 15:08:42.680126 2026] [security2:error] [pid 955873:tid 956048] [client 104.28.198.244:22781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3AAAATc"]
[Thu Sep 17 15:08:42.860932 2026] [security2:error] [pid 955873:tid 956080] [client 35.222.223.233:38960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/info.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW4AAAAVc"]
[Thu Sep 17 15:08:42.968171 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3QAAAVA"]
[Thu Sep 17 15:08:42.968193 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3QAAAVA"]
[Thu Sep 17 15:08:42.994281 2026] [security2:error] [pid 955873:tid 956128] [client 34.95.188.156:33052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/core/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW5gAAAYc"]
[Thu Sep 17 15:08:43.117474 2026] [security2:error] [pid 955873:tid 956104] [client 35.222.223.233:38976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/php.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW5wAAAW8"]
[Thu Sep 17 15:08:43.130478 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW6AAAATE"]
[Thu Sep 17 15:08:43.130579 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW6AAAATE"]
[Thu Sep 17 15:08:43.362382 2026] [security2:error] [pid 955873:tid 956115] [client 154.190.208.131:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW7QAAAXo"]
[Thu Sep 17 15:08:43.362501 2026] [security2:error] [pid 955873:tid 956115] [client 154.190.208.131:41597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW7QAAAXo"]
[Thu Sep 17 15:08:43.375726 2026] [security2:error] [pid 955873:tid 956098] [client 34.166.190.5:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW7gAAAWk"]
[Thu Sep 17 15:08:43.421288 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:33952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW2xFTPRVSLOsRVhoW8AAAARg"]
[Thu Sep 17 15:08:43.432687 2026] [security2:error] [pid 955873:tid 956094] [client 35.222.223.233:38978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/i.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW8gAAAWU"]
[Thu Sep 17 15:08:43.490518 2026] [security2:error] [pid 955873:tid 956035] [client 34.95.188.156:33062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW8wAAASo"]
[Thu Sep 17 15:08:43.572568 2026] [security2:error] [pid 955873:tid 956071] [client 162.241.226.11:20366] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW9AAAAU4"]
[Thu Sep 17 15:08:43.579302 2026] [authz_core:error] [pid 955873:tid 956121] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/library/SimplePie/error_log
[Thu Sep 17 15:08:43.630287 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW2xFTPRVSLOsRVhoW9QAAAYA"]
[Thu Sep 17 15:08:43.769281 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/wp-includes/SimplePie/library/"] [unique_id "aqxW2xFTPRVSLOsRVhoW-QAAARY"]
[Thu Sep 17 15:08:43.776813 2026] [security2:error] [pid 955873:tid 956086] [client 207.46.13.231:8523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thehivetribe.com"] [uri "/index.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWHwABXUk"]
[Thu Sep 17 15:08:43.956679 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:38986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/pi.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW_wAAAQw"]
[Thu Sep 17 15:08:44.079738 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.190.5:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXBgAAARU"]
[Thu Sep 17 15:08:44.155861 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW_gAAASM"]
[Thu Sep 17 15:08:44.155882 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW_gAAASM"]
[Thu Sep 17 15:08:44.231997 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:38992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/pinfo.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXCQAAAX4"]
[Thu Sep 17 15:08:44.298632 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:33952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Author.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXCgAAAXM"]
[Thu Sep 17 15:08:44.298745 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:33952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Author.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXCgAAAXM"]
[Thu Sep 17 15:08:44.311006 2026] [security2:error] [pid 955873:tid 955951] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.bak"] [unique_id "aqxW3BFTPRVSLOsRVhoXDAABJU0"]
[Thu Sep 17 15:08:44.311014 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.backup"] [unique_id "aqxW3BFTPRVSLOsRVhoXDQABJUw"]
[Thu Sep 17 15:08:44.312015 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.old"] [unique_id "aqxW3BFTPRVSLOsRVhoXEQABJUw"]
[Thu Sep 17 15:08:44.321457 2026] [security2:error] [pid 955873:tid 955955] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXGgABJVE"]
[Thu Sep 17 15:08:44.581610 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:38996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/test.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXJAAAAUs"]
[Thu Sep 17 15:08:44.586786 2026] [security2:error] [pid 955873:tid 955960] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/.env.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXIQABJVY"]
[Thu Sep 17 15:08:44.591869 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:33960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXJQAAAUA"]
[Thu Sep 17 15:08:44.591932 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:33960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXJQAAAUA"]
[Thu Sep 17 15:08:44.598398 2026] [security2:error] [pid 955873:tid 955963] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env~"] [unique_id "aqxW3BFTPRVSLOsRVhoXJgABO1k"]
[Thu Sep 17 15:08:44.632916 2026] [security2:error] [pid 955873:tid 956000] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.swp"] [unique_id "aqxW3BFTPRVSLOsRVhoXJwABXn4"]
[Thu Sep 17 15:08:44.863876 2026] [security2:error] [pid 955873:tid 955980] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/api/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXMQABVGo"]
[Thu Sep 17 15:08:44.863876 2026] [security2:error] [pid 955873:tid 955973] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/app/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXMgABVGM"]
[Thu Sep 17 15:08:44.882094 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:33964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/"] [unique_id "aqxW3BFTPRVSLOsRVhoXNAAAAWc"]
[Thu Sep 17 15:08:44.929718 2026] [security2:error] [pid 955873:tid 955978] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/backend/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXOgABRGg"]
[Thu Sep 17 15:08:44.943885 2026] [security2:error] [pid 955873:tid 955884] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/config/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPQABZAo"]
[Thu Sep 17 15:08:44.943908 2026] [security2:error] [pid 955873:tid 955883] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/client/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXQAABZAk"]
[Thu Sep 17 15:08:44.943930 2026] [security2:error] [pid 955873:tid 955987] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/src/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPAABZHE"]
[Thu Sep 17 15:08:44.943950 2026] [security2:error] [pid 955873:tid 955998] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/web/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPwABZHw"]
[Thu Sep 17 15:08:44.943968 2026] [security2:error] [pid 955873:tid 955961] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/server/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPgABZFc"]
[Thu Sep 17 15:08:45.001999 2026] [security2:error] [pid 955873:tid 955958] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/public/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXQgABEVQ"]
[Thu Sep 17 15:08:45.001999 2026] [security2:error] [pid 955873:tid 955979] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/frontend/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXQQABEWk"]
[Thu Sep 17 15:08:45.014563 2026] [security2:error] [pid 955873:tid 955994] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/var/www/html/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXRAABeng"]
[Thu Sep 17 15:08:45.014684 2026] [security2:error] [pid 955873:tid 955985] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/var/www/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXRQABem8"]
[Thu Sep 17 15:08:45.015162 2026] [security2:error] [pid 955873:tid 955885] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/laravel/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXRgABegs"]
[Thu Sep 17 15:08:45.024057 2026] [security2:error] [pid 955873:tid 955983] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/application/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXSAABhm0"]
[Thu Sep 17 15:08:45.056850 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/"] [unique_id "aqxW3RFTPRVSLOsRVhoXRwAAAWk"]
[Thu Sep 17 15:08:45.069156 2026] [security2:error] [pid 955873:tid 956001] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/apps/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXSgABfH8"]
[Thu Sep 17 15:08:45.069157 2026] [security2:error] [pid 955873:tid 955984] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/back/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXSwABfG4"]
[Thu Sep 17 15:08:45.069201 2026] [security2:error] [pid 955873:tid 955935] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/backup/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXTAABfD0"]
[Thu Sep 17 15:08:45.070590 2026] [security2:error] [pid 955873:tid 955974] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/cms/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXTQABfGQ"]
[Thu Sep 17 15:08:45.078728 2026] [security2:error] [pid 955873:tid 955957] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/dev/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXTwABSlM"]
[Thu Sep 17 15:08:45.079703 2026] [security2:error] [pid 955873:tid 955966] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/test/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUwABSlw"]
[Thu Sep 17 15:08:45.079766 2026] [security2:error] [pid 955873:tid 955977] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/production/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUAABSmc"]
[Thu Sep 17 15:08:45.079789 2026] [security2:error] [pid 955873:tid 955970] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/staging/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUgABSmA"]
[Thu Sep 17 15:08:45.079836 2026] [security2:error] [pid 955873:tid 955892] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/prod/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUQABShI"]
[Thu Sep 17 15:08:45.079867 2026] [security2:error] [pid 955873:tid 955886] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/old/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXVAABSgw"]
[Thu Sep 17 15:08:45.137510 2026] [security2:error] [pid 955873:tid 955897] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/node-api/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXVwABRhc"]
[Thu Sep 17 15:08:45.137526 2026] [security2:error] [pid 955873:tid 955982] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/new/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXVgABRmw"]
[Thu Sep 17 15:08:45.149283 2026] [security2:error] [pid 955873:tid 955967] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/api-backend/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWAABKl0"]
[Thu Sep 17 15:08:45.149769 2026] [security2:error] [pid 955873:tid 955990] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/admin-app/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWQABKnQ"]
[Thu Sep 17 15:08:45.158503 2026] [security2:error] [pid 955873:tid 955999] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/public_html/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWwABKn0"]
[Thu Sep 17 15:08:45.194630 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:33964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW3RFTPRVSLOsRVhoXXQAAAT0"]
[Thu Sep 17 15:08:45.204190 2026] [security2:error] [pid 955873:tid 955875] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/current/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXXgABKgE"]
[Thu Sep 17 15:08:45.204734 2026] [security2:error] [pid 955873:tid 955887] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/server/api/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXXwABKg0"]
[Thu Sep 17 15:08:45.204768 2026] [security2:error] [pid 955873:tid 955986] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/server/backend/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYAABKnA"]
[Thu Sep 17 15:08:45.205402 2026] [security2:error] [pid 955873:tid 955901] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.docker/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYQABKhs"]
[Thu Sep 17 15:08:45.213337 2026] [security2:error] [pid 955873:tid 955914] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYgABKig"]
[Thu Sep 17 15:08:45.213388 2026] [security2:error] [pid 955873:tid 955902] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/administrator/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWgABKhw"]
[Thu Sep 17 15:08:45.213939 2026] [security2:error] [pid 955873:tid 955989] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/aws/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYwABKnM"]
[Thu Sep 17 15:08:45.214630 2026] [security2:error] [pid 955873:tid 955997] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/stripe/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXZQABKns"]
[Thu Sep 17 15:08:45.214742 2026] [security2:error] [pid 955873:tid 955969] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.aws/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXZAABKl8"]
[Thu Sep 17 15:08:45.273342 2026] [security2:error] [pid 955873:tid 955894] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/v2/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXawABGxQ"]
[Thu Sep 17 15:08:45.273376 2026] [security2:error] [pid 955873:tid 955891] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/v1/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXbAABGxE"]
[Thu Sep 17 15:08:45.284899 2026] [security2:error] [pid 955873:tid 955971] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/v3/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXbQABfWE"]
[Thu Sep 17 15:08:45.285372 2026] [security2:error] [pid 955873:tid 955909] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/media/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXbgABfSM"]
[Thu Sep 17 15:08:45.324613 2026] [security2:error] [pid 955873:tid 956094] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXTgAAAWU"]
[Thu Sep 17 15:08:45.378951 2026] [security2:error] [pid 955873:tid 956019] [client 134.185.85.61:59020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "agingwellcoaching.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxW3RFTPRVSLOsRVhoXfgAAARo"]
[Thu Sep 17 15:08:45.402120 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:39006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/p.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXgwAAARc"]
[Thu Sep 17 15:08:45.408471 2026] [security2:error] [pid 955873:tid 955917] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.git/config.bak"] [unique_id "aqxW3RFTPRVSLOsRVhoXhQABDis"]
[Thu Sep 17 15:08:45.491573 2026] [security2:error] [pid 955873:tid 955923] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.aws/credentials.bak"] [unique_id "aqxW3RFTPRVSLOsRVhoXkAABEDE"]
[Thu Sep 17 15:08:45.497006 2026] [security2:error] [pid 955873:tid 955922] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.ssh/id_rsa"] [unique_id "aqxW3RFTPRVSLOsRVhoXlQABOTA"]
[Thu Sep 17 15:08:45.497038 2026] [security2:error] [pid 955873:tid 955937] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/id_rsa"] [unique_id "aqxW3RFTPRVSLOsRVhoXlgABOT8"]
[Thu Sep 17 15:08:45.614102 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXcAAAATQ"]
[Thu Sep 17 15:08:45.614123 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXcAAAATQ"]
[Thu Sep 17 15:08:45.711171 2026] [security2:error] [pid 955873:tid 956072] [client 4.240.114.86:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXswAAAU8"], referer: binance.com
[Thu Sep 17 15:08:45.756346 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:33964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Base.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXtwAAAQs"]
[Thu Sep 17 15:08:45.756439 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:33964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Base.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXtwAAAQs"]
[Thu Sep 17 15:08:45.765479 2026] [security2:error] [pid 955873:tid 956030] [client 134.185.85.61:63416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "agingwellcoaching.com"] [uri "/media/system/js/core.js"] [unique_id "aqxW3RFTPRVSLOsRVhoXuAAAASU"]
[Thu Sep 17 15:08:45.776126 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXvwABQEw"]
[Thu Sep 17 15:08:45.805576 2026] [security2:error] [pid 955873:tid 956069] [client 35.222.223.233:39020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/debug.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXxAAAAUw"]
[Thu Sep 17 15:08:45.912220 2026] [security2:error] [pid 955873:tid 955991] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/aws.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX0wABZ3U"]
[Thu Sep 17 15:08:45.916212 2026] [security2:error] [pid 955873:tid 955988] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/stripe.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX1QABUXI"]
[Thu Sep 17 15:08:45.920247 2026] [security2:error] [pid 955873:tid 955995] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/mail.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX1wABZHk"]
[Thu Sep 17 15:08:45.922649 2026] [security2:error] [pid 955873:tid 955973] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/config.inc.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX2AABEWM"]
[Thu Sep 17 15:08:45.990264 2026] [security2:error] [pid 955873:tid 955968] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/nexmo.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX2wABd14"]
[Thu Sep 17 15:08:45.994929 2026] [security2:error] [pid 955873:tid 955976] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/wp-config.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX3gABfGY"]
[Thu Sep 17 15:08:46.023684 2026] [security2:error] [pid 955873:tid 955884] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eris.media"] [uri "/wp-config.php.bak"] [unique_id "aqxW3hFTPRVSLOsRVhoX3wABSgo"]
[Thu Sep 17 15:08:46.046106 2026] [security2:error] [pid 955873:tid 955883] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eris.media"] [uri "/wp-config.php.old"] [unique_id "aqxW3hFTPRVSLOsRVhoX4AABNQk"]
[Thu Sep 17 15:08:46.046851 2026] [security2:error] [pid 955873:tid 955987] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eris.media"] [uri "/wp-config.php.new"] [unique_id "aqxW3hFTPRVSLOsRVhoX4QABL3E"]
[Thu Sep 17 15:08:46.050330 2026] [security2:error] [pid 955873:tid 955998] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/.wp-config.php.swp"] [unique_id "aqxW3hFTPRVSLOsRVhoX4gABWXw"]
[Thu Sep 17 15:08:46.054825 2026] [security2:error] [pid 955873:tid 955958] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/wp-content/mysql.sql"] [unique_id "aqxW3hFTPRVSLOsRVhoX5QABOFQ"]
[Thu Sep 17 15:08:46.060061 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/DB.php"] [unique_id "aqxW3hFTPRVSLOsRVhoX6gAAAUY"]
[Thu Sep 17 15:08:46.060141 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:33976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/DB.php"] [unique_id "aqxW3hFTPRVSLOsRVhoX6gAAAUY"]
[Thu Sep 17 15:08:46.104070 2026] [security2:error] [pid 955873:tid 956017] [client 35.222.223.233:39024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoX7gAAARg"]
[Thu Sep 17 15:08:46.129784 2026] [security2:error] [pid 955873:tid 955935] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/terraform.tfstate.backup"] [unique_id "aqxW3hFTPRVSLOsRVhoX8AABUz0"]
[Thu Sep 17 15:08:46.354248 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/File.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYGAAAARA"]
[Thu Sep 17 15:08:46.354326 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:33978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/File.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYGAAAARA"]
[Thu Sep 17 15:08:46.418724 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:39036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/test/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYHgAAATA"]
[Thu Sep 17 15:08:46.555281 2026] [security2:error] [pid 955873:tid 955916] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYLwABcio"]
[Thu Sep 17 15:08:46.584278 2026] [security2:error] [pid 955873:tid 955922] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/info.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYMgABPDA"]
[Thu Sep 17 15:08:46.610885 2026] [security2:error] [pid 955873:tid 955937] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/infos.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYMwABWz8"]
[Thu Sep 17 15:08:46.614091 2026] [security2:error] [pid 955873:tid 955907] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/php_info.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNAABISE"]
[Thu Sep 17 15:08:46.614537 2026] [security2:error] [pid 955873:tid 955924] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/php.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNQABITI"]
[Thu Sep 17 15:08:46.615328 2026] [security2:error] [pid 955873:tid 955927] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/php-info.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNwABIzU"]
[Thu Sep 17 15:08:46.615352 2026] [security2:error] [pid 955873:tid 955945] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/infophp.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNgABI0c"]
[Thu Sep 17 15:08:46.618414 2026] [security2:error] [pid 955873:tid 955932] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYOQABEjo"]
[Thu Sep 17 15:08:46.620041 2026] [security2:error] [pid 955873:tid 955926] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/admin/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYOgABEjQ"]
[Thu Sep 17 15:08:46.620775 2026] [security2:error] [pid 955873:tid 955930] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/admin_phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYOwABEjg"]
[Thu Sep 17 15:08:46.622352 2026] [security2:error] [pid 955873:tid 955943] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/api/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPAABEkU"]
[Thu Sep 17 15:08:46.630456 2026] [security2:error] [pid 955873:tid 955879] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/public/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPQABVgU"]
[Thu Sep 17 15:08:46.639259 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:33994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcache.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPgAAAWY"]
[Thu Sep 17 15:08:46.639320 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:33994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcache.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPgAAAWY"]
[Thu Sep 17 15:08:46.735750 2026] [security2:error] [pid 955873:tid 956120] [client 35.222.223.233:39046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYRQAAAX8"]
[Thu Sep 17 15:08:46.758094 2026] [security2:error] [pid 955873:tid 955933] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/database.sql"] [unique_id "aqxW3hFTPRVSLOsRVhoYSAABJDs"]
[Thu Sep 17 15:08:46.862212 2026] [security2:error] [pid 955873:tid 955951] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/web.config.txt"] [unique_id "aqxW3hFTPRVSLOsRVhoYWAABLU0"]
[Thu Sep 17 15:08:46.893723 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/dbdump.sql"] [unique_id "aqxW3hFTPRVSLOsRVhoYWQABT0w"]
[Thu Sep 17 15:08:46.900122 2026] [security2:error] [pid 955873:tid 955956] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/privatekey.key"] [unique_id "aqxW3hFTPRVSLOsRVhoYWwABglI"]
[Thu Sep 17 15:08:46.989769 2026] [security2:error] [pid 955873:tid 955991] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/config.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYZwABOnU"]
[Thu Sep 17 15:08:46.992629 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcached.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYagAAAVc"]
[Thu Sep 17 15:08:46.992748 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcached.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYagAAAVc"]
[Thu Sep 17 15:08:47.042002 2026] [security2:error] [pid 955873:tid 955895] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/lms/.env"] [unique_id "aqxW3xFTPRVSLOsRVhoYbwABSxU"]
[Thu Sep 17 15:08:47.042839 2026] [security2:error] [pid 955873:tid 955973] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/wp-content/uploads/backup.sql"] [unique_id "aqxW3xFTPRVSLOsRVhoYcAABS2M"]
[Thu Sep 17 15:08:47.043011 2026] [security2:error] [pid 955873:tid 955980] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config.php.old"] [unique_id "aqxW3xFTPRVSLOsRVhoYcQABS2o"]
[Thu Sep 17 15:08:47.159618 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:39060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/old/phpinfo.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYdwAAAUA"]
[Thu Sep 17 15:08:47.272999 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/MySQL.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYeQAAAWo"]
[Thu Sep 17 15:08:47.273094 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:34014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/MySQL.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYeQAAAWo"]
[Thu Sep 17 15:08:47.355795 2026] [security2:error] [pid 955873:tid 956064] [client 66.249.66.43:36849] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "memorytrackspodcast.com"] [uri "/robots.txt"] [unique_id "aqxW3xFTPRVSLOsRVhoYfAAAAUc"]
[Thu Sep 17 15:08:47.426694 2026] [security2:error] [pid 955873:tid 956074] [client 35.222.223.233:39066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYggAAAVE"]
[Thu Sep 17 15:08:47.434699 2026] [authz_core:error] [pid 955873:tid 956048] [client 20.244.34.24:51890] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:08:47.566882 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Redis.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYhgAAASc"]
[Thu Sep 17 15:08:47.566961 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Redis.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYhgAAASc"]
[Thu Sep 17 15:08:47.681405 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:39078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/public/phpinfo.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYiAAAAT0"]
[Thu Sep 17 15:08:47.857468 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:34034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Caption.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYjAAAAWw"]
[Thu Sep 17 15:08:47.857544 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:34034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Caption.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYjAAAAWw"]
[Thu Sep 17 15:08:48.111499 2026] [security2:error] [pid 955873:tid 956091] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYkAAAAWI"]
[Thu Sep 17 15:08:48.163365 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Category.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlAAAATM"]
[Thu Sep 17 15:08:48.163453 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Category.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlAAAATM"]
[Thu Sep 17 15:08:48.172158 2026] [security2:error] [pid 955873:tid 956043] [client 186.105.232.15:59003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlQAAATI"]
[Thu Sep 17 15:08:48.172270 2026] [security2:error] [pid 955873:tid 956043] [client 186.105.232.15:59003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlQAAATI"]
[Thu Sep 17 15:08:48.197865 2026] [security2:error] [pid 955873:tid 956122] [client 35.222.223.233:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/php-info.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlgAAAYE"]
[Thu Sep 17 15:08:48.442524 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/"] [unique_id "aqxW4BFTPRVSLOsRVhoYmQAAAUM"]
[Thu Sep 17 15:08:48.537423 2026] [access_compat:error] [pid 955873:tid 956121] [client 159.69.14.102:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/prehistoric-tales
[Thu Sep 17 15:08:48.568233 2026] [security2:error] [pid 955873:tid 956023] [client 35.222.223.233:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpversion.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYngAAAR4"]
[Thu Sep 17 15:08:48.609972 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/"] [unique_id "aqxW4BFTPRVSLOsRVhoYnwAAAVY"]
[Thu Sep 17 15:08:48.748768 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW4BFTPRVSLOsRVhoYpgAAAQ0"]
[Thu Sep 17 15:08:48.784141 2026] [security2:error] [pid 955873:tid 956022] [client 35.222.223.233:38730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/_phpinfo.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYpwAAAR0"]
[Thu Sep 17 15:08:48.978938 2026] [security2:error] [pid 955873:tid 956037] [client 185.55.149.49:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYrAAAASw"]
[Thu Sep 17 15:08:48.979045 2026] [security2:error] [pid 955873:tid 956037] [client 185.55.149.49:49838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYrAAAASw"]
[Thu Sep 17 15:08:49.090333 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYqwAAAX4"]
[Thu Sep 17 15:08:49.090359 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYqwAAAX4"]
[Thu Sep 17 15:08:49.168049 2026] [security2:error] [pid 955873:tid 956012] [client 35.222.223.233:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/old_phpinfo.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYrgAAARM"]
[Thu Sep 17 15:08:49.229852 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/"] [unique_id "aqxW4RFTPRVSLOsRVhoYrwAAAXk"]
[Thu Sep 17 15:08:49.280523 2026] [security2:error] [pid 955873:tid 956068] [client 4.240.114.86:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYsAAAAUs"], referer: binance.com
[Thu Sep 17 15:08:49.387251 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/"] [unique_id "aqxW4RFTPRVSLOsRVhoYswAAAVg"]
[Thu Sep 17 15:08:49.419010 2026] [security2:error] [pid 955873:tid 956030] [client 35.222.223.233:38744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/server-info.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYtQAAASU"]
[Thu Sep 17 15:08:49.525390 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/wp-includes/SimplePie/library/SimplePie/Content/"] [unique_id "aqxW4RFTPRVSLOsRVhoYuAAAAUA"]
[Thu Sep 17 15:08:49.699245 2026] [security2:error] [pid 955873:tid 956099] [client 35.222.223.233:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/server-status.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYuwAAAWo"]
[Thu Sep 17 15:08:49.815157 2026] [security2:error] [pid 955873:tid 956064] [client 45.169.98.18:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYvAAAAUc"]
[Thu Sep 17 15:08:49.815263 2026] [security2:error] [pid 955873:tid 956064] [client 45.169.98.18:63248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYvAAAAUc"]
[Thu Sep 17 15:08:49.858181 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYugAAAVE"]
[Thu Sep 17 15:08:49.858203 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYugAAAVE"]
[Thu Sep 17 15:08:50.021118 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:34050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/Sniffer.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYwAAAAVk"]
[Thu Sep 17 15:08:50.021212 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/Sniffer.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYwAAAAVk"]
[Thu Sep 17 15:08:50.084946 2026] [security2:error] [pid 955873:tid 956039] [client 162.241.226.11:51364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYxAAAAS4"]
[Thu Sep 17 15:08:50.281993 2026] [security2:error] [pid 955873:tid 956063] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYwwAAAUY"]
[Thu Sep 17 15:08:50.312079 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Copyright.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYyQAAASA"]
[Thu Sep 17 15:08:50.312177 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Copyright.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYyQAAASA"]
[Thu Sep 17 15:08:50.593628 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Core.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY1AAAATk"]
[Thu Sep 17 15:08:50.593748 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Core.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY1AAAATk"]
[Thu Sep 17 15:08:50.629266 2026] [security2:error] [pid 955873:tid 956088] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY0wAAAV8"]
[Thu Sep 17 15:08:50.769428 2026] [security2:error] [pid 955873:tid 956126] [client 35.222.223.233:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxW4hFTPRVSLOsRVhoY1QAAAYU"]
[Thu Sep 17 15:08:50.874056 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Credit.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY2AAAATw"]
[Thu Sep 17 15:08:50.874142 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Credit.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY2AAAATw"]
[Thu Sep 17 15:08:51.017954 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY2wAAAWA"]
[Thu Sep 17 15:08:51.165300 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/"] [unique_id "aqxW4xFTPRVSLOsRVhoY3AAAASM"]
[Thu Sep 17 15:08:51.314094 2026] [security2:error] [pid 955873:tid 956015] [client 114.119.129.200:43515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vancouvermodernportraits.com"] [uri "/"] [unique_id "aqxW4xFTPRVSLOsRVhoY3gAAARY"], referer: https://www.vancouvermodernportraits.com/
[Thu Sep 17 15:08:51.326369 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/"] [unique_id "aqxW4xFTPRVSLOsRVhoY3QAAASE"]
[Thu Sep 17 15:08:51.333273 2026] [security2:error] [pid 955873:tid 956065] [client 35.222.223.233:38774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY3wAAAUg"]
[Thu Sep 17 15:08:51.470982 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW4xFTPRVSLOsRVhoY4gAAASQ"]
[Thu Sep 17 15:08:51.624771 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:38776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY5QAAAW0"]
[Thu Sep 17 15:08:51.716485 2026] [authz_core:error] [pid 955873:tid 956122] [client 5.189.145.112:62235] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:08:51.803506 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY5AAAAVU"]
[Thu Sep 17 15:08:51.803529 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY5AAAAVU"]
[Thu Sep 17 15:08:51.892780 2026] [security2:error] [pid 955873:tid 956051] [client 35.222.223.233:38786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY6gAAATo"]
[Thu Sep 17 15:08:51.945291 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/"] [unique_id "aqxW4xFTPRVSLOsRVhoY6wAAAQs"]
[Thu Sep 17 15:08:51.987385 2026] [security2:error] [pid 955873:tid 956072] [client 115.244.164.14:57426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY7gAAAU8"]
[Thu Sep 17 15:08:51.987447 2026] [security2:error] [pid 955873:tid 956072] [client 115.244.164.14:57426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY7gAAAU8"]
[Thu Sep 17 15:08:52.103126 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/"] [unique_id "aqxW5BFTPRVSLOsRVhoY8AAAAUw"]
[Thu Sep 17 15:08:52.169593 2026] [security2:error] [pid 955873:tid 956097] [client 162.241.226.11:25040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/wp-cron.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY8wAAAWg"]
[Thu Sep 17 15:08:52.246729 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/wp-includes/SimplePie/library/SimplePie/Decode/"] [unique_id "aqxW5BFTPRVSLOsRVhoY9QAAATY"]
[Thu Sep 17 15:08:52.417174 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY_wAAAUA"]
[Thu Sep 17 15:08:52.583307 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY_AAAAVk"]
[Thu Sep 17 15:08:52.583332 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY_AAAAVk"]
[Thu Sep 17 15:08:52.728903 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/Entities.php"] [unique_id "aqxW5BFTPRVSLOsRVhoZAQAAAXY"]
[Thu Sep 17 15:08:52.729012 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/Entities.php"] [unique_id "aqxW5BFTPRVSLOsRVhoZAQAAAXY"]
[Thu Sep 17 15:08:52.812130 2026] [security2:error] [pid 955873:tid 956062] [client 35.222.223.233:38814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxW5BFTPRVSLOsRVhoZAgAAAUU"]
[Thu Sep 17 15:08:53.017918 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Enclosure.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZBwAAARo"]
[Thu Sep 17 15:08:53.018032 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Enclosure.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZBwAAARo"]
[Thu Sep 17 15:08:53.071147 2026] [autoindex:error] [pid 955873:tid 956016] [client 104.219.251.70:50692] AH01276: Cannot serve directory /home4/gcpmanag/public_html/website_a0c825a6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:08:53.212640 2026] [security2:error] [pid 955873:tid 956075] [client 35.222.223.233:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php.old"] [unique_id "aqxW5RFTPRVSLOsRVhoZCgAAAVI"]
[Thu Sep 17 15:08:53.307440 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Exception.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZDgAAATk"]
[Thu Sep 17 15:08:53.307546 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Exception.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZDgAAATk"]
[Thu Sep 17 15:08:53.324784 2026] [security2:error] [pid 955873:tid 956088] [client 4.240.114.86:52443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZDwAAAV8"], referer: binance.com
[Thu Sep 17 15:08:53.521724 2026] [security2:error] [pid 955873:tid 956021] [client 162.241.226.11:25050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/wp-cron.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZFAAAARw"]
[Thu Sep 17 15:08:53.560259 2026] [security2:error] [pid 955873:tid 956100] [client 35.222.223.233:38820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php~"] [unique_id "aqxW5RFTPRVSLOsRVhoZFQAAAWs"]
[Thu Sep 17 15:08:53.598237 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/File.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZFgAAATw"]
[Thu Sep 17 15:08:53.598339 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/File.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZFgAAATw"]
[Thu Sep 17 15:08:53.742565 2026] [security2:error] [pid 955873:tid 956033] [client 35.198.113.100:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZEwABKGw"]
[Thu Sep 17 15:08:53.854791 2026] [security2:error] [pid 955873:tid 956018] [client 35.222.223.233:38824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/info.php.bak"] [unique_id "aqxW5RFTPRVSLOsRVhoZGgAAARk"]
[Thu Sep 17 15:08:53.888837 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:42254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/"] [unique_id "aqxW5RFTPRVSLOsRVhoZHQAAAQw"]
[Thu Sep 17 15:08:53.901540 2026] [security2:error] [pid 955873:tid 955875] [remote 40.77.167.18:35798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZHgABHQE"], referer: https://talent-in-borders.com/lindsey-stirling-2026-snow-waltz-holiday-tour/
[Thu Sep 17 15:08:53.903915 2026] [security2:error] [pid 955873:tid 956084] [client 24.96.123.201:32949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZGAABW10"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:08:54.043059 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/"] [unique_id "aqxW5hFTPRVSLOsRVhoZIAAAAX8"]
[Thu Sep 17 15:08:54.127264 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZIQAAAWY"]
[Thu Sep 17 15:08:54.127353 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:42194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZIQAAAWY"]
[Thu Sep 17 15:08:54.145827 2026] [security2:error] [pid 955873:tid 956055] [client 35.222.223.233:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php.save"] [unique_id "aqxW5hFTPRVSLOsRVhoZIgAAAT4"]
[Thu Sep 17 15:08:54.183467 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:42254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW5hFTPRVSLOsRVhoZIwAAAUk"]
[Thu Sep 17 15:08:54.439844 2026] [security2:error] [pid 955873:tid 956113] [client 35.222.223.233:38838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZKQAAAXg"]
[Thu Sep 17 15:08:54.515463 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZJgAAAYE"]
[Thu Sep 17 15:08:54.515482 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZJgAAAYE"]
[Thu Sep 17 15:08:54.656755 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/Parser.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZLQAAAXc"]
[Thu Sep 17 15:08:54.656877 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/Parser.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZLQAAAXc"]
[Thu Sep 17 15:08:54.703314 2026] [security2:error] [pid 955873:tid 956077] [client 35.222.223.233:38840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZLgAAAVQ"]
[Thu Sep 17 15:08:54.922640 2026] [security2:error] [pid 955873:tid 956037] [client 193.36.224.219:65425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/000.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZMgAAASw"]
[Thu Sep 17 15:08:54.970893 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/IRI.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZNgAAAUs"]
[Thu Sep 17 15:08:54.970994 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:42270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/IRI.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZNgAAAUs"]
[Thu Sep 17 15:08:55.009594 2026] [security2:error] [pid 955873:tid 956096] [client 35.222.223.233:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZNwAAAWc"]
[Thu Sep 17 15:08:55.256104 2026] [security2:error] [pid 955873:tid 956064] [client 35.222.223.233:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOQAAAUc"]
[Thu Sep 17 15:08:55.262431 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Item.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOgAAAVk"]
[Thu Sep 17 15:08:55.262510 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Item.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOgAAAVk"]
[Thu Sep 17 15:08:55.269339 2026] [security2:error] [pid 955873:tid 956040] [client 193.36.224.168:35273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/about.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOwAAAS8"]
[Thu Sep 17 15:08:55.338655 2026] [security2:error] [pid 955873:tid 956062] [client 20.244.34.24:57795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZPQAAAUU"], referer: binance.com
[Thu Sep 17 15:08:55.562087 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Locator.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZQQAAARc"]
[Thu Sep 17 15:08:55.562328 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Locator.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZQQAAARc"]
[Thu Sep 17 15:08:55.580156 2026] [security2:error] [pid 955873:tid 956020] [client 35.222.223.233:38858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZQgAAARs"]
[Thu Sep 17 15:08:55.859263 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Misc.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZSQAAAV8"]
[Thu Sep 17 15:08:55.859361 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Misc.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZSQAAAV8"]
[Thu Sep 17 15:08:55.896593 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:38874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/www/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZTAAAAYg"]
[Thu Sep 17 15:08:56.174357 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:42304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/"] [unique_id "aqxW6BFTPRVSLOsRVhoZUQAAATM"]
[Thu Sep 17 15:08:56.301079 2026] [security2:error] [pid 955873:tid 956100] [client 35.222.223.233:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZUgAAAWs"]
[Thu Sep 17 15:08:56.333062 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/"] [unique_id "aqxW6BFTPRVSLOsRVhoZUwAAATw"]
[Thu Sep 17 15:08:56.478038 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:42304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW6BFTPRVSLOsRVhoZWAAAARU"]
[Thu Sep 17 15:08:56.618047 2026] [security2:error] [pid 955873:tid 956036] [client 193.36.224.170:23053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWQAAASs"]
[Thu Sep 17 15:08:56.643567 2026] [security2:error] [pid 955873:tid 956033] [client 35.222.223.233:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWwAAASg"]
[Thu Sep 17 15:08:56.812548 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWgAAASs"]
[Thu Sep 17 15:08:56.812573 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWgAAASs"]
[Thu Sep 17 15:08:56.858329 2026] [security2:error] [pid 955873:tid 956084] [client 216.24.219.103:30703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/about.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZYAAAAVs"]
[Thu Sep 17 15:08:56.962482 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/IPv6.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZZQAAASY"]
[Thu Sep 17 15:08:56.962581 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/IPv6.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZZQAAASY"]
[Thu Sep 17 15:08:57.017544 2026] [security2:error] [pid 955873:tid 956108] [client 4.240.114.86:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZZwAAAXM"], referer: binance.com
[Thu Sep 17 15:08:57.032966 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:38888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/site/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZaAAAAW0"]
[Thu Sep 17 15:08:57.256375 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/"] [unique_id "aqxW6RFTPRVSLOsRVhoZaQAAAXk"]
[Thu Sep 17 15:08:57.264231 2026] [security2:error] [pid 955873:tid 956056] [client 35.222.223.233:38902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZagAAAT8"]
[Thu Sep 17 15:08:57.381382 2026] [security2:error] [pid 955873:tid 956030] [client 216.24.219.97:21985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZawAAASU"]
[Thu Sep 17 15:08:57.426088 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/"] [unique_id "aqxW6RFTPRVSLOsRVhoZbQAAARM"]
[Thu Sep 17 15:08:57.468953 2026] [security2:error] [pid 955873:tid 956097] [client 35.222.223.233:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZcwAAAWg"]
[Thu Sep 17 15:08:57.567016 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW6RFTPRVSLOsRVhoZdgAAATY"]
[Thu Sep 17 15:08:57.638831 2026] [security2:error] [pid 955873:tid 956054] [client 193.36.224.219:38045] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-includes/hp2.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZdwAAAT0"]
[Thu Sep 17 15:08:57.768275 2026] [security2:error] [pid 955873:tid 956013] [client 35.222.223.233:33874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZfQAAARQ"]
[Thu Sep 17 15:08:57.891999 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZegAAAW8"]
[Thu Sep 17 15:08:57.892032 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZegAAAW8"]
[Thu Sep 17 15:08:58.042407 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/Date.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZhQAAARc"]
[Thu Sep 17 15:08:58.042530 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/Date.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZhQAAARc"]
[Thu Sep 17 15:08:58.180007 2026] [security2:error] [pid 955873:tid 956093] [client 172.86.81.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hendersonlife.info"] [uri "/index.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZfAAAAWQ"], referer: http://hendersonlife.info/.git/config
[Thu Sep 17 15:08:58.222643 2026] [security2:error] [pid 955873:tid 956105] [client 35.222.223.233:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/core/phpinfo.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZjQAAAXA"]
[Thu Sep 17 15:08:58.286995 2026] [security2:error] [pid 955873:tid 956021] [client 193.36.224.222:41803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/bless.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZjwAAARw"]
[Thu Sep 17 15:08:58.328745 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parser.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZkgAAAUM"]
[Thu Sep 17 15:08:58.328860 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parser.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZkgAAAUM"]
[Thu Sep 17 15:08:58.394260 2026] [security2:error] [pid 955873:tid 956009] [client 24.96.123.201:60723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZkAABECA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260611193227&hideliu=1&hidemyself=1&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:58.530893 2026] [security2:error] [pid 955873:tid 956073] [client 35.222.223.233:33890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmAAAAVA"]
[Thu Sep 17 15:08:58.613797 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Rating.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmwAAAVs"]
[Thu Sep 17 15:08:58.613897 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Rating.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmwAAAVs"]
[Thu Sep 17 15:08:58.714464 2026] [security2:error] [pid 955873:tid 956056] [client 216.24.219.37:25331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/goods.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZoQAAAT8"]
[Thu Sep 17 15:08:58.901672 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:42332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Registry.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZpAAAAQo"]
[Thu Sep 17 15:08:58.901794 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:42332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Registry.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZpAAAAQo"]
[Thu Sep 17 15:08:58.973030 2026] [security2:error] [pid 955873:tid 956005] [client 193.36.224.149:60867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/blurbs.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZpgAAAQw"]
[Thu Sep 17 15:08:59.024716 2026] [security2:error] [pid 955873:tid 956004] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZowAAAQs"]
[Thu Sep 17 15:08:59.091814 2026] [core:error] [pid 955873:tid 956087] [client 195.96.139.110:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:59.091841 2026] [core:error] [pid 955873:tid 956087] [client 195.96.139.110:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:59.129450 2026] [security2:error] [pid 955873:tid 956030] [client 186.105.232.15:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrQAAASU"]
[Thu Sep 17 15:08:59.131277 2026] [security2:error] [pid 955873:tid 956030] [client 186.105.232.15:59594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrQAAASU"]
[Thu Sep 17 15:08:59.164639 2026] [security2:error] [pid 955873:tid 956065] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pfa.ccv.mybluehost.me"] [uri "/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmQAAAUg"]
[Thu Sep 17 15:08:59.164877 2026] [security2:error] [pid 955873:tid 956113] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pfa.ccv.mybluehost.me"] [uri "/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZogAAAXg"]
[Thu Sep 17 15:08:59.182033 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Restriction.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrwAAATc"]
[Thu Sep 17 15:08:59.182120 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Restriction.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrwAAATc"]
[Thu Sep 17 15:08:59.249447 2026] [security2:error] [pid 955873:tid 956052] [client 104.234.19.143:41469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZsAAAATs"]
[Thu Sep 17 15:08:59.306024 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZqgAAAUs"]
[Thu Sep 17 15:08:59.463027 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:42348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Sanitize.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtAAAAXA"]
[Thu Sep 17 15:08:59.463157 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:42348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Sanitize.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtAAAAXA"]
[Thu Sep 17 15:08:59.541974 2026] [security2:error] [pid 955873:tid 956122] [client 185.55.149.49:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtQAAAYE"]
[Thu Sep 17 15:08:59.542067 2026] [security2:error] [pid 955873:tid 956122] [client 185.55.149.49:52703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtQAAAYE"]
[Thu Sep 17 15:08:59.584389 2026] [security2:error] [pid 955873:tid 956103] [client 193.36.224.108:49879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/abcd.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtgAAAW4"]
[Thu Sep 17 15:08:59.618062 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZswAAAQ8"]
[Thu Sep 17 15:08:59.776366 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Source.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZuwAAAUM"]
[Thu Sep 17 15:08:59.776470 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Source.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZuwAAAUM"]
[Thu Sep 17 15:08:59.949631 2026] [security2:error] [pid 955873:tid 956083] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZugAAAVo"]
[Thu Sep 17 15:09:00.000969 2026] [security2:error] [pid 955873:tid 956079] [client 193.36.224.116:59785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZvgAAAVY"]
[Thu Sep 17 15:09:00.054944 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/"] [unique_id "aqxW7BFTPRVSLOsRVhoZwgAAAWs"]
[Thu Sep 17 15:09:00.216681 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/"] [unique_id "aqxW7BFTPRVSLOsRVhoZwwAAASM"]
[Thu Sep 17 15:09:00.217295 2026] [security2:error] [pid 955873:tid 956020] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZwQAAARs"]
[Thu Sep 17 15:09:00.286569 2026] [security2:error] [pid 955873:tid 956033] [client 45.169.98.18:63813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZxgAAASg"]
[Thu Sep 17 15:09:00.286997 2026] [security2:error] [pid 955873:tid 956033] [client 45.169.98.18:63813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZxgAAASg"]
[Thu Sep 17 15:09:00.335968 2026] [security2:error] [pid 955873:tid 956084] [client 216.24.219.21:57537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/dex.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZyAAAAVs"]
[Thu Sep 17 15:09:00.357697 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW7BFTPRVSLOsRVhoZygAAASY"]
[Thu Sep 17 15:09:00.493310 2026] [security2:error] [pid 955873:tid 956124] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZxwAAAYM"]
[Thu Sep 17 15:09:00.728640 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZzQAAATo"]
[Thu Sep 17 15:09:00.728673 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZzQAAATo"]
[Thu Sep 17 15:09:00.791596 2026] [security2:error] [pid 955873:tid 956069] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZzgAAAUw"]
[Thu Sep 17 15:09:00.868546 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3AAAAQs"]
[Thu Sep 17 15:09:00.896868 2026] [security2:error] [pid 955873:tid 956087] [client 4.240.114.86:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3gAAAV4"], referer: binance.com
[Thu Sep 17 15:09:00.931259 2026] [security2:error] [pid 955873:tid 956090] [client 216.24.219.88:53881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3wAAAWE"]
[Thu Sep 17 15:09:00.971845 2026] [security2:error] [pid 955873:tid 956071] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jcktax.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ2AAAAU4"], referer: https://pfa.ccv.mybluehost.me/api/session/properties
[Thu Sep 17 15:09:00.971845 2026] [security2:error] [pid 955873:tid 956005] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jcktax.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ2QAAAQw"], referer: http://pfa.ccv.mybluehost.me/api/session/properties
[Thu Sep 17 15:09:01.041519 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/"] [unique_id "aqxW7RFTPRVSLOsRVhoZ4QAAAUg"]
[Thu Sep 17 15:09:01.126963 2026] [security2:error] [pid 955873:tid 956115] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3QAAAXo"]
[Thu Sep 17 15:09:01.179014 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/wp-includes/SimplePie/library/SimplePie/XML/"] [unique_id "aqxW7RFTPRVSLOsRVhoZ4wAAASE"]
[Thu Sep 17 15:09:01.438107 2026] [security2:error] [pid 955873:tid 956112] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ5gAAAXc"]
[Thu Sep 17 15:09:01.560201 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ6wAAAWQ"]
[Thu Sep 17 15:09:01.560306 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ6wAAAWQ"]
[Thu Sep 17 15:09:01.697539 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/Parser.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ9AAAAWI"]
[Thu Sep 17 15:09:01.697679 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/Parser.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ9AAAAWI"]
[Thu Sep 17 15:09:01.805841 2026] [security2:error] [pid 955873:tid 956078] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ8AAAAVU"]
[Thu Sep 17 15:09:01.985926 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/gzdecode.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ_gAAAVo"]
[Thu Sep 17 15:09:01.986032 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/gzdecode.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ_gAAAVo"]
[Thu Sep 17 15:09:02.097899 2026] [security2:error] [pid 955873:tid 956053] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ_QAAATw"]
[Thu Sep 17 15:09:02.120290 2026] [security2:error] [pid 955873:tid 955922] [remote 47.128.98.144:21510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cobblehillstudio.net"] [uri "/robots.txt"] [unique_id "aqxW7hFTPRVSLOsRVhoaAAABcjA"]
[Thu Sep 17 15:09:02.264919 2026] [security2:error] [pid 955873:tid 956011] [client 40.87.20.23:28172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "dfdub.com"] [uri "/"] [unique_id "aqxW7hFTPRVSLOsRVhoaBwAAARI"]
[Thu Sep 17 15:09:02.274390 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:47392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/"] [unique_id "aqxW7hFTPRVSLOsRVhoaCQAAASM"]
[Thu Sep 17 15:09:02.325912 2026] [security2:error] [pid 955873:tid 956031] [client 40.87.20.23:28172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=:"] [hostname "dfdub.com"] [uri "/"] [unique_id "aqxW7hFTPRVSLOsRVhoaCgAAASY"]
[Thu Sep 17 15:09:02.403894 2026] [security2:error] [pid 955873:tid 956121] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaAwAAAYA"]
[Thu Sep 17 15:09:02.424420 2026] [security2:error] [pid 955873:tid 956114] [client 193.36.224.222:33031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDAAAAXk"]
[Thu Sep 17 15:09:02.434687 2026] [authz_core:error] [pid 955873:tid 956095] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/src/error_log
[Thu Sep 17 15:09:02.477815 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/"] [unique_id "aqxW7hFTPRVSLOsRVhoaCwAAAWY"]
[Thu Sep 17 15:09:02.589412 2026] [security2:error] [pid 955873:tid 956020] [client 115.244.164.14:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDwAAARs"]
[Thu Sep 17 15:09:02.589519 2026] [security2:error] [pid 955873:tid 956020] [client 115.244.164.14:58065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDwAAARs"]
[Thu Sep 17 15:09:02.625277 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:47392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/wp-includes/SimplePie/"] [unique_id "aqxW7hFTPRVSLOsRVhoaEQAAAVA"]
[Thu Sep 17 15:09:02.715129 2026] [security2:error] [pid 955873:tid 956056] [client 176.134.14.88:3765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaEAABPzI"]
[Thu Sep 17 15:09:02.715403 2026] [security2:error] [pid 955873:tid 956043] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDgAAATI"]
[Thu Sep 17 15:09:02.969585 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaHwAAAWE"]
[Thu Sep 17 15:09:02.969620 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaHwAAAWE"]
[Thu Sep 17 15:09:03.041719 2026] [security2:error] [pid 955873:tid 956067] [client 216.24.219.36:52153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaIQAAAUo"]
[Thu Sep 17 15:09:03.059352 2026] [security2:error] [pid 955873:tid 956077] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaIAAAAVQ"]
[Thu Sep 17 15:09:03.109621 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Author.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaIgAAAXo"]
[Thu Sep 17 15:09:03.109778 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Author.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaIgAAAXo"]
[Thu Sep 17 15:09:03.398577 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:47400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaJwAAARc"]
[Thu Sep 17 15:09:03.398669 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:47400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaJwAAARc"]
[Thu Sep 17 15:09:03.412625 2026] [security2:error] [pid 955873:tid 956092] [client 193.36.224.226:38311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaKAAAAWM"]
[Thu Sep 17 15:09:03.700404 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:47410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/"] [unique_id "aqxW7xFTPRVSLOsRVhoaLAAAAYE"]
[Thu Sep 17 15:09:03.707385 2026] [security2:error] [pid 955873:tid 956111] [client 216.24.219.102:23435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaLQAAAXY"]
[Thu Sep 17 15:09:03.853342 2026] [authz_core:error] [pid 955873:tid 956057] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/src/Cache/error_log
[Thu Sep 17 15:09:03.860987 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/"] [unique_id "aqxW7xFTPRVSLOsRVhoaMQAAAUA"]
[Thu Sep 17 15:09:04.001732 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:47410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/wp-includes/SimplePie/src/"] [unique_id "aqxW8BFTPRVSLOsRVhoaNAAAAV8"]
[Thu Sep 17 15:09:04.125948 2026] [security2:error] [pid 955873:tid 956075] [client 193.36.224.150:40341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaNQAAAVI"]
[Thu Sep 17 15:09:04.251472 2026] [security2:error] [pid 955873:tid 956098] [client 4.240.114.86:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaOwAAAWk"], referer: binance.com
[Thu Sep 17 15:09:04.327803 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaOAAAARg"]
[Thu Sep 17 15:09:04.327832 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaOAAAARg"]
[Thu Sep 17 15:09:04.469861 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:47410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Base.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaPgAAAWs"]
[Thu Sep 17 15:09:04.470003 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:47410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Base.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaPgAAAWs"]
[Thu Sep 17 15:09:04.671819 2026] [security2:error] [pid 955873:tid 956007] [client 193.36.224.212:41815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/file.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaPwAAAQ4"]
[Thu Sep 17 15:09:04.764490 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/BaseDataCache.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaQwAAAYM"]
[Thu Sep 17 15:09:04.764586 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/BaseDataCache.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaQwAAAYM"]
[Thu Sep 17 15:09:05.069843 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:47424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/CallableNameFilter.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaRQAAAX0"]
[Thu Sep 17 15:09:05.069944 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:47424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/CallableNameFilter.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaRQAAAX0"]
[Thu Sep 17 15:09:05.123532 2026] [security2:error] [pid 955873:tid 956041] [client 193.36.224.149:65499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaRgAAATA"]
[Thu Sep 17 15:09:05.377607 2026] [security2:error] [pid 955873:tid 956025] [client 5.102.173.71:56448] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaMwAAASA"]
[Thu Sep 17 15:09:05.380903 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DB.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTQAAAWo"]
[Thu Sep 17 15:09:05.381012 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:47430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DB.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTQAAAWo"]
[Thu Sep 17 15:09:05.458999 2026] [security2:error] [pid 955873:tid 956038] [client 154.190.208.131:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTgAAAS0"]
[Thu Sep 17 15:09:05.459100 2026] [security2:error] [pid 955873:tid 956038] [client 154.190.208.131:41450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTgAAAS0"]
[Thu Sep 17 15:09:05.507248 2026] [security2:error] [pid 955873:tid 956087] [client 193.36.224.148:48949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-mail.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTwAAAV4"]
[Thu Sep 17 15:09:05.676231 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DataCache.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaUQAAAU0"]
[Thu Sep 17 15:09:05.676350 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DataCache.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaUQAAAU0"]
[Thu Sep 17 15:09:05.802276 2026] [security2:error] [pid 955873:tid 956109] [client 193.36.224.146:55871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/ioxi-o.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaVQAAAXQ"]
[Thu Sep 17 15:09:05.944361 2026] [security2:error] [pid 955873:tid 956030] [client 157.20.87.107:59913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaVAABJR4"]
[Thu Sep 17 15:09:05.976017 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/File.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaWAAAAYQ"]
[Thu Sep 17 15:09:05.976147 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/File.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaWAAAAYQ"]
[Thu Sep 17 15:09:06.051496 2026] [authz_core:error] [pid 955873:tid 956020] [client 5.189.145.112:60688] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:09:06.242587 2026] [security2:error] [pid 955873:tid 956042] [client 5.102.173.71:56448] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaUAAAATE"]
[Thu Sep 17 15:09:06.257718 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcache.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaXQAAAUQ"]
[Thu Sep 17 15:09:06.257808 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:47454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcache.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaXQAAAUQ"]
[Thu Sep 17 15:09:06.294827 2026] [security2:error] [pid 955873:tid 956016] [client 104.234.19.146:38797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaXwAAARc"]
[Thu Sep 17 15:09:06.300465 2026] [security2:error] [pid 955873:tid 956092] [client 20.244.34.24:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaYQAAAWM"], referer: binance.com
[Thu Sep 17 15:09:06.534204 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcached.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaYgAAAVk"]
[Thu Sep 17 15:09:06.534295 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:47464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcached.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaYgAAAVk"]
[Thu Sep 17 15:09:06.815179 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/MySQL.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaagAAAQ8"]
[Thu Sep 17 15:09:06.815279 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/MySQL.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaagAAAQ8"]
[Thu Sep 17 15:09:06.851469 2026] [security2:error] [pid 955873:tid 956117] [client 193.36.224.152:39827] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/style.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaawAAAXw"]
[Thu Sep 17 15:09:07.097646 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:47484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/NameFilter.php"] [unique_id "aqxW8xFTPRVSLOsRVhoabQAAAVE"]
[Thu Sep 17 15:09:07.097777 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:47484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/NameFilter.php"] [unique_id "aqxW8xFTPRVSLOsRVhoabQAAAVE"]
[Thu Sep 17 15:09:07.350912 2026] [security2:error] [pid 955873:tid 956086] [client 193.36.224.151:44667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/style.php"] [unique_id "aqxW8xFTPRVSLOsRVhoacQAAAV0"]
[Thu Sep 17 15:09:07.391562 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Psr16.php"] [unique_id "aqxW8xFTPRVSLOsRVhoacgAAARA"]
[Thu Sep 17 15:09:07.391674 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Psr16.php"] [unique_id "aqxW8xFTPRVSLOsRVhoacgAAARA"]
[Thu Sep 17 15:09:07.676852 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:47504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Redis.php"] [unique_id "aqxW8xFTPRVSLOsRVhoadQAAAUM"]
[Thu Sep 17 15:09:07.677018 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:47504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Redis.php"] [unique_id "aqxW8xFTPRVSLOsRVhoadQAAAUM"]
[Thu Sep 17 15:09:07.723594 2026] [security2:error] [pid 955873:tid 956014] [client 193.36.224.168:64323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/themes/style.php"] [unique_id "aqxW8xFTPRVSLOsRVhoaewAAARU"]
[Thu Sep 17 15:09:07.959032 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:47516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Caption.php"] [unique_id "aqxW8xFTPRVSLOsRVhoafQAAARM"]
[Thu Sep 17 15:09:07.959141 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:47516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Caption.php"] [unique_id "aqxW8xFTPRVSLOsRVhoafQAAARM"]
[Thu Sep 17 15:09:08.260043 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Category.php"] [unique_id "aqxW9BFTPRVSLOsRVhoaggAAAU8"]
[Thu Sep 17 15:09:08.260147 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Category.php"] [unique_id "aqxW9BFTPRVSLOsRVhoaggAAAU8"]
[Thu Sep 17 15:09:08.419544 2026] [security2:error] [pid 955873:tid 956054] [client 193.36.224.226:24183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-editor.php"] [unique_id "aqxW9BFTPRVSLOsRVhoahgAAAT0"]
[Thu Sep 17 15:09:08.542009 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/"] [unique_id "aqxW9BFTPRVSLOsRVhoaigAAAQw"]
[Thu Sep 17 15:09:08.707760 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/"] [unique_id "aqxW9BFTPRVSLOsRVhoaiwAAAS0"]
[Thu Sep 17 15:09:08.759073 2026] [security2:error] [pid 955873:tid 956109] [client 104.234.19.143:31787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/lufix.php"] [unique_id "aqxW9BFTPRVSLOsRVhoajwAAAXQ"]
[Thu Sep 17 15:09:08.851560 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/wp-includes/SimplePie/src/"] [unique_id "aqxW9BFTPRVSLOsRVhoakAAAAUc"]
[Thu Sep 17 15:09:08.952959 2026] [security2:error] [pid 955873:tid 956113] [client 4.240.114.86:61353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxW9BFTPRVSLOsRVhoalAAAAXg"], referer: binance.com
[Thu Sep 17 15:09:09.089034 2026] [security2:error] [pid 955873:tid 956044] [client 193.36.224.148:28647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/txets.php"] [unique_id "aqxW9RFTPRVSLOsRVhoalwAAATM"]
[Thu Sep 17 15:09:09.100895 2026] [security2:error] [pid 955873:tid 956125] [client 162.241.226.11:52654] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxW9RFTPRVSLOsRVhoalgAAAYQ"]
[Thu Sep 17 15:09:09.195449 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9BFTPRVSLOsRVhoalQAAAUg"]
[Thu Sep 17 15:09:09.195475 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9BFTPRVSLOsRVhoalQAAAUg"]
[Thu Sep 17 15:09:09.343122 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/"] [unique_id "aqxW9RFTPRVSLOsRVhoangAAAUQ"]
[Thu Sep 17 15:09:09.355474 2026] [security2:error] [pid 955873:tid 956092] [client 193.36.224.148:29017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxW9RFTPRVSLOsRVhoanwAAAWM"]
[Thu Sep 17 15:09:09.396071 2026] [security2:error] [pid 955873:tid 956058] [client 162.241.226.11:32906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxW9BFTPRVSLOsRVhoahAAAAUw"]
[Thu Sep 17 15:09:09.432497 2026] [security2:error] [pid 955873:tid 956013] [client 80.189.24.86:41297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoanQABFC4"]
[Thu Sep 17 15:09:09.502484 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/"] [unique_id "aqxW9RFTPRVSLOsRVhoaogAAAUs"]
[Thu Sep 17 15:09:09.644379 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/wp-includes/SimplePie/src/Content/"] [unique_id "aqxW9RFTPRVSLOsRVhoapAAAAT4"]
[Thu Sep 17 15:09:09.734317 2026] [security2:error] [pid 955873:tid 956062] [client 216.24.219.37:47511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/txets.php"] [unique_id "aqxW9RFTPRVSLOsRVhoapgAAAUU"]
[Thu Sep 17 15:09:09.978410 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoaqAAAAVU"]
[Thu Sep 17 15:09:09.978434 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoaqAAAAVU"]
[Thu Sep 17 15:09:10.082218 2026] [security2:error] [pid 955873:tid 956008] [client 186.105.232.15:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoarwAAAQ8"]
[Thu Sep 17 15:09:10.082334 2026] [security2:error] [pid 955873:tid 956008] [client 186.105.232.15:60191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoarwAAAQ8"]
[Thu Sep 17 15:09:10.120119 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:47534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/Sniffer.php"] [unique_id "aqxW9hFTPRVSLOsRVhoasAAAAXc"]
[Thu Sep 17 15:09:10.120224 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/Sniffer.php"] [unique_id "aqxW9hFTPRVSLOsRVhoasAAAAXc"]
[Thu Sep 17 15:09:10.286422 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoatAAAAXU"]
[Thu Sep 17 15:09:10.286575 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:53330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoatAAAAXU"]
[Thu Sep 17 15:09:10.291777 2026] [security2:error] [pid 955873:tid 956007] [client 216.24.219.101:61905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-includes/txets.php"] [unique_id "aqxW9hFTPRVSLOsRVhoatQAAAQ4"]
[Thu Sep 17 15:09:10.401037 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Copyright.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauAAAAYA"]
[Thu Sep 17 15:09:10.401142 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:59180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Copyright.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauAAAAYA"]
[Thu Sep 17 15:09:10.543285 2026] [security2:error] [pid 955873:tid 956118] [client 162.241.226.11:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoaoQAAAYY"]
[Thu Sep 17 15:09:10.692961 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Credit.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauwAAATA"]
[Thu Sep 17 15:09:10.693044 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:59188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Credit.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauwAAATA"]
[Thu Sep 17 15:09:10.803578 2026] [security2:error] [pid 955873:tid 956043] [client 45.169.98.18:64370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoavwAAATI"]
[Thu Sep 17 15:09:10.804097 2026] [security2:error] [pid 955873:tid 956043] [client 45.169.98.18:64370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoavwAAATI"]
[Thu Sep 17 15:09:10.979487 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Enclosure.php"] [unique_id "aqxW9hFTPRVSLOsRVhoawQAAASM"]
[Thu Sep 17 15:09:10.979570 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:59192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Enclosure.php"] [unique_id "aqxW9hFTPRVSLOsRVhoawQAAASM"]
[Thu Sep 17 15:09:11.266383 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Exception.php"] [unique_id "aqxW9xFTPRVSLOsRVhoaygAAAYQ"]
[Thu Sep 17 15:09:11.266478 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:59194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Exception.php"] [unique_id "aqxW9xFTPRVSLOsRVhoaygAAAYQ"]
[Thu Sep 17 15:09:11.542031 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/File.php"] [unique_id "aqxW9xFTPRVSLOsRVhoazQAAATg"]
[Thu Sep 17 15:09:11.542105 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/File.php"] [unique_id "aqxW9xFTPRVSLOsRVhoazQAAATg"]
[Thu Sep 17 15:09:11.824198 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Gzdecode.php"] [unique_id "aqxW9xFTPRVSLOsRVhoa0gAAAWM"]
[Thu Sep 17 15:09:11.824308 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:59212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Gzdecode.php"] [unique_id "aqxW9xFTPRVSLOsRVhoa0gAAAWM"]
[Thu Sep 17 15:09:12.134549 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:59224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/"] [unique_id "aqxW-BFTPRVSLOsRVhoa1gAAAQ0"]
[Thu Sep 17 15:09:12.297897 2026] [authz_core:error] [pid 955873:tid 956062] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/src/HTTP/error_log
[Thu Sep 17 15:09:12.302297 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/"] [unique_id "aqxW-BFTPRVSLOsRVhoa2gAAAUU"]
[Thu Sep 17 15:09:12.445295 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:59224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/wp-includes/SimplePie/src/"] [unique_id "aqxW-BFTPRVSLOsRVhoa3gAAASU"]
[Thu Sep 17 15:09:12.810436 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa4QAAAX4"]
[Thu Sep 17 15:09:12.810466 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa4QAAAX4"]
[Thu Sep 17 15:09:12.951701 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Client.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa8QAAAYU"]
[Thu Sep 17 15:09:12.951865 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Client.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa8QAAAYU"]
[Thu Sep 17 15:09:12.956509 2026] [security2:error] [pid 955873:tid 956015] [client 127.0.0.1:40804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxW-BFTPRVSLOsRVhoa8AAAARY"]
[Thu Sep 17 15:09:12.956581 2026] [security2:error] [pid 955873:tid 956022] [client 127.0.0.1:40802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.showtimeeventsvb.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxW-BFTPRVSLOsRVhoa7gAAAR0"]
[Thu Sep 17 15:09:12.956749 2026] [security2:error] [pid 955873:tid 956007] [client 74.7.228.8:47762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.showtimeeventsvb.com"] [uri "/robots.txt"] [unique_id "aqxW-BFTPRVSLOsRVhoa7QABDnI"]
[Thu Sep 17 15:09:12.960422 2026] [security2:error] [pid 955873:tid 956081] [client 4.240.114.86:63463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa8gAAAVg"], referer: binance.com
[Thu Sep 17 15:09:12.983708 2026] [security2:error] [pid 955873:tid 956104] [client 181.232.231.164:38465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa7AABb1s"]
[Thu Sep 17 15:09:13.124272 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa9wAAAXU"]
[Thu Sep 17 15:09:13.124348 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:58717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa9wAAAXU"]
[Thu Sep 17 15:09:13.238080 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/ClientException.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa-gAAAXE"]
[Thu Sep 17 15:09:13.238176 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:59234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/ClientException.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa-gAAAXE"]
[Thu Sep 17 15:09:13.266541 2026] [security2:error] [pid 955873:tid 955973] [remote 47.128.31.238:59768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cobblehillstudio.net"] [uri "/robots.txt"] [unique_id "aqxW-RFTPRVSLOsRVhoa-wABdmM"]
[Thu Sep 17 15:09:13.543896 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/FileClient.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa_gAAAVM"]
[Thu Sep 17 15:09:13.543979 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:59236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/FileClient.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa_gAAAVM"]
[Thu Sep 17 15:09:13.822459 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Parser.php"] [unique_id "aqxW-RFTPRVSLOsRVhobAwAAAU4"]
[Thu Sep 17 15:09:13.822554 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:59252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Parser.php"] [unique_id "aqxW-RFTPRVSLOsRVhobAwAAAU4"]
[Thu Sep 17 15:09:13.924506 2026] [security2:error] [pid 955873:tid 956045] [client 216.24.219.38:20953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/goods.php"] [unique_id "aqxW-RFTPRVSLOsRVhobBgAAATQ"]
[Thu Sep 17 15:09:14.098107 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr7Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobBwAAATg"]
[Thu Sep 17 15:09:14.098197 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr7Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobBwAAATg"]
[Thu Sep 17 15:09:14.375983 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr18Client.php"] [unique_id "aqxW-hFTPRVSLOsRVhobDwAAAUg"]
[Thu Sep 17 15:09:14.376090 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:59264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr18Client.php"] [unique_id "aqxW-hFTPRVSLOsRVhobDwAAAUg"]
[Thu Sep 17 15:09:14.619315 2026] [security2:error] [pid 955873:tid 956032] [client 104.28.198.244:22581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-hFTPRVSLOsRVhobFAAAASc"]
[Thu Sep 17 15:09:14.663595 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/RawTextResponse.php"] [unique_id "aqxW-hFTPRVSLOsRVhobGQAAASU"]
[Thu Sep 17 15:09:14.663717 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:59274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/RawTextResponse.php"] [unique_id "aqxW-hFTPRVSLOsRVhobGQAAASU"]
[Thu Sep 17 15:09:14.777321 2026] [security2:error] [pid 955873:tid 956032] [client 104.28.198.244:22581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-hFTPRVSLOsRVhobFAAAASc"]
[Thu Sep 17 15:09:14.989487 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobIAAAAW4"]
[Thu Sep 17 15:09:14.989612 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:59282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobIAAAAW4"]
[Thu Sep 17 15:09:15.275024 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/IRI.php"] [unique_id "aqxW-xFTPRVSLOsRVhobIwAAAYU"]
[Thu Sep 17 15:09:15.275131 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/IRI.php"] [unique_id "aqxW-xFTPRVSLOsRVhobIwAAAYU"]
[Thu Sep 17 15:09:15.288121 2026] [security2:error] [pid 955873:tid 956022] [client 216.24.219.89:52145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/php8.php"] [unique_id "aqxW-xFTPRVSLOsRVhobJgAAAR0"]
[Thu Sep 17 15:09:15.576399 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Item.php"] [unique_id "aqxW-xFTPRVSLOsRVhobKgAAAVA"]
[Thu Sep 17 15:09:15.576494 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:59310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Item.php"] [unique_id "aqxW-xFTPRVSLOsRVhobKgAAAVA"]
[Thu Sep 17 15:09:15.876713 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Locator.php"] [unique_id "aqxW-xFTPRVSLOsRVhobLQAAAXM"]
[Thu Sep 17 15:09:15.876814 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:59318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Locator.php"] [unique_id "aqxW-xFTPRVSLOsRVhobLQAAAXM"]
[Thu Sep 17 15:09:16.154399 2026] [security2:error] [pid 955873:tid 956123] [client 4.240.114.86:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxW_BFTPRVSLOsRVhobMgAAAYI"], referer: binance.com
[Thu Sep 17 15:09:16.161343 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Misc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobMwAAAWo"]
[Thu Sep 17 15:09:16.161426 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Misc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobMwAAAWo"]
[Thu Sep 17 15:09:16.356465 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobOQAAATc"]
[Thu Sep 17 15:09:16.356562 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobOQAAATc"]
[Thu Sep 17 15:09:16.457952 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:59330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/"] [unique_id "aqxW_BFTPRVSLOsRVhobOwAAAYQ"]
[Thu Sep 17 15:09:16.611602 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/"] [unique_id "aqxW_BFTPRVSLOsRVhobPgAAAXg"]
[Thu Sep 17 15:09:16.665163 2026] [security2:error] [pid 955873:tid 956056] [client 95.108.213.138:32948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/index.php"] [unique_id "aqxW_BFTPRVSLOsRVhobPQABPws"]
[Thu Sep 17 15:09:16.755162 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:59330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/wp-includes/SimplePie/src/"] [unique_id "aqxW_BFTPRVSLOsRVhobQwAAATk"]
[Thu Sep 17 15:09:16.927180 2026] [security2:error] [pid 955873:tid 956047] [client 40.87.20.23:61434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxW_BFTPRVSLOsRVhobRgAAATY"]
[Thu Sep 17 15:09:16.993422 2026] [security2:error] [pid 955873:tid 956013] [client 40.87.20.23:61434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=:"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxW_BFTPRVSLOsRVhobRwAAARQ"]
[Thu Sep 17 15:09:17.019328 2026] [security2:error] [pid 955873:tid 956051] [client 20.244.34.24:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxW_RFTPRVSLOsRVhobSAAAATo"], referer: binance.com
[Thu Sep 17 15:09:17.107455 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_BFTPRVSLOsRVhobRQAAARc"]
[Thu Sep 17 15:09:17.107482 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_BFTPRVSLOsRVhobRQAAARc"]
[Thu Sep 17 15:09:17.250118 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/IPv6.php"] [unique_id "aqxW_RFTPRVSLOsRVhobTAAAAVk"]
[Thu Sep 17 15:09:17.250214 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:59330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/IPv6.php"] [unique_id "aqxW_RFTPRVSLOsRVhobTAAAAVk"]
[Thu Sep 17 15:09:17.528716 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/"] [unique_id "aqxW_RFTPRVSLOsRVhobUgAAAVI"]
[Thu Sep 17 15:09:17.686709 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/"] [unique_id "aqxW_RFTPRVSLOsRVhobVAAAARk"]
[Thu Sep 17 15:09:17.824645 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/wp-includes/SimplePie/src/"] [unique_id "aqxW_RFTPRVSLOsRVhobXQAAAVg"]
[Thu Sep 17 15:09:18.152486 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_RFTPRVSLOsRVhobYQAAASg"]
[Thu Sep 17 15:09:18.152512 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_RFTPRVSLOsRVhobYQAAASg"]
[Thu Sep 17 15:09:18.293854 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/Date.php"] [unique_id "aqxW_hFTPRVSLOsRVhobZgAAASI"]
[Thu Sep 17 15:09:18.293923 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/Date.php"] [unique_id "aqxW_hFTPRVSLOsRVhobZgAAASI"]
[Thu Sep 17 15:09:18.363175 2026] [security2:error] [pid 955873:tid 955966] [remote 16.216.88.153:28672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.88.216.16.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/lgz-members-only-resources/"] [unique_id "aqxW_hFTPRVSLOsRVhobZwABNVw"]
[Thu Sep 17 15:09:18.583222 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parser.php"] [unique_id "aqxW_hFTPRVSLOsRVhobaQAAAXk"]
[Thu Sep 17 15:09:18.583297 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:59348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parser.php"] [unique_id "aqxW_hFTPRVSLOsRVhobaQAAAXk"]
[Thu Sep 17 15:09:18.870193 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Rating.php"] [unique_id "aqxW_hFTPRVSLOsRVhobbwAAARg"]
[Thu Sep 17 15:09:18.870289 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:59362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Rating.php"] [unique_id "aqxW_hFTPRVSLOsRVhobbwAAARg"]
[Thu Sep 17 15:09:19.124851 2026] [security2:error] [pid 955873:tid 956037] [client 17.166.233.26:53490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/index.php"] [unique_id "aqxW_xFTPRVSLOsRVhobcwABLGc"]
[Thu Sep 17 15:09:19.158722 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Registry.php"] [unique_id "aqxW_xFTPRVSLOsRVhobdQAAAVs"]
[Thu Sep 17 15:09:19.158810 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:59376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Registry.php"] [unique_id "aqxW_xFTPRVSLOsRVhobdQAAAVs"]
[Thu Sep 17 15:09:19.454729 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/RegistryAware.php"] [unique_id "aqxW_xFTPRVSLOsRVhobegAAAVw"]
[Thu Sep 17 15:09:19.454828 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:59380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/RegistryAware.php"] [unique_id "aqxW_xFTPRVSLOsRVhobegAAAVw"]
[Thu Sep 17 15:09:19.756357 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Restriction.php"] [unique_id "aqxW_xFTPRVSLOsRVhobfQAAARc"]
[Thu Sep 17 15:09:19.756471 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:59396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Restriction.php"] [unique_id "aqxW_xFTPRVSLOsRVhobfQAAARc"]
[Thu Sep 17 15:09:20.034122 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Sanitize.php"] [unique_id "aqxXABFTPRVSLOsRVhobfwAAATM"]
[Thu Sep 17 15:09:20.034208 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:50456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Sanitize.php"] [unique_id "aqxXABFTPRVSLOsRVhobfwAAATM"]
[Thu Sep 17 15:09:20.315644 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/SimplePie.php"] [unique_id "aqxXABFTPRVSLOsRVhobggAAAWE"]
[Thu Sep 17 15:09:20.315756 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:50464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/SimplePie.php"] [unique_id "aqxXABFTPRVSLOsRVhobggAAAWE"]
[Thu Sep 17 15:09:20.360322 2026] [security2:error] [pid 955873:tid 956129] [client 4.240.114.86:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxXABFTPRVSLOsRVhobhAAAAYg"], referer: binance.com
[Thu Sep 17 15:09:20.604724 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:50474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Source.php"] [unique_id "aqxXABFTPRVSLOsRVhobiAAAAWU"]
[Thu Sep 17 15:09:20.604809 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:50474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Source.php"] [unique_id "aqxXABFTPRVSLOsRVhobiAAAAWU"]
[Thu Sep 17 15:09:20.690914 2026] [authz_core:error] [pid 955873:tid 956077] [client 169.58.197.253:59493] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:09:20.883852 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/"] [unique_id "aqxXABFTPRVSLOsRVhobkAAAAVU"]
[Thu Sep 17 15:09:21.040505 2026] [security2:error] [pid 955873:tid 956089] [client 185.55.149.49:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkgAAAWA"]
[Thu Sep 17 15:09:21.040597 2026] [security2:error] [pid 955873:tid 956089] [client 185.55.149.49:59061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkgAAAWA"]
[Thu Sep 17 15:09:21.041168 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/"] [unique_id "aqxXARFTPRVSLOsRVhobkQAAAWY"]
[Thu Sep 17 15:09:21.046389 2026] [security2:error] [pid 955873:tid 956053] [client 186.105.232.15:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkwAAATw"]
[Thu Sep 17 15:09:21.046453 2026] [security2:error] [pid 955873:tid 956053] [client 186.105.232.15:60801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkwAAATw"]
[Thu Sep 17 15:09:21.180262 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/wp-includes/SimplePie/src/"] [unique_id "aqxXARFTPRVSLOsRVhoblAAAAVo"]
[Thu Sep 17 15:09:21.276437 2026] [security2:error] [pid 955873:tid 956079] [client 45.169.98.18:64936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhoblwAAAVY"]
[Thu Sep 17 15:09:21.276527 2026] [security2:error] [pid 955873:tid 956079] [client 45.169.98.18:64936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhoblwAAAVY"]
[Thu Sep 17 15:09:21.510132 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXARFTPRVSLOsRVhobmgAAATU"]
[Thu Sep 17 15:09:21.510158 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXARFTPRVSLOsRVhobmgAAATU"]
[Thu Sep 17 15:09:21.654928 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/"] [unique_id "aqxXARFTPRVSLOsRVhoboAAAAWs"]
[Thu Sep 17 15:09:21.987471 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/"] [unique_id "aqxXARFTPRVSLOsRVhobqAAAAT0"]
[Thu Sep 17 15:09:22.085269 2026] [core:error] [pid 955873:tid 956123] [client 142.93.220.18:48766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.085286 2026] [core:error] [pid 955873:tid 956123] [client 142.93.220.18:48766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.140320 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/wp-includes/SimplePie/src/XML/"] [unique_id "aqxXAhFTPRVSLOsRVhobqwAAAUI"]
[Thu Sep 17 15:09:22.481310 2026] [security2:error] [pid 955873:tid 956016] [client 5.58.77.106:39088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXAhFTPRVSLOsRVhobtAABF3A"]
[Thu Sep 17 15:09:22.481501 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAhFTPRVSLOsRVhobrwAAAVw"]
[Thu Sep 17 15:09:22.481514 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAhFTPRVSLOsRVhobrwAAAVw"]
[Thu Sep 17 15:09:22.625389 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/Parser.php"] [unique_id "aqxXAhFTPRVSLOsRVhobuQAAAUw"]
[Thu Sep 17 15:09:22.625495 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/Parser.php"] [unique_id "aqxXAhFTPRVSLOsRVhobuQAAAUw"]
[Thu Sep 17 15:09:22.849046 2026] [core:error] [pid 955873:tid 956068] [client 142.93.220.18:48780] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.849065 2026] [core:error] [pid 955873:tid 956068] [client 142.93.220.18:48780] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.913722 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/"] [unique_id "aqxXAhFTPRVSLOsRVhobwgAAAXo"]
[Thu Sep 17 15:09:23.082137 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/"] [unique_id "aqxXAxFTPRVSLOsRVhobxAAAAT4"]
[Thu Sep 17 15:09:23.219985 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "aqxXAxFTPRVSLOsRVhobyAAAAXw"]
[Thu Sep 17 15:09:23.353304 2026] [core:error] [pid 955873:tid 956081] [client 142.93.220.18:48784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.353323 2026] [core:error] [pid 955873:tid 956081] [client 142.93.220.18:48784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.379082 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "aqxXAxFTPRVSLOsRVhobzAAAARI"]
[Thu Sep 17 15:09:23.519023 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/wp-includes/Text/"] [unique_id "aqxXAxFTPRVSLOsRVhobzgAAASQ"]
[Thu Sep 17 15:09:23.705302 2026] [security2:error] [pid 955873:tid 956127] [client 210.222.43.21:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhobzwAAAYY"], referer: http://talent-in-borders.com/bc
[Thu Sep 17 15:09:23.727317 2026] [security2:error] [pid 955873:tid 956022] [client 115.244.164.14:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0QAAAR0"]
[Thu Sep 17 15:09:23.727407 2026] [security2:error] [pid 955873:tid 956022] [client 115.244.164.14:59359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0QAAAR0"]
[Thu Sep 17 15:09:23.857775 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0AAAAWA"]
[Thu Sep 17 15:09:23.857797 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0AAAAWA"]
[Thu Sep 17 15:09:23.969795 2026] [core:error] [pid 955873:tid 956120] [client 142.93.220.18:48794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.969814 2026] [core:error] [pid 955873:tid 956120] [client 142.93.220.18:48794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.998224 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "aqxXAxFTPRVSLOsRVhob2AAAAXE"]
[Thu Sep 17 15:09:24.167014 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "aqxXBBFTPRVSLOsRVhob3AAAATU"]
[Thu Sep 17 15:09:24.322191 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/wp-includes/Text/Diff/"] [unique_id "aqxXBBFTPRVSLOsRVhob4AAAAXc"]
[Thu Sep 17 15:09:24.463129 2026] [core:error] [pid 955873:tid 956038] [client 142.93.220.18:48806] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:24.463152 2026] [core:error] [pid 955873:tid 956038] [client 142.93.220.18:48806] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:24.658491 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBBFTPRVSLOsRVhob4wAAAR8"]
[Thu Sep 17 15:09:24.658515 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBBFTPRVSLOsRVhob4wAAAR8"]
[Thu Sep 17 15:09:24.797958 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:50496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/native.php"] [unique_id "aqxXBBFTPRVSLOsRVhob5wAAAXg"]
[Thu Sep 17 15:09:24.798054 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/native.php"] [unique_id "aqxXBBFTPRVSLOsRVhob5wAAAXg"]
[Thu Sep 17 15:09:24.884914 2026] [security2:error] [pid 955873:tid 956017] [client 20.244.34.24:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXBBFTPRVSLOsRVhob6QAAARg"], referer: binance.com
[Thu Sep 17 15:09:24.932854 2026] [core:error] [pid 955873:tid 956023] [client 142.93.220.18:48808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:24.932873 2026] [core:error] [pid 955873:tid 956023] [client 142.93.220.18:48808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:25.079824 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/shell.php"] [unique_id "aqxXBRFTPRVSLOsRVhob7gAAAQo"]
[Thu Sep 17 15:09:25.079939 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:50498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/shell.php"] [unique_id "aqxXBRFTPRVSLOsRVhob7gAAAQo"]
[Thu Sep 17 15:09:25.366776 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:50510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/string.php"] [unique_id "aqxXBRFTPRVSLOsRVhob9wAAAVk"]
[Thu Sep 17 15:09:25.366888 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:50510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/string.php"] [unique_id "aqxXBRFTPRVSLOsRVhob9wAAAVk"]
[Thu Sep 17 15:09:25.676858 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/xdiff.php"] [unique_id "aqxXBRFTPRVSLOsRVhob_AAAAVQ"]
[Thu Sep 17 15:09:25.676977 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:50514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/xdiff.php"] [unique_id "aqxXBRFTPRVSLOsRVhob_AAAAVQ"]
[Thu Sep 17 15:09:25.829579 2026] [security2:error] [pid 955873:tid 956049] [client 4.240.114.86:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxXBRFTPRVSLOsRVhocAQAAATg"], referer: binance.com
[Thu Sep 17 15:09:25.961794 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer.php"] [unique_id "aqxXBRFTPRVSLOsRVhocBAAAASQ"]
[Thu Sep 17 15:09:25.961947 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer.php"] [unique_id "aqxXBRFTPRVSLOsRVhocBAAAASQ"]
[Thu Sep 17 15:09:26.005879 2026] [security2:error] [pid 955873:tid 956025] [client 74.7.241.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jewishgrimsby.com"] [uri "/index.php"] [unique_id "aqxXARFTPRVSLOsRVhoblgABIA0"]
[Thu Sep 17 15:09:26.170895 2026] [security2:error] [pid 955873:tid 956015] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocBgAAARY"]
[Thu Sep 17 15:09:26.243226 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:50536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXBhFTPRVSLOsRVhocCwAAAVY"]
[Thu Sep 17 15:09:26.243449 2026] [security2:error] [pid 955873:tid 956083] [client 45.175.15.193:35214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocCgABWho"]
[Thu Sep 17 15:09:26.399789 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXBhFTPRVSLOsRVhocDgAAARM"]
[Thu Sep 17 15:09:26.543940 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:50536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/wp-includes/Text/Diff/"] [unique_id "aqxXBhFTPRVSLOsRVhocEQAAASM"]
[Thu Sep 17 15:09:26.629793 2026] [security2:error] [pid 955873:tid 956103] [client 74.7.228.50:56530] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "30daychallenge.toolsforthejourney.com"] [uri "/index.php"] [unique_id "aqxXBBFTPRVSLOsRVhob6AABbgA"]
[Thu Sep 17 15:09:26.778646 2026] [security2:error] [pid 955873:tid 956112] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env"] [unique_id "aqxXBhFTPRVSLOsRVhocEwAAAXc"]
[Thu Sep 17 15:09:26.866172 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocEgAAARw"]
[Thu Sep 17 15:09:26.866202 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocEgAAARw"]
[Thu Sep 17 15:09:26.914119 2026] [security2:error] [pid 955873:tid 956108] [client 154.190.208.131:42639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXBhFTPRVSLOsRVhocGAAAAXM"]
[Thu Sep 17 15:09:26.917933 2026] [security2:error] [pid 955873:tid 956108] [client 154.190.208.131:42639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXBhFTPRVSLOsRVhocGAAAAXM"]
[Thu Sep 17 15:09:27.007210 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:50536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/inline.php"] [unique_id "aqxXBxFTPRVSLOsRVhocGQAAAU4"]
[Thu Sep 17 15:09:27.007351 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:50536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/inline.php"] [unique_id "aqxXBxFTPRVSLOsRVhocGQAAAU4"]
[Thu Sep 17 15:09:27.092138 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocGgAAAVE"]
[Thu Sep 17 15:09:27.294464 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxXBxFTPRVSLOsRVhocHgAAAUM"]
[Thu Sep 17 15:09:27.376139 2026] [security2:error] [pid 955873:tid 956037] [client 169.58.27.94:37501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.27.58.169.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "showtimeeventsvb.com"] [uri "/wp-login.php"] [unique_id "aqxXBxFTPRVSLOsRVhocIAAAASw"]
[Thu Sep 17 15:09:27.411558 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocHwAAATE"]
[Thu Sep 17 15:09:27.617326 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocIQAAAUI"]
[Thu Sep 17 15:09:27.617347 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocIQAAAUI"]
[Thu Sep 17 15:09:27.727966 2026] [security2:error] [pid 955873:tid 956085] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocJAAAAVw"]
[Thu Sep 17 15:09:27.764223 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxXBxFTPRVSLOsRVhocKAAAAQw"]
[Thu Sep 17 15:09:28.056952 2026] [security2:error] [pid 955873:tid 956069] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocLgAAAUw"]
[Thu Sep 17 15:09:28.090848 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocLQAAAVk"]
[Thu Sep 17 15:09:28.090872 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocLQAAAVk"]
[Thu Sep 17 15:09:28.143981 2026] [security2:error] [pid 955873:tid 956070] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhob1gABTU8"], referer: http://ourstraytribe.com/blog/
[Thu Sep 17 15:09:28.212585 2026] [security2:error] [pid 955873:tid 956043] [client 104.28.198.244:22783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCBFTPRVSLOsRVhocMgAAATI"]
[Thu Sep 17 15:09:28.212690 2026] [security2:error] [pid 955873:tid 956043] [client 104.28.198.244:22783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCBFTPRVSLOsRVhocMgAAATI"]
[Thu Sep 17 15:09:28.235776 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxXCBFTPRVSLOsRVhocNAAAAUs"]
[Thu Sep 17 15:09:28.331489 2026] [security2:error] [pid 955873:tid 956008] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocMwABDzo"], referer: http://ourstraytribe.com/backup/
[Thu Sep 17 15:09:28.392828 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocOgAAAWE"]
[Thu Sep 17 15:09:28.507380 2026] [security2:error] [pid 955873:tid 956098] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocQQABaTU"], referer: http://ourstraytribe.com/wp/
[Thu Sep 17 15:09:28.597839 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocPgAAAV0"]
[Thu Sep 17 15:09:28.597863 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocPgAAAV0"]
[Thu Sep 17 15:09:28.724326 2026] [security2:error] [pid 955873:tid 956081] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocRQABWEU"], referer: http://ourstraytribe.com/wordpress/
[Thu Sep 17 15:09:28.725769 2026] [security2:error] [pid 955873:tid 956011] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocRgAAARI"]
[Thu Sep 17 15:09:28.742847 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxXCBFTPRVSLOsRVhocRwAAASQ"]
[Thu Sep 17 15:09:28.895604 2026] [security2:error] [pid 955873:tid 956033] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocSwABKBA"], referer: http://ourstraytribe.com/old/
[Thu Sep 17 15:09:28.909846 2026] [authz_core:error] [pid 955873:tid 956127] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-content/mu-plugins/error_log
[Thu Sep 17 15:09:28.910622 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxXCBFTPRVSLOsRVhocTgAAAYY"]
[Thu Sep 17 15:09:28.976544 2026] [security2:error] [pid 955873:tid 956079] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.bak"] [unique_id "aqxXCBFTPRVSLOsRVhocUgAAAVY"]
[Thu Sep 17 15:09:29.053046 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/sso.php"] [unique_id "aqxXCRFTPRVSLOsRVhocVgAAATU"]
[Thu Sep 17 15:09:29.053154 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/sso.php"] [unique_id "aqxXCRFTPRVSLOsRVhocVgAAATU"]
[Thu Sep 17 15:09:29.061344 2026] [security2:error] [pid 955873:tid 956117] [client 162.241.226.11:42670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocTAAAAXw"]
[Thu Sep 17 15:09:29.090241 2026] [security2:error] [pid 955873:tid 956083] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocUwABWgU"], referer: http://ourstraytribe.com/new/
[Thu Sep 17 15:09:29.217726 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.backup"] [unique_id "aqxXCRFTPRVSLOsRVhocWwAAAXQ"]
[Thu Sep 17 15:09:29.240102 2026] [security2:error] [pid 955873:tid 956119] [client 162.241.226.11:42672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCRFTPRVSLOsRVhocVwAAAX4"]
[Thu Sep 17 15:09:29.330472 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXCRFTPRVSLOsRVhocXAAAAVM"]
[Thu Sep 17 15:09:29.489971 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXCRFTPRVSLOsRVhocYwAAATc"]
[Thu Sep 17 15:09:29.535320 2026] [security2:error] [pid 955873:tid 956060] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCRFTPRVSLOsRVhocYgAAAUM"]
[Thu Sep 17 15:09:29.629226 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/blocks/"] [unique_id "aqxXCRFTPRVSLOsRVhocZQAAAW0"]
[Thu Sep 17 15:09:29.768891 2026] [security2:error] [pid 955873:tid 956107] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.old"] [unique_id "aqxXCRFTPRVSLOsRVhocZwAAAXI"]
[Thu Sep 17 15:09:29.781051 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxXCRFTPRVSLOsRVhocZgAAAS4"]
[Thu Sep 17 15:09:29.920680 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxXCRFTPRVSLOsRVhocawAAATk"]
[Thu Sep 17 15:09:30.072976 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxXChFTPRVSLOsRVhocbQAAAUg"]
[Thu Sep 17 15:09:30.080124 2026] [security2:error] [pid 955873:tid 956041] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhocbAAAATA"]
[Thu Sep 17 15:09:30.210818 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/"] [unique_id "aqxXChFTPRVSLOsRVhocbwAAATo"]
[Thu Sep 17 15:09:30.371801 2026] [authz_core:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/customize/error_log
[Thu Sep 17 15:09:30.386409 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/"] [unique_id "aqxXChFTPRVSLOsRVhocdAAAAUE"]
[Thu Sep 17 15:09:30.391405 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhoccgAAAVk"]
[Thu Sep 17 15:09:30.528087 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-control.php"] [unique_id "aqxXChFTPRVSLOsRVhoceAAAAUs"]
[Thu Sep 17 15:09:30.528200 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-control.php"] [unique_id "aqxXChFTPRVSLOsRVhoceAAAAUs"]
[Thu Sep 17 15:09:30.713620 2026] [security2:error] [pid 955873:tid 956052] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhocewAAATs"]
[Thu Sep 17 15:09:30.811828 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-setting.php"] [unique_id "aqxXChFTPRVSLOsRVhocfwAAAWk"]
[Thu Sep 17 15:09:30.811925 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:55060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-setting.php"] [unique_id "aqxXChFTPRVSLOsRVhocfwAAAWk"]
[Thu Sep 17 15:09:31.029074 2026] [security2:error] [pid 955873:tid 956075] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhocgAAAAVI"]
[Thu Sep 17 15:09:31.093339 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-position-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocggAAARE"]
[Thu Sep 17 15:09:31.093433 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:55068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-position-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocggAAARE"]
[Thu Sep 17 15:09:31.192069 2026] [security2:error] [pid 955873:tid 956080] [client 4.240.114.86:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxXCxFTPRVSLOsRVhocgwAAAVc"], referer: binance.com
[Thu Sep 17 15:09:31.340886 2026] [security2:error] [pid 955873:tid 956007] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCxFTPRVSLOsRVhochQAAAQ4"]
[Thu Sep 17 15:09:31.373719 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-code-editor-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhociAAAATM"]
[Thu Sep 17 15:09:31.373824 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:55084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-code-editor-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhociAAAATM"]
[Thu Sep 17 15:09:31.657626 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:55098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-color-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjAAAAXE"]
[Thu Sep 17 15:09:31.657745 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:55098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-color-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjAAAAXE"]
[Thu Sep 17 15:09:31.663468 2026] [security2:error] [pid 955873:tid 956062] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCxFTPRVSLOsRVhociwAAAUU"]
[Thu Sep 17 15:09:31.750424 2026] [security2:error] [pid 955873:tid 956055] [client 45.169.98.18:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjQAAAT4"]
[Thu Sep 17 15:09:31.750527 2026] [security2:error] [pid 955873:tid 956055] [client 45.169.98.18:65496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjQAAAT4"]
[Thu Sep 17 15:09:31.754744 2026] [security2:error] [pid 955873:tid 956120] [client 185.55.149.49:54157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjgAAAX8"]
[Thu Sep 17 15:09:31.754818 2026] [security2:error] [pid 955873:tid 956120] [client 185.55.149.49:54157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjgAAAX8"]
[Thu Sep 17 15:09:31.964875 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhockwAAARw"]
[Thu Sep 17 15:09:31.964966 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:55100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhockwAAARw"]
[Thu Sep 17 15:09:31.972183 2026] [security2:error] [pid 955873:tid 956019] [client 186.105.232.15:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhoclAAAARo"]
[Thu Sep 17 15:09:31.972285 2026] [security2:error] [pid 955873:tid 956019] [client 186.105.232.15:61391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhoclAAAARo"]
[Thu Sep 17 15:09:31.972852 2026] [security2:error] [pid 955873:tid 956083] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCxFTPRVSLOsRVhockgAAAVo"]
[Thu Sep 17 15:09:32.277685 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-custom-css-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocmAAAAYI"]
[Thu Sep 17 15:09:32.277802 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:55116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-custom-css-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocmAAAAYI"]
[Thu Sep 17 15:09:32.289614 2026] [security2:error] [pid 955873:tid 956097] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhoclwAAAWg"]
[Thu Sep 17 15:09:32.432318 2026] [security2:error] [pid 955873:tid 956074] [client 177.245.246.91:10340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhocnAABUTk"]
[Thu Sep 17 15:09:32.561012 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-date-time-control.php"] [unique_id "aqxXDBFTPRVSLOsRVhocoAAAAR8"]
[Thu Sep 17 15:09:32.561134 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:55128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-date-time-control.php"] [unique_id "aqxXDBFTPRVSLOsRVhocoAAAAR8"]
[Thu Sep 17 15:09:32.616320 2026] [security2:error] [pid 955873:tid 956026] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhocnwAAASE"]
[Thu Sep 17 15:09:32.851461 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-filter-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocpgAAAQw"]
[Thu Sep 17 15:09:32.851558 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:55140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-filter-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocpgAAAQw"]
[Thu Sep 17 15:09:32.931391 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhocpwAAAUg"]
[Thu Sep 17 15:09:33.137118 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocsgAAAUs"]
[Thu Sep 17 15:09:33.137230 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocsgAAAUs"]
[Thu Sep 17 15:09:33.245905 2026] [security2:error] [pid 955873:tid 956069] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDRFTPRVSLOsRVhocswAAAUw"]
[Thu Sep 17 15:09:33.446301 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:55148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-setting.php"] [unique_id "aqxXDRFTPRVSLOsRVhocuQAAARQ"]
[Thu Sep 17 15:09:33.446397 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:55148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-setting.php"] [unique_id "aqxXDRFTPRVSLOsRVhocuQAAARQ"]
[Thu Sep 17 15:09:33.487134 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.swp"] [unique_id "aqxXDRFTPRVSLOsRVhocugAAAYc"]
[Thu Sep 17 15:09:33.721804 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env~"] [unique_id "aqxXDRFTPRVSLOsRVhocvwAAAV0"]
[Thu Sep 17 15:09:33.732303 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:55152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocwAAAARU"]
[Thu Sep 17 15:09:33.732416 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:55152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocwAAAARU"]
[Thu Sep 17 15:09:34.015706 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-media-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhocxwAAAR0"]
[Thu Sep 17 15:09:34.015820 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:55158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-media-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhocxwAAAR0"]
[Thu Sep 17 15:09:34.048017 2026] [security2:error] [pid 955873:tid 956056] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDRFTPRVSLOsRVhocxgAAAT8"]
[Thu Sep 17 15:09:34.281613 2026] [security2:error] [pid 955873:tid 956127] [client 115.244.164.14:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0AAAAYY"]
[Thu Sep 17 15:09:34.281725 2026] [security2:error] [pid 955873:tid 956127] [client 115.244.164.14:59997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0AAAAYY"]
[Thu Sep 17 15:09:34.311309 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:55160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0gAAAYA"]
[Thu Sep 17 15:09:34.311449 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:55160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0gAAAYA"]
[Thu Sep 17 15:09:34.371942 2026] [security2:error] [pid 955873:tid 956104] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0QAAAW8"]
[Thu Sep 17 15:09:34.605341 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc2wAAAUA"]
[Thu Sep 17 15:09:34.605429 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:55170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc2wAAAUA"]
[Thu Sep 17 15:09:34.692026 2026] [security2:error] [pid 955873:tid 956076] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc3AAAAVM"]
[Thu Sep 17 15:09:34.902425 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc5QAAAW0"]
[Thu Sep 17 15:09:34.902559 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:55178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc5QAAAW0"]
[Thu Sep 17 15:09:35.011266 2026] [security2:error] [pid 955873:tid 956005] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc6QAAAQw"]
[Thu Sep 17 15:09:35.147066 2026] [security2:error] [pid 955873:tid 956085] [client 176.29.238.12:2270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc6wABXE0"]
[Thu Sep 17 15:09:35.185796 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-setting.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc7AAAAUs"]
[Thu Sep 17 15:09:35.185901 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-setting.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc7AAAAUs"]
[Thu Sep 17 15:09:35.337541 2026] [security2:error] [pid 955873:tid 956061] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc7QAAAUQ"]
[Thu Sep 17 15:09:35.469401 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:55200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-location-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc9QAAASY"]
[Thu Sep 17 15:09:35.469509 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:55200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-location-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc9QAAASY"]
[Thu Sep 17 15:09:35.656029 2026] [security2:error] [pid 955873:tid 956010] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc9wAAARE"]
[Thu Sep 17 15:09:35.761601 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-locations-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc-AAAASc"]
[Thu Sep 17 15:09:35.761737 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:55214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-locations-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc-AAAASc"]
[Thu Sep 17 15:09:35.973972 2026] [security2:error] [pid 955873:tid 956126] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc-wAAAYU"]
[Thu Sep 17 15:09:36.062508 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-name-control.php"] [unique_id "aqxXEBFTPRVSLOsRVhoc_wAAAWE"]
[Thu Sep 17 15:09:36.062627 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:55216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-name-control.php"] [unique_id "aqxXEBFTPRVSLOsRVhoc_wAAAWE"]
[Thu Sep 17 15:09:36.211381 2026] [security2:error] [pid 955873:tid 956110] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/app/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodAQAAAXU"]
[Thu Sep 17 15:09:36.349381 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section.php"] [unique_id "aqxXEBFTPRVSLOsRVhodBAAAAX8"]
[Thu Sep 17 15:09:36.349486 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:55218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section.php"] [unique_id "aqxXEBFTPRVSLOsRVhodBAAAAX8"]
[Thu Sep 17 15:09:36.451370 2026] [security2:error] [pid 955873:tid 956121] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/apps/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodBgAAAYA"]
[Thu Sep 17 15:09:36.653912 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-setting.php"] [unique_id "aqxXEBFTPRVSLOsRVhodCAAAARo"]
[Thu Sep 17 15:09:36.654038 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:55224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-setting.php"] [unique_id "aqxXEBFTPRVSLOsRVhodCAAAARo"]
[Thu Sep 17 15:09:36.689146 2026] [security2:error] [pid 955873:tid 956007] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodCQAAAQ4"]
[Thu Sep 17 15:09:36.774344 2026] [security2:error] [pid 955873:tid 956128] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mythicexpeditionspress.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc8wAAAYc"]
[Thu Sep 17 15:09:36.781878 2026] [security2:error] [pid 955873:tid 956122] [client 74.7.230.49:46274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mythicexpeditionspress.com"] [uri "/robots.txt"] [unique_id "aqxXDxFTPRVSLOsRVhoc7wABgUw"]
[Thu Sep 17 15:09:36.855576 2026] [security2:error] [pid 955873:tid 956127] [client 104.28.198.244:22790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXEBFTPRVSLOsRVhodDgAAAYY"]
[Thu Sep 17 15:09:36.855692 2026] [security2:error] [pid 955873:tid 956127] [client 104.28.198.244:22790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXEBFTPRVSLOsRVhodDgAAAYY"]
[Thu Sep 17 15:09:36.927900 2026] [security2:error] [pid 955873:tid 956054] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/web/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodEAAAAT0"]
[Thu Sep 17 15:09:36.937711 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menus-panel.php"] [unique_id "aqxXEBFTPRVSLOsRVhodEQAAAU8"]
[Thu Sep 17 15:09:36.937839 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:55234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menus-panel.php"] [unique_id "aqxXEBFTPRVSLOsRVhodEQAAAU8"]
[Thu Sep 17 15:09:37.109746 2026] [security2:error] [pid 955873:tid 956071] [client 4.240.114.86:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxXERFTPRVSLOsRVhodEwAAAU4"], referer: binance.com
[Thu Sep 17 15:09:37.167176 2026] [security2:error] [pid 955873:tid 956018] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/site/.env"] [unique_id "aqxXERFTPRVSLOsRVhodFAAAARk"]
[Thu Sep 17 15:09:37.215544 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-control.php"] [unique_id "aqxXERFTPRVSLOsRVhodFQAAAXg"]
[Thu Sep 17 15:09:37.215651 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:55248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-control.php"] [unique_id "aqxXERFTPRVSLOsRVhodFQAAAXg"]
[Thu Sep 17 15:09:37.400040 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/public/.env"] [unique_id "aqxXERFTPRVSLOsRVhodGgAAATE"]
[Thu Sep 17 15:09:37.496421 2026] [security2:error] [pid 955873:tid 956057] [client 154.190.208.131:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXERFTPRVSLOsRVhodGwAAAUA"]
[Thu Sep 17 15:09:37.497959 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-section.php"] [unique_id "aqxXERFTPRVSLOsRVhodHAAAAUg"]
[Thu Sep 17 15:09:37.498097 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:55264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-section.php"] [unique_id "aqxXERFTPRVSLOsRVhodHAAAAUg"]
[Thu Sep 17 15:09:37.505984 2026] [security2:error] [pid 955873:tid 956057] [client 154.190.208.131:41886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXERFTPRVSLOsRVhodGwAAAUA"]
[Thu Sep 17 15:09:37.595764 2026] [security2:error] [pid 955873:tid 956095] [client 52.167.144.54:64468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc2AABZi4"]
[Thu Sep 17 15:09:37.722459 2026] [security2:error] [pid 955873:tid 956058] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXERFTPRVSLOsRVhodHwAAAUE"]
[Thu Sep 17 15:09:37.776578 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-partial.php"] [unique_id "aqxXERFTPRVSLOsRVhodIwAAAUk"]
[Thu Sep 17 15:09:37.776681 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:55272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-partial.php"] [unique_id "aqxXERFTPRVSLOsRVhodIwAAAUk"]
[Thu Sep 17 15:09:37.963940 2026] [security2:error] [pid 955873:tid 956101] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/backend/.env"] [unique_id "aqxXERFTPRVSLOsRVhodKAAAAWw"]
[Thu Sep 17 15:09:38.083932 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh.php"] [unique_id "aqxXEhFTPRVSLOsRVhodKQAAASI"]
[Thu Sep 17 15:09:38.084015 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:55278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh.php"] [unique_id "aqxXEhFTPRVSLOsRVhodKQAAASI"]
[Thu Sep 17 15:09:38.202850 2026] [security2:error] [pid 955873:tid 956049] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/server/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodKgAAATg"]
[Thu Sep 17 15:09:38.373455 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-sidebar-section.php"] [unique_id "aqxXEhFTPRVSLOsRVhodMAAAAYU"]
[Thu Sep 17 15:09:38.373542 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:55280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-sidebar-section.php"] [unique_id "aqxXEhFTPRVSLOsRVhodMAAAAYU"]
[Thu Sep 17 15:09:38.442011 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/frontend/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodMgAAAWA"]
[Thu Sep 17 15:09:38.653210 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-site-icon-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodNQAAAYM"]
[Thu Sep 17 15:09:38.653307 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:55288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-site-icon-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodNQAAAYM"]
[Thu Sep 17 15:09:38.678671 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/src/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodNwAAASA"]
[Thu Sep 17 15:09:38.797937 2026] [security2:error] [pid 955873:tid 956052] [client 47.79.200.121:22650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXEhFTPRVSLOsRVhodNAAAATs"], referer: https://www.google.com/
[Thu Sep 17 15:09:38.915280 2026] [security2:error] [pid 955873:tid 956103] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/core/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodOwAAAW4"]
[Thu Sep 17 15:09:38.964864 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-theme-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodPwAAATo"]
[Thu Sep 17 15:09:38.964987 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:55294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-theme-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodPwAAATo"]
[Thu Sep 17 15:09:39.153729 2026] [security2:error] [pid 955873:tid 956106] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/core/app/.env"] [unique_id "aqxXExFTPRVSLOsRVhodQQAAAXE"]
[Thu Sep 17 15:09:39.254983 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-panel.php"] [unique_id "aqxXExFTPRVSLOsRVhodQwAAARM"]
[Thu Sep 17 15:09:39.255063 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:55310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-panel.php"] [unique_id "aqxXExFTPRVSLOsRVhodQwAAARM"]
[Thu Sep 17 15:09:39.392674 2026] [security2:error] [pid 955873:tid 956096] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/config/.env"] [unique_id "aqxXExFTPRVSLOsRVhodSAAAAWc"]
[Thu Sep 17 15:09:39.562125 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-section.php"] [unique_id "aqxXExFTPRVSLOsRVhodTAAAARk"]
[Thu Sep 17 15:09:39.562214 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:55312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-section.php"] [unique_id "aqxXExFTPRVSLOsRVhodTAAAARk"]
[Thu Sep 17 15:09:39.627824 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/private/.env"] [unique_id "aqxXExFTPRVSLOsRVhodTQAAAXY"]
[Thu Sep 17 15:09:39.843266 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-upload-control.php"] [unique_id "aqxXExFTPRVSLOsRVhodTwAAASs"]
[Thu Sep 17 15:09:39.843374 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:55320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-upload-control.php"] [unique_id "aqxXExFTPRVSLOsRVhodTwAAASs"]
[Thu Sep 17 15:09:39.864858 2026] [security2:error] [pid 955873:tid 956102] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/application/.env"] [unique_id "aqxXExFTPRVSLOsRVhodUgAAAW0"]
[Thu Sep 17 15:09:40.100769 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/bootstrap/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodVQAAAUg"]
[Thu Sep 17 15:09:40.128752 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:52908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-sidebar-block-editor-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodVgAAATY"]
[Thu Sep 17 15:09:40.128836 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:52908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-sidebar-block-editor-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodVgAAATY"]
[Thu Sep 17 15:09:40.337894 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/database/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodWAAAAVE"]
[Thu Sep 17 15:09:40.406620 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXAAAAR8"]
[Thu Sep 17 15:09:40.406728 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXAAAAR8"]
[Thu Sep 17 15:09:40.574979 2026] [security2:error] [pid 955873:tid 956050] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/storage/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodXgAAATk"]
[Thu Sep 17 15:09:40.698894 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:52932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-form-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXwAAAVs"]
[Thu Sep 17 15:09:40.699005 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:52932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-form-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXwAAAVs"]
[Thu Sep 17 15:09:40.808281 2026] [security2:error] [pid 955873:tid 956115] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/var/www/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodYAAAAXo"]
[Thu Sep 17 15:09:40.979356 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxXFBFTPRVSLOsRVhodZgAAAVQ"]
[Thu Sep 17 15:09:41.040834 2026] [security2:error] [pid 955873:tid 956061] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/var/www/html/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodaAAAAUQ"]
[Thu Sep 17 15:09:41.273233 2026] [security2:error] [pid 955873:tid 956091] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/current/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodbQAAAWI"]
[Thu Sep 17 15:09:41.487403 2026] [security2:error] [pid 955873:tid 956082] [client 34.87.188.48:60676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "blacksaabath.theworldinc.com"] [uri "/"] [unique_id "aqxXFRFTPRVSLOsRVhodcQAAAVk"]
[Thu Sep 17 15:09:41.511970 2026] [security2:error] [pid 955873:tid 956079] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/release/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodcwAAAVY"]
[Thu Sep 17 15:09:41.554007 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxXFRFTPRVSLOsRVhoddAAAAQs"]
[Thu Sep 17 15:09:41.719337 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxXFRFTPRVSLOsRVhodeAAAAW4"]
[Thu Sep 17 15:09:41.719435 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxXFRFTPRVSLOsRVhodeAAAAW4"]
[Thu Sep 17 15:09:41.751755 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/releases/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodegAAARw"]
[Thu Sep 17 15:09:41.995200 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/shared/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodfwAAAYc"]
[Thu Sep 17 15:09:42.002230 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxXFhFTPRVSLOsRVhodgAAAATQ"]
[Thu Sep 17 15:09:42.002308 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxXFhFTPRVSLOsRVhodgAAAATQ"]
[Thu Sep 17 15:09:42.237452 2026] [security2:error] [pid 955873:tid 956078] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/deploy/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodhAAAAVU"]
[Thu Sep 17 15:09:42.259964 2026] [security2:error] [pid 955873:tid 956096] [client 45.169.98.18:49983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhgAAAWc"]
[Thu Sep 17 15:09:42.260067 2026] [security2:error] [pid 955873:tid 956096] [client 45.169.98.18:49983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhgAAAWc"]
[Thu Sep 17 15:09:42.265547 2026] [security2:error] [pid 955873:tid 956059] [client 35.204.107.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.brownsdailydose.com"] [uri "/index.php"] [unique_id "aqxXFhFTPRVSLOsRVhodgwAAAUI"], referer: http://www.brownsdailydose.com/robots.txt
[Thu Sep 17 15:09:42.293122 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhwAAAU0"]
[Thu Sep 17 15:09:42.293197 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhwAAAU0"]
[Thu Sep 17 15:09:42.399947 2026] [authz_core:error] [pid 955873:tid 956029] [client 169.58.197.253:60858] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:09:42.433313 2026] [security2:error] [pid 955873:tid 956054] [client 185.55.149.49:54778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodjwAAAT0"]
[Thu Sep 17 15:09:42.433406 2026] [security2:error] [pid 955873:tid 956054] [client 185.55.149.49:54778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodjwAAAT0"]
[Thu Sep 17 15:09:42.475967 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/build/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodkAAAAXY"]
[Thu Sep 17 15:09:42.598917 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxXFhFTPRVSLOsRVhodkgAAASs"]
[Thu Sep 17 15:09:42.599004 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxXFhFTPRVSLOsRVhodkgAAASs"]
[Thu Sep 17 15:09:42.715985 2026] [security2:error] [pid 955873:tid 956092] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/dist/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodlQAAAWM"]
[Thu Sep 17 15:09:42.846818 2026] [security2:error] [pid 955873:tid 956069] [client 186.105.232.15:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodmgAAAUw"]
[Thu Sep 17 15:09:42.846943 2026] [security2:error] [pid 955873:tid 956069] [client 186.105.232.15:61972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodmgAAAUw"]
[Thu Sep 17 15:09:42.896084 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxXFhFTPRVSLOsRVhodnAAAAQw"]
[Thu Sep 17 15:09:42.896193 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxXFhFTPRVSLOsRVhodnAAAAQw"]
[Thu Sep 17 15:09:42.952502 2026] [security2:error] [pid 955873:tid 956035] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/public_html/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodnQAAASo"]
[Thu Sep 17 15:09:43.192689 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/htdocs/.env"] [unique_id "aqxXFxFTPRVSLOsRVhodoAAAAWY"]
[Thu Sep 17 15:09:43.209490 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/"] [unique_id "aqxXFxFTPRVSLOsRVhodoQAAARs"]
[Thu Sep 17 15:09:43.404247 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/"] [unique_id "aqxXFxFTPRVSLOsRVhodqQAAARQ"]
[Thu Sep 17 15:09:43.430439 2026] [security2:error] [pid 955873:tid 956049] [client 4.240.114.86:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxXFxFTPRVSLOsRVhodrQAAATg"], referer: binance.com
[Thu Sep 17 15:09:43.432435 2026] [security2:error] [pid 955873:tid 956077] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/www/.env"] [unique_id "aqxXFxFTPRVSLOsRVhodrgAAAVQ"]
[Thu Sep 17 15:09:43.546641 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/crystal/"] [unique_id "aqxXFxFTPRVSLOsRVhodrwAAAVI"]
[Thu Sep 17 15:09:43.669148 2026] [security2:error] [pid 955873:tid 956006] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/html/.env"] [unique_id "aqxXFxFTPRVSLOsRVhodsQAAAQ0"]
[Thu Sep 17 15:09:43.702200 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/crystal/"] [unique_id "aqxXFxFTPRVSLOsRVhodsgAAAWI"]
[Thu Sep 17 15:09:43.842855 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/crystal/wp-includes/images/"] [unique_id "aqxXFxFTPRVSLOsRVhodtgAAASg"]
[Thu Sep 17 15:09:43.856378 2026] [security2:error] [pid 955873:tid 956080] [client 191.30.92.32:50076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXFxFTPRVSLOsRVhodswABV24"]
[Thu Sep 17 15:09:43.919283 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/live/.env"] [unique_id "aqxXFxFTPRVSLOsRVhoduwAAAR0"]
[Thu Sep 17 15:09:44.156287 2026] [security2:error] [pid 955873:tid 956019] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/prod/.env"] [unique_id "aqxXGBFTPRVSLOsRVhodvQAAARo"]
[Thu Sep 17 15:09:44.236375 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodvAAAATo"]
[Thu Sep 17 15:09:44.236408 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodvAAAATo"]
[Thu Sep 17 15:09:44.324170 2026] [security2:error] [pid 955873:tid 956045] [client 52.167.144.231:11083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodwAABNHg"]
[Thu Sep 17 15:09:44.392851 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/dev/.env"] [unique_id "aqxXGBFTPRVSLOsRVhodwwAAAXM"]
[Thu Sep 17 15:09:44.519127 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/icon-library/"] [unique_id "aqxXGBFTPRVSLOsRVhodxgAAAXk"]
[Thu Sep 17 15:09:44.607319 2026] [security2:error] [pid 955873:tid 956037] [client 91.56.35.230:42435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tlpsoftware.arrowake.com"] [uri "/index.php"] [unique_id "aqxXFRFTPRVSLOsRVhoddgABLAk"], referer: http://tlpsoftware.arrowake.com/robots.txt
[Thu Sep 17 15:09:44.631976 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/staging/.env"] [unique_id "aqxXGBFTPRVSLOsRVhodywAAAXQ"]
[Thu Sep 17 15:09:44.728937 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/icon-library/"] [unique_id "aqxXGBFTPRVSLOsRVhodzAAAAXY"]
[Thu Sep 17 15:09:44.824581 2026] [security2:error] [pid 955873:tid 956039] [client 115.244.164.14:60627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXGBFTPRVSLOsRVhod0AAAAS4"]
[Thu Sep 17 15:09:44.824684 2026] [security2:error] [pid 955873:tid 956039] [client 115.244.164.14:60627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXGBFTPRVSLOsRVhod0AAAAS4"]
[Thu Sep 17 15:09:44.864734 2026] [security2:error] [pid 955873:tid 956076] [client 127.0.0.1:54542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vls.tjo.mybluehost.me"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXGBFTPRVSLOsRVhod0QAAAVM"]
[Thu Sep 17 15:09:44.864733 2026] [security2:error] [pid 955873:tid 956102] [client 127.0.0.1:54554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXGBFTPRVSLOsRVhod0gAAAW0"]
[Thu Sep 17 15:09:44.864817 2026] [security2:error] [pid 955873:tid 956088] [client 74.7.228.3:42826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vls.tjo.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxXGBFTPRVSLOsRVhodzwABXxI"]
[Thu Sep 17 15:09:44.871887 2026] [security2:error] [pid 955873:tid 956057] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/opt/.env"] [unique_id "aqxXGBFTPRVSLOsRVhod0wAAAUA"]
[Thu Sep 17 15:09:44.874343 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/icon-library/wp-includes/images/"] [unique_id "aqxXGBFTPRVSLOsRVhod1AAAAUg"]
[Thu Sep 17 15:09:45.114497 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/laravel/.env"] [unique_id "aqxXGRFTPRVSLOsRVhod2QAAATE"]
[Thu Sep 17 15:09:45.300482 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod2AAAASU"]
[Thu Sep 17 15:09:45.300510 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod2AAAASU"]
[Thu Sep 17 15:09:45.353194 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/symfony/.env"] [unique_id "aqxXGRFTPRVSLOsRVhod3QAAAV4"]
[Thu Sep 17 15:09:45.441738 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/media/"] [unique_id "aqxXGRFTPRVSLOsRVhod4QAAAVI"]
[Thu Sep 17 15:09:45.603069 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/media/"] [unique_id "aqxXGRFTPRVSLOsRVhod4wAAATA"]
[Thu Sep 17 15:09:45.756019 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/media/wp-includes/images/"] [unique_id "aqxXGRFTPRVSLOsRVhod5wAAAWQ"]
[Thu Sep 17 15:09:46.102343 2026] [security2:error] [pid 955873:tid 956015] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/wordpress/.env"] [unique_id "aqxXGhFTPRVSLOsRVhod7wAAARY"]
[Thu Sep 17 15:09:46.134871 2026] [security2:error] [pid 955873:tid 956081] [client 103.58.74.95:56180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhod7gABWHQ"]
[Thu Sep 17 15:09:46.146029 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod7AAAAWI"]
[Thu Sep 17 15:09:46.146057 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod7AAAAWI"]
[Thu Sep 17 15:09:46.164629 2026] [security2:error] [pid 955873:tid 956008] [client 5.189.145.112:54457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxXGhFTPRVSLOsRVhod8QAAAQ8"], referer: binance.com
[Thu Sep 17 15:09:46.288393 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aqxXGhFTPRVSLOsRVhod8gAAATs"]
[Thu Sep 17 15:09:46.360348 2026] [security2:error] [pid 955873:tid 956011] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/wp/.env"] [unique_id "aqxXGhFTPRVSLOsRVhod9AAAARI"]
[Thu Sep 17 15:09:46.456417 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aqxXGhFTPRVSLOsRVhod-AAAAX4"]
[Thu Sep 17 15:09:46.530250 2026] [security2:error] [pid 955873:tid 956018] [client 52.167.144.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodzQAAARk"]
[Thu Sep 17 15:09:46.597805 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/smilies/wp-includes/images/"] [unique_id "aqxXGhFTPRVSLOsRVhod-wAAAYg"]
[Thu Sep 17 15:09:46.617460 2026] [security2:error] [pid 955873:tid 956051] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cms/.env"] [unique_id "aqxXGhFTPRVSLOsRVhod_AAAATo"]
[Thu Sep 17 15:09:46.646781 2026] [security2:error] [pid 955873:tid 956062] [client 162.241.226.11:56334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhod-QAAAUU"]
[Thu Sep 17 15:09:46.804713 2026] [security2:error] [pid 955873:tid 956110] [client 162.241.226.11:56348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhod_wAAAXU"]
[Thu Sep 17 15:09:46.868348 2026] [security2:error] [pid 955873:tid 956059] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/drupal/.env"] [unique_id "aqxXGhFTPRVSLOsRVhoeAwAAAUI"]
[Thu Sep 17 15:09:46.943798 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhoeAQAAAU8"]
[Thu Sep 17 15:09:46.943830 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhoeAQAAAU8"]
[Thu Sep 17 15:09:47.098073 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/.well-known/"] [unique_id "aqxXGxFTPRVSLOsRVhoeBwAAAXQ"]
[Thu Sep 17 15:09:47.116423 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/joomla/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeCAAAAXY"]
[Thu Sep 17 15:09:47.249580 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxXGxFTPRVSLOsRVhoeCQAAAWc"]
[Thu Sep 17 15:09:47.368071 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/magento/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeCgAAAU4"]
[Thu Sep 17 15:09:47.390303 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/ALFA_DATA/"] [unique_id "aqxXGxFTPRVSLOsRVhoeDQAAARM"]
[Thu Sep 17 15:09:47.616364 2026] [security2:error] [pid 955873:tid 956088] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/shopify/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeEQAAAV8"]
[Thu Sep 17 15:09:47.725784 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGxFTPRVSLOsRVhoeEAAAAW0"]
[Thu Sep 17 15:09:47.725817 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGxFTPRVSLOsRVhoeEAAAAW0"]
[Thu Sep 17 15:09:47.866800 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/.well-knownold/"] [unique_id "aqxXGxFTPRVSLOsRVhoeFAAAASo"]
[Thu Sep 17 15:09:47.867367 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/prestashop/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeEwAAAQo"]
[Thu Sep 17 15:09:48.047903 2026] [access_compat:error] [pid 955873:tid 956063] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/requests
[Thu Sep 17 15:09:48.116396 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/codeigniter/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeHAAAAVE"]
[Thu Sep 17 15:09:48.200604 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeGgAAARg"]
[Thu Sep 17 15:09:48.200631 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeGgAAARg"]
[Thu Sep 17 15:09:48.242847 2026] [security2:error] [pid 955873:tid 956031] [client 4.240.114.86:56141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeIAAAASY"], referer: binance.com
[Thu Sep 17 15:09:48.353568 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxXHBFTPRVSLOsRVhoeIQAAAWs"]
[Thu Sep 17 15:09:48.365608 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cakephp/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeIgAAAV0"]
[Thu Sep 17 15:09:48.494075 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/cgi-bin/"] [unique_id "aqxXHBFTPRVSLOsRVhoeJgAAATg"]
[Thu Sep 17 15:09:48.613583 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/zend/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeKgAAASA"]
[Thu Sep 17 15:09:48.642677 2026] [cgid:error] [pid 955873:tid 956033] [client 143.244.57.120:47574] AH01265: stderr from /home1/endurin2/public_html/seedboxpress/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:09:48.643138 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.seedboxpress.com"] [uri "/cgi-bin/"] [unique_id "aqxXHBFTPRVSLOsRVhoeKwAAASg"]
[Thu Sep 17 15:09:48.794973 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/index/"] [unique_id "aqxXHBFTPRVSLOsRVhoeLwAAATs"]
[Thu Sep 17 15:09:48.862370 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/yii/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeMgAAAWE"]
[Thu Sep 17 15:09:48.873823 2026] [security2:error] [pid 955873:tid 956077] [client 154.190.208.131:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNAAAAVQ"]
[Thu Sep 17 15:09:48.879273 2026] [security2:error] [pid 955873:tid 956077] [client 154.190.208.131:42491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNAAAAVQ"]
[Thu Sep 17 15:09:49.109842 2026] [security2:error] [pid 955873:tid 956040] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/laravel5/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoeOQAAAS8"]
[Thu Sep 17 15:09:49.131152 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNwAAAW4"]
[Thu Sep 17 15:09:49.131179 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNwAAAW4"]
[Thu Sep 17 15:09:49.272304 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/id/"] [unique_id "aqxXHRFTPRVSLOsRVhoePQAAAQ4"]
[Thu Sep 17 15:09:49.357576 2026] [security2:error] [pid 955873:tid 956051] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/v1/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoePgAAATo"]
[Thu Sep 17 15:09:49.599512 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeQgAAAS0"]
[Thu Sep 17 15:09:49.599538 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeQgAAAS0"]
[Thu Sep 17 15:09:49.610871 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/v2/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoeSQAAASM"]
[Thu Sep 17 15:09:49.740282 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/www/"] [unique_id "aqxXHRFTPRVSLOsRVhoeSgAAASQ"]
[Thu Sep 17 15:09:49.867084 2026] [security2:error] [pid 955873:tid 956076] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/v3/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoeSwAAAVM"]
[Thu Sep 17 15:09:50.085293 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeTQAAAVw"]
[Thu Sep 17 15:09:50.085320 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeTQAAAVw"]
[Thu Sep 17 15:09:50.115802 2026] [security2:error] [pid 955873:tid 956105] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/v1/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoebQAAAXA"]
[Thu Sep 17 15:09:50.230365 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/web/"] [unique_id "aqxXHhFTPRVSLOsRVhoecAAAAVg"]
[Thu Sep 17 15:09:50.371585 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/v2/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoedAAAAWE"]
[Thu Sep 17 15:09:50.587208 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoedQAAARA"]
[Thu Sep 17 15:09:50.587233 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoedQAAARA"]
[Thu Sep 17 15:09:50.624371 2026] [security2:error] [pid 955873:tid 956101] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/rest/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoeegAAAWw"]
[Thu Sep 17 15:09:50.730773 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/uploads/"] [unique_id "aqxXHhFTPRVSLOsRVhoeewAAAS8"]
[Thu Sep 17 15:09:50.877166 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/graphql/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoefgAAAWY"]
[Thu Sep 17 15:09:51.061282 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoefQAAAXE"]
[Thu Sep 17 15:09:51.061306 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoefQAAAXE"]
[Thu Sep 17 15:09:51.133179 2026] [security2:error] [pid 955873:tid 956059] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/gateway/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoeggAAAUI"]
[Thu Sep 17 15:09:51.221989 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/upload/"] [unique_id "aqxXHxFTPRVSLOsRVhoegwAAAYI"]
[Thu Sep 17 15:09:51.385758 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/microservice/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoehwAAAXg"]
[Thu Sep 17 15:09:51.554253 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoehAAAAXQ"]
[Thu Sep 17 15:09:51.554276 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoehAAAAXQ"]
[Thu Sep 17 15:09:51.631761 2026] [security2:error] [pid 955873:tid 956070] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/service/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoejQAAAU0"]
[Thu Sep 17 15:09:51.697693 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/uploads/"] [unique_id "aqxXHxFTPRVSLOsRVhoejgAAAR8"]
[Thu Sep 17 15:09:51.885087 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/v3/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoekwAAAU4"]
[Thu Sep 17 15:09:52.043391 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoekAAAAYQ"]
[Thu Sep 17 15:09:52.043419 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoekAAAAYQ"]
[Thu Sep 17 15:09:52.131088 2026] [security2:error] [pid 955873:tid 956100] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/dev/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoelQAAAWs"]
[Thu Sep 17 15:09:52.190709 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Admin/uploads/"] [unique_id "aqxXIBFTPRVSLOsRVhoemQAAAV0"]
[Thu Sep 17 15:09:52.249231 2026] [security2:error] [pid 955873:tid 956122] [client 216.73.160.164:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-login.php"] [unique_id "aqxXIBFTPRVSLOsRVhoelwAAAYE"]
[Thu Sep 17 15:09:52.303146 2026] [security2:error] [pid 955873:tid 956045] [client 45.8.19.105:42125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.19.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-login.php"] [unique_id "aqxXIBFTPRVSLOsRVhoemAAAATQ"]
[Thu Sep 17 15:09:52.379011 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/staging/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoenAAAAUg"]
[Thu Sep 17 15:09:52.532812 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoemgAAATw"]
[Thu Sep 17 15:09:52.532840 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoemgAAATw"]
[Thu Sep 17 15:09:52.629694 2026] [security2:error] [pid 955873:tid 956033] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/vendor/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoeowAAASg"]
[Thu Sep 17 15:09:52.682137 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/"] [unique_id "aqxXIBFTPRVSLOsRVhoepgAAAWA"]
[Thu Sep 17 15:09:52.688444 2026] [security2:error] [pid 955873:tid 956008] [client 5.189.145.112:53722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxXIBFTPRVSLOsRVhoepwAAAQ8"], referer: binance.com
[Thu Sep 17 15:09:52.736119 2026] [security2:error] [pid 955873:tid 956041] [client 45.169.98.18:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqQAAATA"]
[Thu Sep 17 15:09:52.736247 2026] [security2:error] [pid 955873:tid 956041] [client 45.169.98.18:50603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqQAAATA"]
[Thu Sep 17 15:09:52.877947 2026] [security2:error] [pid 955873:tid 956115] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/lib/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoerAAAAXo"]
[Thu Sep 17 15:09:52.997105 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqgAAAYU"]
[Thu Sep 17 15:09:52.997136 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqgAAAYU"]
[Thu Sep 17 15:09:53.104043 2026] [security2:error] [pid 955873:tid 956077] [client 4.240.114.86:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxXIRFTPRVSLOsRVhoerwAAAVQ"], referer: binance.com
[Thu Sep 17 15:09:53.107029 2026] [security2:error] [pid 955873:tid 956080] [client 185.55.149.49:53003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoesAAAAVc"]
[Thu Sep 17 15:09:53.107133 2026] [security2:error] [pid 955873:tid 956080] [client 185.55.149.49:53003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoesAAAAVc"]
[Thu Sep 17 15:09:53.129447 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/resources/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoesQAAAQo"]
[Thu Sep 17 15:09:53.380433 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/assets/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoeuQAAATc"]
[Thu Sep 17 15:09:53.463422 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/index.php"] [unique_id "aqxXIRFTPRVSLOsRVhoesgAAAVs"]
[Thu Sep 17 15:09:53.626603 2026] [security2:error] [pid 955873:tid 956078] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/uploads/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoexwAAAVU"]
[Thu Sep 17 15:09:53.644810 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:47574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxXIRFTPRVSLOsRVhoexgAAAXw"]
[Thu Sep 17 15:09:53.644950 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxXIRFTPRVSLOsRVhoexgAAAXw"]
[Thu Sep 17 15:09:53.669028 2026] [security2:error] [pid 955873:tid 956042] [client 186.105.232.15:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoeyAAAATE"]
[Thu Sep 17 15:09:53.669211 2026] [security2:error] [pid 955873:tid 956042] [client 186.105.232.15:62577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoeyAAAATE"]
[Thu Sep 17 15:09:53.794083 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/images/"] [unique_id "aqxXIRFTPRVSLOsRVhoezgAAASM"]
[Thu Sep 17 15:09:53.868274 2026] [security2:error] [pid 955873:tid 956043] [client 177.10.15.94:3697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXIRFTPRVSLOsRVhoezAABMkU"]
[Thu Sep 17 15:09:53.876966 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/internal/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoe0gAAAXQ"]
[Thu Sep 17 15:09:54.128199 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/tools/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe2AAAAU4"]
[Thu Sep 17 15:09:54.383359 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/scripts/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe4AAAAUg"]
[Thu Sep 17 15:09:54.394853 2026] [security2:error] [pid 955873:tid 956027] [client 17.166.155.60:56252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mybeloved.camera"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqwABIj8"]
[Thu Sep 17 15:09:54.459944 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe2gAAATk"]
[Thu Sep 17 15:09:54.459969 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe2gAAATk"]
[Thu Sep 17 15:09:54.635524 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/bin/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe5gAAAS4"]
[Thu Sep 17 15:09:54.742727 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/assets/"] [unique_id "aqxXIhFTPRVSLOsRVhoe6AAAAWI"]
[Thu Sep 17 15:09:54.806297 2026] [security2:error] [pid 955873:tid 956041] [client 177.10.15.94:3697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe5wABMAU"]
[Thu Sep 17 15:09:54.884501 2026] [security2:error] [pid 955873:tid 956049] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sbin/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe7QAAATg"]
[Thu Sep 17 15:09:55.084112 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe7gAAAXo"]
[Thu Sep 17 15:09:55.084140 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe7gAAAXo"]
[Thu Sep 17 15:09:55.134590 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/local/.env"] [unique_id "aqxXIxFTPRVSLOsRVhoe7wAAAWE"]
[Thu Sep 17 15:09:55.228500 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxXIxFTPRVSLOsRVhoe8AAAAVQ"]
[Thu Sep 17 15:09:55.381199 2026] [security2:error] [pid 955873:tid 956004] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/portal/.env"] [unique_id "aqxXIxFTPRVSLOsRVhoe-AAAAQs"]
[Thu Sep 17 15:09:55.438997 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe-wAAATM"]
[Thu Sep 17 15:09:55.439133 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:61266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe-wAAATM"]
[Thu Sep 17 15:09:55.579500 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe9wAAAX4"]
[Thu Sep 17 15:09:55.579526 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe9wAAAX4"]
[Thu Sep 17 15:09:55.628826 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/dashboard/.env"] [unique_id "aqxXIxFTPRVSLOsRVhoe_AAAAV4"]
[Thu Sep 17 15:09:55.720935 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/upload/image/"] [unique_id "aqxXIxFTPRVSLOsRVhoe_gAAAYY"]
[Thu Sep 17 15:09:55.879968 2026] [security2:error] [pid 955873:tid 956106] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/panel/.env"] [unique_id "aqxXIxFTPRVSLOsRVhofBwAAAXE"]
[Thu Sep 17 15:09:56.053306 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhofBgAAARA"]
[Thu Sep 17 15:09:56.053336 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhofBgAAARA"]
[Thu Sep 17 15:09:56.124506 2026] [security2:error] [pid 955873:tid 956104] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/crm/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofCAAAAW8"]
[Thu Sep 17 15:09:56.195668 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/assets/images/"] [unique_id "aqxXJBFTPRVSLOsRVhofDAAAAW4"]
[Thu Sep 17 15:09:56.339610 2026] [security2:error] [pid 955873:tid 956040] [client 47.79.207.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofCwAAAS8"], referer: https://www.google.com/
[Thu Sep 17 15:09:56.370457 2026] [security2:error] [pid 955873:tid 956125] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/erp/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofFQAAAYQ"]
[Thu Sep 17 15:09:56.534519 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofEwAAAR8"]
[Thu Sep 17 15:09:56.534547 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofEwAAAR8"]
[Thu Sep 17 15:09:56.584328 2026] [core:error] [pid 955873:tid 956035] [client 184.154.76.35:56886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=www.goldroadholdings.com&yahoo.com
[Thu Sep 17 15:09:56.584349 2026] [core:error] [pid 955873:tid 956035] [client 184.154.76.35:56886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=www.goldroadholdings.com&yahoo.com
[Thu Sep 17 15:09:56.617496 2026] [security2:error] [pid 955873:tid 956092] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/shop/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofHAAAAWM"]
[Thu Sep 17 15:09:56.676276 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Public/"] [unique_id "aqxXJBFTPRVSLOsRVhofHQAAAUg"]
[Thu Sep 17 15:09:56.871770 2026] [security2:error] [pid 955873:tid 956033] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/store/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofIgAAASg"]
[Thu Sep 17 15:09:56.952958 2026] [security2:error] [pid 955873:tid 956075] [client 104.28.198.244:23020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIwAAAVI"]
[Thu Sep 17 15:09:56.953048 2026] [security2:error] [pid 955873:tid 956075] [client 104.28.198.244:23020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIwAAAVI"]
[Thu Sep 17 15:09:57.009490 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIQAAATw"]
[Thu Sep 17 15:09:57.009518 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIQAAATw"]
[Thu Sep 17 15:09:57.117683 2026] [security2:error] [pid 955873:tid 956008] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/saas/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofJAAAAQ8"]
[Thu Sep 17 15:09:57.150274 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/vendor/"] [unique_id "aqxXJRFTPRVSLOsRVhofJgAAASY"]
[Thu Sep 17 15:09:57.370948 2026] [security2:error] [pid 955873:tid 956010] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/client/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofKwAAARE"]
[Thu Sep 17 15:09:57.499671 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofKAAAATA"]
[Thu Sep 17 15:09:57.499697 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofKAAAATA"]
[Thu Sep 17 15:09:57.618541 2026] [security2:error] [pid 955873:tid 956057] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/project/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofLAAAAUA"]
[Thu Sep 17 15:09:57.641131 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/local/"] [unique_id "aqxXJRFTPRVSLOsRVhofLQAAAUo"]
[Thu Sep 17 15:09:57.868287 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/admin-panel/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofMwAAATc"]
[Thu Sep 17 15:09:57.983963 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofMAAAAWE"]
[Thu Sep 17 15:09:57.983988 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofMAAAAWE"]
[Thu Sep 17 15:09:58.118712 2026] [security2:error] [pid 955873:tid 956129] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/control-panel/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofOAAAAYg"]
[Thu Sep 17 15:09:58.129705 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/modules/"] [unique_id "aqxXJhFTPRVSLOsRVhofOQAAAYU"]
[Thu Sep 17 15:09:58.364645 2026] [security2:error] [pid 955873:tid 956026] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/user-panel/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofRAAAASE"]
[Thu Sep 17 15:09:58.471404 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofPwAAAQ4"]
[Thu Sep 17 15:09:58.471430 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofPwAAAQ4"]
[Thu Sep 17 15:09:58.615334 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/node/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofRgAAAWY"]
[Thu Sep 17 15:09:58.635425 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Site/"] [unique_id "aqxXJhFTPRVSLOsRVhofRwAAASU"]
[Thu Sep 17 15:09:58.871364 2026] [security2:error] [pid 955873:tid 956018] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/express/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofTAAAARk"]
[Thu Sep 17 15:09:58.976188 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofSgAAATI"]
[Thu Sep 17 15:09:58.976227 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofSgAAATI"]
[Thu Sep 17 15:09:59.120757 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/system/"] [unique_id "aqxXJxFTPRVSLOsRVhofTgAAATE"]
[Thu Sep 17 15:09:59.121953 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/next/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofTwAAARw"]
[Thu Sep 17 15:09:59.371977 2026] [security2:error] [pid 955873:tid 956123] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/nuxt/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofVAAAAYI"]
[Thu Sep 17 15:09:59.460695 2026] [security2:error] [pid 955873:tid 956014] [client 5.189.145.112:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxXJxFTPRVSLOsRVhofVQAAARU"], referer: binance.com
[Thu Sep 17 15:09:59.478304 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofUAAAAS8"]
[Thu Sep 17 15:09:59.478330 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofUAAAAS8"]
[Thu Sep 17 15:09:59.552007 2026] [security2:error] [pid 955873:tid 956114] [client 4.240.114.86:63166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxXJxFTPRVSLOsRVhofVgAAAXk"], referer: binance.com
[Thu Sep 17 15:09:59.620801 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/template/"] [unique_id "aqxXJxFTPRVSLOsRVhofVwAAAUs"]
[Thu Sep 17 15:09:59.624368 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/nest/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofWAAAAYc"]
[Thu Sep 17 15:09:59.832297 2026] [security2:error] [pid 955873:tid 956006] [client 154.190.208.131:41754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJxFTPRVSLOsRVhofXQAAAQ0"]
[Thu Sep 17 15:09:59.832801 2026] [security2:error] [pid 955873:tid 956006] [client 154.190.208.131:41754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJxFTPRVSLOsRVhofXQAAAQ0"]
[Thu Sep 17 15:09:59.870193 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/react/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofXgAAAUg"]
[Thu Sep 17 15:09:59.947871 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofWQAAARg"]
[Thu Sep 17 15:09:59.947896 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofWQAAARg"]
[Thu Sep 17 15:10:00.121538 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/shop/"] [unique_id "aqxXKBFTPRVSLOsRVhofYQAAAQ8"]
[Thu Sep 17 15:10:00.128501 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/vue/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofYgAAAWA"]
[Thu Sep 17 15:10:00.376890 2026] [security2:error] [pid 955873:tid 956023] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/angular/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofbAAAAR4"]
[Thu Sep 17 15:10:00.458723 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofZAAAAWc"]
[Thu Sep 17 15:10:00.458753 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofZAAAAWc"]
[Thu Sep 17 15:10:00.600314 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/files/"] [unique_id "aqxXKBFTPRVSLOsRVhofbgAAARM"]
[Thu Sep 17 15:10:00.629293 2026] [security2:error] [pid 955873:tid 956072] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/svelte/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofbwAAAU8"]
[Thu Sep 17 15:10:00.901372 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/vite/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofdQAAATc"]
[Thu Sep 17 15:10:00.952480 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofcAAAAWs"]
[Thu Sep 17 15:10:00.952503 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofcAAAAWs"]
[Thu Sep 17 15:10:01.094792 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/editor/"] [unique_id "aqxXKRFTPRVSLOsRVhofdgAAASs"]
[Thu Sep 17 15:10:01.151921 2026] [security2:error] [pid 955873:tid 956083] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/backup/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofdwAAAVo"]
[Thu Sep 17 15:10:01.397869 2026] [security2:error] [pid 955873:tid 956127] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/backups/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofggAAAYY"]
[Thu Sep 17 15:10:01.479489 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhoffAAAASA"]
[Thu Sep 17 15:10:01.479515 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhoffAAAASA"]
[Thu Sep 17 15:10:01.628686 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/include/"] [unique_id "aqxXKRFTPRVSLOsRVhofhgAAAWY"]
[Thu Sep 17 15:10:01.655853 2026] [security2:error] [pid 955873:tid 956101] [client 162.241.226.11:34540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofgQAAAWw"]
[Thu Sep 17 15:10:01.656179 2026] [security2:error] [pid 955873:tid 956073] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/old/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofhwAAAVA"]
[Thu Sep 17 15:10:01.892580 2026] [security2:error] [pid 955873:tid 956117] [client 162.241.226.11:34554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofiAAAAXw"]
[Thu Sep 17 15:10:01.906578 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/tmp/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofkQAAAXQ"]
[Thu Sep 17 15:10:02.019652 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofigAAAS0"]
[Thu Sep 17 15:10:02.019710 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofigAAAS0"]
[Thu Sep 17 15:10:02.158070 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/temp/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofnwAAARw"]
[Thu Sep 17 15:10:02.166889 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Assets/"] [unique_id "aqxXKhFTPRVSLOsRVhofoAAAAYI"]
[Thu Sep 17 15:10:02.404790 2026] [security2:error] [pid 955873:tid 956024] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/lab/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofqwAAAR8"]
[Thu Sep 17 15:10:02.524640 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofqAAAAUs"]
[Thu Sep 17 15:10:02.524677 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofqAAAAUs"]
[Thu Sep 17 15:10:02.656511 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cronlab/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofsgAAAYE"]
[Thu Sep 17 15:10:02.687469 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/images/stories/"] [unique_id "aqxXKhFTPRVSLOsRVhofswAAATU"]
[Thu Sep 17 15:10:02.760816 2026] [security2:error] [pid 955873:tid 956050] [client 189.110.229.241:35765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofsQABOWg"]
[Thu Sep 17 15:10:02.906138 2026] [security2:error] [pid 955873:tid 956081] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cron/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofuQAAAVg"]
[Thu Sep 17 15:10:03.057641 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofuAAAAWA"]
[Thu Sep 17 15:10:03.057679 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofuAAAAWA"]
[Thu Sep 17 15:10:03.151994 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/en/.env"] [unique_id "aqxXKxFTPRVSLOsRVhofvQAAAVk"]
[Thu Sep 17 15:10:03.198055 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/plugins/"] [unique_id "aqxXKxFTPRVSLOsRVhofwgAAARQ"]
[Thu Sep 17 15:10:03.214127 2026] [security2:error] [pid 955873:tid 956098] [client 45.169.98.18:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhofxgAAAWk"]
[Thu Sep 17 15:10:03.214225 2026] [security2:error] [pid 955873:tid 956098] [client 45.169.98.18:51161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhofxgAAAWk"]
[Thu Sep 17 15:10:03.471422 2026] [security2:error] [pid 955873:tid 956056] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/administrator/.env"] [unique_id "aqxXKxFTPRVSLOsRVhogDgAAAT8"]
[Thu Sep 17 15:10:03.496605 2026] [security2:error] [pid 955873:tid 956033] [client 172.226.166.151:26405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofXwABKCw"]
[Thu Sep 17 15:10:03.555306 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhofzwAAARI"]
[Thu Sep 17 15:10:03.555332 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhofzwAAARI"]
[Thu Sep 17 15:10:03.672448 2026] [security2:error] [pid 955873:tid 956106] [client 189.110.229.241:35765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhogEwABcTU"]
[Thu Sep 17 15:10:03.696620 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/php/"] [unique_id "aqxXKxFTPRVSLOsRVhogFAAAAVc"]
[Thu Sep 17 15:10:03.719412 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/psnlink/.env"] [unique_id "aqxXKxFTPRVSLOsRVhogFQAAASA"]
[Thu Sep 17 15:10:03.787387 2026] [security2:error] [pid 955873:tid 956016] [client 185.55.149.49:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhogFwAAARc"]
[Thu Sep 17 15:10:03.787531 2026] [security2:error] [pid 955873:tid 956016] [client 185.55.149.49:53751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhogFwAAARc"]
[Thu Sep 17 15:10:03.969320 2026] [security2:error] [pid 955873:tid 956102] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/exapi/.env"] [unique_id "aqxXKxFTPRVSLOsRVhogHwAAAW0"]
[Thu Sep 17 15:10:04.050261 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhogGwAAAT4"]
[Thu Sep 17 15:10:04.050286 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhogGwAAAT4"]
[Thu Sep 17 15:10:04.198066 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/"] [unique_id "aqxXLBFTPRVSLOsRVhogIAAAARk"]
[Thu Sep 17 15:10:04.220559 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sitemaps/.env"] [unique_id "aqxXLBFTPRVSLOsRVhogIQAAAXg"]
[Thu Sep 17 15:10:04.544480 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/"] [unique_id "aqxXLBFTPRVSLOsRVhogJQAAAU0"]
[Thu Sep 17 15:10:04.585944 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:49880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogJwAAARw"]
[Thu Sep 17 15:10:04.689997 2026] [security2:error] [pid 955873:tid 956063] [client 192.178.15.197:62676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogKQAAAUY"]
[Thu Sep 17 15:10:04.692686 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxXLBFTPRVSLOsRVhogMQAAASM"]
[Thu Sep 17 15:10:04.709253 2026] [security2:error] [pid 955873:tid 956047] [client 186.105.232.15:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLBFTPRVSLOsRVhogMgAAATY"]
[Thu Sep 17 15:10:04.709390 2026] [security2:error] [pid 955873:tid 956047] [client 186.105.232.15:63171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLBFTPRVSLOsRVhogMgAAATY"]
[Thu Sep 17 15:10:04.931773 2026] [security2:error] [pid 955873:tid 956045] [client 35.244.43.255:49880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogNgAAATQ"]
[Thu Sep 17 15:10:05.144229 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxXLBFTPRVSLOsRVhogNwAAAVw"]
[Thu Sep 17 15:10:05.181899 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/logs/.env"] [unique_id "aqxXLRFTPRVSLOsRVhogOQAAAU4"]
[Thu Sep 17 15:10:05.288095 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/wp-admin/css/"] [unique_id "aqxXLRFTPRVSLOsRVhogQQAAAYM"]
[Thu Sep 17 15:10:05.662493 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLRFTPRVSLOsRVhogSgAAATs"]
[Thu Sep 17 15:10:05.662516 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLRFTPRVSLOsRVhogSgAAATs"]
[Thu Sep 17 15:10:05.823899 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxXLRFTPRVSLOsRVhogUQAAAXA"]
[Thu Sep 17 15:10:05.918322 2026] [security2:error] [pid 955873:tid 956072] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cache/.env"] [unique_id "aqxXLRFTPRVSLOsRVhogVQAAAU8"]
[Thu Sep 17 15:10:06.011630 2026] [security2:error] [pid 955873:tid 956077] [client 115.244.164.14:61893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLhFTPRVSLOsRVhogVwAAAVQ"]
[Thu Sep 17 15:10:06.011745 2026] [security2:error] [pid 955873:tid 956077] [client 115.244.164.14:61893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLhFTPRVSLOsRVhogVwAAAVQ"]
[Thu Sep 17 15:10:06.034907 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxXLRFTPRVSLOsRVhogVgAAAYY"]
[Thu Sep 17 15:10:06.151931 2026] [security2:error] [pid 955873:tid 956068] [client 172.226.166.151:26591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogOAABSz8"]
[Thu Sep 17 15:10:06.155793 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailer/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogWQAAATc"]
[Thu Sep 17 15:10:06.178211 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/wp-admin/css/colors/"] [unique_id "aqxXLhFTPRVSLOsRVhogWgAAASA"]
[Thu Sep 17 15:10:06.236012 2026] [authz_core:error] [pid 955873:tid 956008] [client 169.58.197.253:62258] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:10:06.396656 2026] [security2:error] [pid 955873:tid 956073] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mail/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogYQAAAVA"]
[Thu Sep 17 15:10:06.525500 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLhFTPRVSLOsRVhogXgAAAQs"]
[Thu Sep 17 15:10:06.525533 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLhFTPRVSLOsRVhogXgAAAQs"]
[Thu Sep 17 15:10:06.566214 2026] [security2:error] [pid 955873:tid 956005] [client 4.240.114.86:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxXLhFTPRVSLOsRVhogZwAAAQw"], referer: binance.com
[Thu Sep 17 15:10:06.641520 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/email/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogaAAAAV0"]
[Thu Sep 17 15:10:06.674486 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxXLhFTPRVSLOsRVhogagAAARk"]
[Thu Sep 17 15:10:06.678274 2026] [security2:error] [pid 955873:tid 956049] [client 210.222.43.21:49883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXLhFTPRVSLOsRVhogZAAAATg"], referer: http://talent-in-borders.com/www
[Thu Sep 17 15:10:06.881264 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxXLhFTPRVSLOsRVhogbQAAASQ"]
[Thu Sep 17 15:10:06.887112 2026] [security2:error] [pid 955873:tid 956070] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/smtp/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogbwAAAU0"]
[Thu Sep 17 15:10:07.023806 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/wp-admin/css/colors/"] [unique_id "aqxXLxFTPRVSLOsRVhogcAAAAQ0"]
[Thu Sep 17 15:10:07.131622 2026] [security2:error] [pid 955873:tid 956045] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailing/.env"] [unique_id "aqxXLxFTPRVSLOsRVhogcQAAATQ"]
[Thu Sep 17 15:10:07.375891 2026] [security2:error] [pid 955873:tid 956050] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/notifications/.env"] [unique_id "aqxXLxFTPRVSLOsRVhogdwAAATk"]
[Thu Sep 17 15:10:07.376471 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLxFTPRVSLOsRVhogcgAAAYQ"]
[Thu Sep 17 15:10:07.376489 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLxFTPRVSLOsRVhogcgAAAYQ"]
[Thu Sep 17 15:10:07.526757 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxXLxFTPRVSLOsRVhogewAAAWA"]
[Thu Sep 17 15:10:07.620355 2026] [security2:error] [pid 955873:tid 956013] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/notify/.env"] [unique_id "aqxXLxFTPRVSLOsRVhoggQAAARQ"]
[Thu Sep 17 15:10:07.865968 2026] [security2:error] [pid 955873:tid 956056] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sender/.env"] [unique_id "aqxXLxFTPRVSLOsRVhogjAAAAT8"]
[Thu Sep 17 15:10:07.907626 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxXLxFTPRVSLOsRVhogigAAAYg"]
[Thu Sep 17 15:10:08.049302 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/wp-admin/css/colors/"] [unique_id "aqxXMBFTPRVSLOsRVhogjQAAAUQ"]
[Thu Sep 17 15:10:08.113217 2026] [security2:error] [pid 955873:tid 956127] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/campaign/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogjgAAAYY"]
[Thu Sep 17 15:10:08.357980 2026] [security2:error] [pid 955873:tid 956112] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/newsletter/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogmgAAAXc"]
[Thu Sep 17 15:10:08.430448 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMBFTPRVSLOsRVhogkgAAATc"]
[Thu Sep 17 15:10:08.430476 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMBFTPRVSLOsRVhogkgAAATc"]
[Thu Sep 17 15:10:08.549733 2026] [security2:error] [pid 955873:tid 956077] [client 104.28.198.244:22766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMBFTPRVSLOsRVhogoAAAAVQ"]
[Thu Sep 17 15:10:08.549880 2026] [security2:error] [pid 955873:tid 956077] [client 104.28.198.244:22766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMBFTPRVSLOsRVhogoAAAAVQ"]
[Thu Sep 17 15:10:08.572926 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxXMBFTPRVSLOsRVhogoQAAARg"]
[Thu Sep 17 15:10:08.600994 2026] [security2:error] [pid 955873:tid 956097] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/ses/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogogAAAWg"]
[Thu Sep 17 15:10:08.769418 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxXMBFTPRVSLOsRVhogpAAAAWY"]
[Thu Sep 17 15:10:08.806767 2026] [security2:error] [pid 955873:tid 956064] [client 5.189.145.112:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxXMBFTPRVSLOsRVhogpQAAAUc"], referer: binance.com
[Thu Sep 17 15:10:08.842809 2026] [security2:error] [pid 955873:tid 956093] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sendgrid/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogpwAAAWQ"]
[Thu Sep 17 15:10:08.912557 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/wp-admin/css/colors/"] [unique_id "aqxXMBFTPRVSLOsRVhogqgAAARs"]
[Thu Sep 17 15:10:09.084013 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sparkpost/.env"] [unique_id "aqxXMRFTPRVSLOsRVhogrgAAASM"]
[Thu Sep 17 15:10:09.256449 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogrAAAAYI"]
[Thu Sep 17 15:10:09.256473 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogrAAAAYI"]
[Thu Sep 17 15:10:09.328279 2026] [security2:error] [pid 955873:tid 956045] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/postmark/.env"] [unique_id "aqxXMRFTPRVSLOsRVhogsgAAATQ"]
[Thu Sep 17 15:10:09.397367 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxXMRFTPRVSLOsRVhoguAAAAV8"]
[Thu Sep 17 15:10:09.563352 2026] [security2:error] [pid 955873:tid 956082] [client 172.59.160.160:11223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.auxotech.com"] [uri "/cpc/theme/load_page.php"] [unique_id "aqxXMRFTPRVSLOsRVhoguQABWVI"], referer: https://www.auxotech.com/cpc/
[Thu Sep 17 15:10:09.569869 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailgun/.env"] [unique_id "aqxXMRFTPRVSLOsRVhoguwAAAYE"]
[Thu Sep 17 15:10:09.599187 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxXMRFTPRVSLOsRVhogugAAARQ"]
[Thu Sep 17 15:10:09.742287 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/wp-admin/css/colors/"] [unique_id "aqxXMRFTPRVSLOsRVhogvgAAAUM"]
[Thu Sep 17 15:10:09.814690 2026] [security2:error] [pid 955873:tid 956105] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mandrill/.env"] [unique_id "aqxXMRFTPRVSLOsRVhogvwAAAXA"]
[Thu Sep 17 15:10:10.064977 2026] [security2:error] [pid 955873:tid 956126] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailjet/.env"] [unique_id "aqxXMhFTPRVSLOsRVhogxAAAAYU"]
[Thu Sep 17 15:10:10.080305 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogwgAAAWs"]
[Thu Sep 17 15:10:10.080332 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogwgAAAWs"]
[Thu Sep 17 15:10:10.225226 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxXMhFTPRVSLOsRVhogxQAAAVs"]
[Thu Sep 17 15:10:10.308139 2026] [security2:error] [pid 955873:tid 956012] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/brevo/.env"] [unique_id "aqxXMhFTPRVSLOsRVhogyAAAARM"]
[Thu Sep 17 15:10:10.466090 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxXMhFTPRVSLOsRVhogzQAAAYY"]
[Thu Sep 17 15:10:10.551023 2026] [security2:error] [pid 955873:tid 956080] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/transactional/.env"] [unique_id "aqxXMhFTPRVSLOsRVhog0QAAAVc"]
[Thu Sep 17 15:10:10.626485 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/wp-admin/css/colors/"] [unique_id "aqxXMhFTPRVSLOsRVhog0gAAAWU"]
[Thu Sep 17 15:10:10.696530 2026] [security2:error] [pid 955873:tid 956090] [client 154.190.208.131:42354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1AAAAWE"]
[Thu Sep 17 15:10:10.696668 2026] [security2:error] [pid 955873:tid 956090] [client 154.190.208.131:42354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1AAAAWE"]
[Thu Sep 17 15:10:10.794891 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/bulk/.env"] [unique_id "aqxXMhFTPRVSLOsRVhog1wAAAS4"]
[Thu Sep 17 15:10:11.023940 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1gAAATM"]
[Thu Sep 17 15:10:11.023965 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1gAAATM"]
[Thu Sep 17 15:10:11.040868 2026] [security2:error] [pid 955873:tid 956099] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/aws/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog5gAAAWo"]
[Thu Sep 17 15:10:11.167144 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxXMxFTPRVSLOsRVhog6gAAAWQ"]
[Thu Sep 17 15:10:11.283033 2026] [security2:error] [pid 955873:tid 956007] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/azure/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog7wAAAQ4"]
[Thu Sep 17 15:10:11.414939 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxXMxFTPRVSLOsRVhog8wAAAU0"]
[Thu Sep 17 15:10:11.522601 2026] [security2:error] [pid 955873:tid 956103] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/gcp/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog-AAAAW4"]
[Thu Sep 17 15:10:11.556244 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/wp-admin/css/colors/"] [unique_id "aqxXMxFTPRVSLOsRVhog-QAAASo"]
[Thu Sep 17 15:10:11.718257 2026] [security2:error] [pid 955873:tid 956042] [client 4.240.114.86:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxXMxFTPRVSLOsRVhog-wAAATE"], referer: binance.com
[Thu Sep 17 15:10:11.763923 2026] [security2:error] [pid 955873:tid 956114] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cloud/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog_AAAAXk"]
[Thu Sep 17 15:10:11.897815 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMxFTPRVSLOsRVhog-gAAATY"]
[Thu Sep 17 15:10:11.897844 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMxFTPRVSLOsRVhog-gAAATY"]
[Thu Sep 17 15:10:12.007050 2026] [security2:error] [pid 955873:tid 956107] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/infrastructure/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohBgAAAXI"]
[Thu Sep 17 15:10:12.040348 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxXNBFTPRVSLOsRVhohCQAAAU4"]
[Thu Sep 17 15:10:12.248855 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/docker/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohDAAAAYE"]
[Thu Sep 17 15:10:12.267645 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxXNBFTPRVSLOsRVhohCwAAAR4"]
[Thu Sep 17 15:10:12.492858 2026] [security2:error] [pid 955873:tid 956119] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/k8s/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohFAAAAX4"]
[Thu Sep 17 15:10:12.505806 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/wp-admin/css/colors/"] [unique_id "aqxXNBFTPRVSLOsRVhohFQAAARM"]
[Thu Sep 17 15:10:12.737021 2026] [security2:error] [pid 955873:tid 956014] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/kubernetes/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohGAAAARU"]
[Thu Sep 17 15:10:12.857757 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNBFTPRVSLOsRVhohFwAAAYY"]
[Thu Sep 17 15:10:12.857781 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNBFTPRVSLOsRVhohFwAAAYY"]
[Thu Sep 17 15:10:12.978616 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/terraform/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohLwAAATc"]
[Thu Sep 17 15:10:12.998776 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxXNBFTPRVSLOsRVhohMQAAAXw"]
[Thu Sep 17 15:10:13.223999 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/ansible/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohNwAAAWY"]
[Thu Sep 17 15:10:13.359856 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohMwAAASU"]
[Thu Sep 17 15:10:13.359892 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohMwAAASU"]
[Thu Sep 17 15:10:13.370137 2026] [security2:error] [pid 955873:tid 956058] [client 177.10.23.92:50650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohOwABQQI"]
[Thu Sep 17 15:10:13.472857 2026] [security2:error] [pid 955873:tid 956118] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.git/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohQQAAAX0"]
[Thu Sep 17 15:10:13.507409 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/cache/"] [unique_id "aqxXNRFTPRVSLOsRVhohQgAAARw"]
[Thu Sep 17 15:10:13.652629 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/cache/index.html"] [unique_id "aqxXNRFTPRVSLOsRVhohRwAAAXk"]
[Thu Sep 17 15:10:13.719310 2026] [security2:error] [pid 955873:tid 956075] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/ci/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohSQAAAVI"]
[Thu Sep 17 15:10:13.737082 2026] [security2:error] [pid 955873:tid 956081] [client 45.169.98.18:51725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNRFTPRVSLOsRVhohSgAAAVg"]
[Thu Sep 17 15:10:13.737236 2026] [security2:error] [pid 955873:tid 956081] [client 45.169.98.18:51725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNRFTPRVSLOsRVhohSgAAAVg"]
[Thu Sep 17 15:10:13.825914 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/"] [unique_id "aqxXNRFTPRVSLOsRVhohSwAAASc"]
[Thu Sep 17 15:10:13.964781 2026] [security2:error] [pid 955873:tid 956088] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cd/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohUwAAAV8"]
[Thu Sep 17 15:10:14.036801 2026] [authz_core:error] [pid 955873:tid 956121] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-admin/maint/error_log
[Thu Sep 17 15:10:14.041206 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/"] [unique_id "aqxXNRFTPRVSLOsRVhohVAAAAYA"]
[Thu Sep 17 15:10:14.205965 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/jenkins/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohVgAAAWA"]
[Thu Sep 17 15:10:14.216964 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aqxXNhFTPRVSLOsRVhohWAAAAYI"]
[Thu Sep 17 15:10:14.217088 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aqxXNhFTPRVSLOsRVhohWAAAAYI"]
[Thu Sep 17 15:10:14.256992 2026] [security2:error] [pid 955873:tid 956006] [client 177.10.23.92:50650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXNhFTPRVSLOsRVhohVQABDWc"]
[Thu Sep 17 15:10:14.445871 2026] [security2:error] [pid 955873:tid 956027] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/gitlab/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohXQAAASI"]
[Thu Sep 17 15:10:14.498417 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:45164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxXNhFTPRVSLOsRVhohXgAAATA"]
[Thu Sep 17 15:10:14.500599 2026] [security2:error] [pid 955873:tid 956045] [client 185.55.149.49:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXNhFTPRVSLOsRVhohXwAAATQ"]
[Thu Sep 17 15:10:14.500715 2026] [security2:error] [pid 955873:tid 956045] [client 185.55.149.49:54458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXNhFTPRVSLOsRVhohXwAAATQ"]
[Thu Sep 17 15:10:14.643802 2026] [authz_core:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-content/plugins/akismet/
[Thu Sep 17 15:10:14.645066 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxXNhFTPRVSLOsRVhohYQAAAVE"]
[Thu Sep 17 15:10:14.690969 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/github/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohYgAAAR0"]
[Thu Sep 17 15:10:14.791351 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:45164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/"] [unique_id "aqxXNhFTPRVSLOsRVhohYwAAARM"]
[Thu Sep 17 15:10:14.939876 2026] [security2:error] [pid 955873:tid 956036] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/actions/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohZwAAASs"]
[Thu Sep 17 15:10:14.962105 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/"] [unique_id "aqxXNhFTPRVSLOsRVhohaAAAAUM"]
[Thu Sep 17 15:10:15.109256 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/icon-library-manifest.php"] [unique_id "aqxXNxFTPRVSLOsRVhohbwAAARU"]
[Thu Sep 17 15:10:15.109398 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:45164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/icon-library-manifest.php"] [unique_id "aqxXNxFTPRVSLOsRVhohbwAAARU"]
[Thu Sep 17 15:10:15.183466 2026] [security2:error] [pid 955873:tid 956104] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/circleci/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohcAAAAW8"]
[Thu Sep 17 15:10:15.400366 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:45168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/script-modules-packages.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdAAAAWw"]
[Thu Sep 17 15:10:15.400501 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:45168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/script-modules-packages.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdAAAAWw"]
[Thu Sep 17 15:10:15.436335 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/travis/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohdQAAAS4"]
[Thu Sep 17 15:10:15.641332 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:63760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdwAAAVo"]
[Thu Sep 17 15:10:15.643721 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:63760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdwAAAVo"]
[Thu Sep 17 15:10:15.677044 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:45170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxXNxFTPRVSLOsRVhoheQAAAW0"]
[Thu Sep 17 15:10:15.678585 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/buildkite/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohewAAAV4"]
[Thu Sep 17 15:10:15.847408 2026] [authz_core:error] [pid 955873:tid 956109] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/block-patterns/error_log
[Thu Sep 17 15:10:15.850039 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxXNxFTPRVSLOsRVhohfwAAAXQ"]
[Thu Sep 17 15:10:15.921622 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mysql/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohhgAAAXM"]
[Thu Sep 17 15:10:15.922923 2026] [security2:error] [pid 955873:tid 956026] [client 156.192.234.52:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohgwAAASE"]
[Thu Sep 17 15:10:15.923040 2026] [security2:error] [pid 955873:tid 956026] [client 156.192.234.52:58434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohgwAAASE"]
[Thu Sep 17 15:10:15.987065 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-accent-bg.php"] [unique_id "aqxXNxFTPRVSLOsRVhohhwAAASU"]
[Thu Sep 17 15:10:15.987195 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-accent-bg.php"] [unique_id "aqxXNxFTPRVSLOsRVhohhwAAASU"]
[Thu Sep 17 15:10:16.165607 2026] [security2:error] [pid 955873:tid 956124] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/postgres/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohiQAAAYM"]
[Thu Sep 17 15:10:16.275956 2026] [security2:error] [pid 955873:tid 956042] [client 66.249.66.196:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kopecdental.com"] [uri "/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohSAAAATE"]
[Thu Sep 17 15:10:16.277784 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:45182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-black-bg.php"] [unique_id "aqxXOBFTPRVSLOsRVhohiwAAAWQ"]
[Thu Sep 17 15:10:16.277902 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:45182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-black-bg.php"] [unique_id "aqxXOBFTPRVSLOsRVhohiwAAAWQ"]
[Thu Sep 17 15:10:16.410409 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mongodb/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohjwAAASA"]
[Thu Sep 17 15:10:16.522045 2026] [security2:error] [pid 955873:tid 956035] [client 115.244.164.14:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOBFTPRVSLOsRVhohkwAAASo"]
[Thu Sep 17 15:10:16.522155 2026] [security2:error] [pid 955873:tid 956035] [client 115.244.164.14:62533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOBFTPRVSLOsRVhohkwAAASo"]
[Thu Sep 17 15:10:16.572477 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered-with-extras.php"] [unique_id "aqxXOBFTPRVSLOsRVhohlAAAAYA"]
[Thu Sep 17 15:10:16.572620 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:45188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered-with-extras.php"] [unique_id "aqxXOBFTPRVSLOsRVhohlAAAAYA"]
[Thu Sep 17 15:10:16.654355 2026] [security2:error] [pid 955873:tid 956047] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/redis/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohlQAAATY"]
[Thu Sep 17 15:10:16.865320 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered.php"] [unique_id "aqxXOBFTPRVSLOsRVhohmgAAARk"]
[Thu Sep 17 15:10:16.865455 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:45190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered.php"] [unique_id "aqxXOBFTPRVSLOsRVhohmgAAARk"]
[Thu Sep 17 15:10:16.896158 2026] [security2:error] [pid 955873:tid 956017] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/elasticsearch/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohmwAAARg"]
[Thu Sep 17 15:10:17.019602 2026] [security2:error] [pid 955873:tid 956006] [client 57.141.14.78:38378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXOBFTPRVSLOsRVhohlwABDV0"]
[Thu Sep 17 15:10:17.137499 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/rabbitmq/.env"] [unique_id "aqxXORFTPRVSLOsRVhohngAAAYE"]
[Thu Sep 17 15:10:17.161338 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay.php"] [unique_id "aqxXORFTPRVSLOsRVhohnwAAAUU"]
[Thu Sep 17 15:10:17.161471 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:45196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay.php"] [unique_id "aqxXORFTPRVSLOsRVhohnwAAAUU"]
[Thu Sep 17 15:10:17.379179 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/kafka/.env"] [unique_id "aqxXORFTPRVSLOsRVhohowAAAR0"]
[Thu Sep 17 15:10:17.469339 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:45200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-grid-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohpQAAAVk"]
[Thu Sep 17 15:10:17.469471 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:45200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-grid-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohpQAAAVk"]
[Thu Sep 17 15:10:17.619589 2026] [security2:error] [pid 955873:tid 956014] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/queue/.env"] [unique_id "aqxXORFTPRVSLOsRVhohqQAAARU"]
[Thu Sep 17 15:10:17.733260 2026] [security2:error] [pid 955873:tid 956105] [client 5.189.145.112:56062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxXORFTPRVSLOsRVhohqgAAAXA"], referer: binance.com
[Thu Sep 17 15:10:17.858882 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/worker/.env"] [unique_id "aqxXORFTPRVSLOsRVhohrQAAAS4"]
[Thu Sep 17 15:10:17.870330 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:45214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-large-title-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohrgAAAUY"]
[Thu Sep 17 15:10:17.870424 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:45214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-large-title-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohrgAAAUY"]
[Thu Sep 17 15:10:18.099764 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/job/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohswAAAQo"]
[Thu Sep 17 15:10:18.125383 2026] [security2:error] [pid 955873:tid 956104] [client 104.28.198.244:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtAAAAW8"]
[Thu Sep 17 15:10:18.125540 2026] [security2:error] [pid 955873:tid 956104] [client 104.28.198.244:22657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtAAAAW8"]
[Thu Sep 17 15:10:18.165542 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:45220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-medium-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtgAAARc"]
[Thu Sep 17 15:10:18.165669 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:45220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-medium-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtgAAARc"]
[Thu Sep 17 15:10:18.342987 2026] [security2:error] [pid 955873:tid 956066] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/test/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohvAAAAUk"]
[Thu Sep 17 15:10:18.462820 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-offset-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohvgAAAWY"]
[Thu Sep 17 15:10:18.462932 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:45228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-offset-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohvgAAAWY"]
[Thu Sep 17 15:10:18.577768 2026] [security2:error] [pid 955873:tid 956050] [client 37.59.21.100:56202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.churchinirving.org"] [uri "/index.php"] [unique_id "aqxXORFTPRVSLOsRVhohoAAAATk"]
[Thu Sep 17 15:10:18.590907 2026] [security2:error] [pid 955873:tid 956030] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/qa/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohvwAAASU"]
[Thu Sep 17 15:10:18.718550 2026] [security2:error] [pid 955873:tid 956079] [client 4.240.114.86:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxXOhFTPRVSLOsRVhohwQAAAVY"], referer: binance.com
[Thu Sep 17 15:10:18.780095 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-small-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohwwAAAXo"]
[Thu Sep 17 15:10:18.780190 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:45238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-small-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohwwAAAXo"]
[Thu Sep 17 15:10:18.835440 2026] [security2:error] [pid 955873:tid 956011] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/preview/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohxQAAARI"]
[Thu Sep 17 15:10:18.875293 2026] [security2:error] [pid 955873:tid 956124] [client 134.185.85.61:51236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "coachmancrafts.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxXOhFTPRVSLOsRVhohxwAAAYM"]
[Thu Sep 17 15:10:19.074172 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-standard-posts.php"] [unique_id "aqxXOxFTPRVSLOsRVhohygAAASA"]
[Thu Sep 17 15:10:19.074297 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:45240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-standard-posts.php"] [unique_id "aqxXOxFTPRVSLOsRVhohygAAASA"]
[Thu Sep 17 15:10:19.078376 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/beta/.env"] [unique_id "aqxXOxFTPRVSLOsRVhohywAAAV0"]
[Thu Sep 17 15:10:19.253861 2026] [security2:error] [pid 955873:tid 956125] [client 134.185.85.61:52119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "coachmancrafts.com"] [uri "/media/system/js/core.js"] [unique_id "aqxXOxFTPRVSLOsRVhohzAAAAYQ"]
[Thu Sep 17 15:10:19.325759 2026] [security2:error] [pid 955873:tid 956009] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/uat/.env"] [unique_id "aqxXOxFTPRVSLOsRVhohzwAAARA"]
[Thu Sep 17 15:10:19.377259 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:45250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/social-links-shared-background-color.php"] [unique_id "aqxXOxFTPRVSLOsRVhoh0wAAAWc"]
[Thu Sep 17 15:10:19.377359 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:45250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/social-links-shared-background-color.php"] [unique_id "aqxXOxFTPRVSLOsRVhoh0wAAAWc"]
[Thu Sep 17 15:10:19.572026 2026] [security2:error] [pid 955873:tid 956006] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/stage/.env"] [unique_id "aqxXOxFTPRVSLOsRVhoh2wAAAQ0"]
[Thu Sep 17 15:10:19.683110 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:45252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxXOxFTPRVSLOsRVhoh3AAAAR4"]
[Thu Sep 17 15:10:19.817037 2026] [security2:error] [pid 955873:tid 956062] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/development/.env"] [unique_id "aqxXOxFTPRVSLOsRVhoh3gAAAUU"]
[Thu Sep 17 15:10:19.844780 2026] [authz_core:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/block-supports/error_log
[Thu Sep 17 15:10:19.848180 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxXOxFTPRVSLOsRVhoh3wAAAVE"]
[Thu Sep 17 15:10:20.004937 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/anchor.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh5gAAAYY"]
[Thu Sep 17 15:10:20.005068 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/anchor.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh5gAAAYY"]
[Thu Sep 17 15:10:20.059381 2026] [security2:error] [pid 955873:tid 956060] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/production/.env"] [unique_id "aqxXPBFTPRVSLOsRVhoh5wAAAUM"]
[Thu Sep 17 15:10:20.288389 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:36066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/aria-label.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh6AAAAVA"]
[Thu Sep 17 15:10:20.288515 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:36066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/aria-label.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh6AAAAVA"]
[Thu Sep 17 15:10:20.300804 2026] [security2:error] [pid 955873:tid 956072] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/config/app/.env"] [unique_id "aqxXPBFTPRVSLOsRVhoh6QAAAU8"]
[Thu Sep 17 15:10:20.541606 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh8QAAAV4"]
[Thu Sep 17 15:10:20.575480 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/auto-register.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh8gAAAXw"]
[Thu Sep 17 15:10:20.575620 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/auto-register.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh8gAAAXw"]
[Thu Sep 17 15:10:20.876796 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/background.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh-AAAASU"]
[Thu Sep 17 15:10:20.876906 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/background.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh-AAAASU"]
[Thu Sep 17 15:10:20.984584 2026] [security2:error] [pid 955873:tid 956078] [client 192.178.15.161:52788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh9QAAAVU"]
[Thu Sep 17 15:10:21.172468 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:36098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-style-variations.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh-wAAARs"]
[Thu Sep 17 15:10:21.172606 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:36098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-style-variations.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh-wAAARs"]
[Thu Sep 17 15:10:21.246197 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:41614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh_wAAAWY"]
[Thu Sep 17 15:10:21.246317 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:41614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh_wAAAWY"]
[Thu Sep 17 15:10:21.258580 2026] [security2:error] [pid 955873:tid 956037] [client 35.244.43.255:37870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/info.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiAQAAASw"]
[Thu Sep 17 15:10:21.459350 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-visibility.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiBQAAAS0"]
[Thu Sep 17 15:10:21.459459 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-visibility.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiBQAAAS0"]
[Thu Sep 17 15:10:21.741233 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:36124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/border.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiCAAAAUI"]
[Thu Sep 17 15:10:21.741379 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:36124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/border.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiCAAAAUI"]
[Thu Sep 17 15:10:21.777854 2026] [security2:error] [pid 955873:tid 956086] [client 57.141.14.51:64950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiBwABXQA"]
[Thu Sep 17 15:10:21.965426 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:37886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/php.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiDQAAATE"]
[Thu Sep 17 15:10:22.030362 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/custom-css.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDgAAAYA"]
[Thu Sep 17 15:10:22.030506 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/custom-css.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDgAAAYA"]
[Thu Sep 17 15:10:22.320540 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/dimensions.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDwAAARg"]
[Thu Sep 17 15:10:22.320644 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:36138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/dimensions.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDwAAARg"]
[Thu Sep 17 15:10:22.598406 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/duotone.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiFQAAAYU"]
[Thu Sep 17 15:10:22.598541 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:36144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/duotone.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiFQAAAYU"]
[Thu Sep 17 15:10:22.673414 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/i.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiFwAAAXY"]
[Thu Sep 17 15:10:22.882893 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/elements.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiHQAAAR0"]
[Thu Sep 17 15:10:22.883007 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/elements.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiHQAAAR0"]
[Thu Sep 17 15:10:23.161305 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/layout.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiIAAAAYY"]
[Thu Sep 17 15:10:23.161438 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:36172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/layout.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiIAAAAYY"]
[Thu Sep 17 15:10:23.276907 2026] [security2:error] [pid 955873:tid 956039] [client 104.243.33.53:57668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "travisklassen.com"] [uri "/.env"] [unique_id "aqxXPxFTPRVSLOsRVhoiJgAAAS4"]
[Thu Sep 17 15:10:23.414568 2026] [security2:error] [pid 955873:tid 956101] [client 35.244.43.255:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/pi.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiLAAAAWw"]
[Thu Sep 17 15:10:23.461786 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:36176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/position.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiLQAAAUk"]
[Thu Sep 17 15:10:23.461908 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:36176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/position.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiLQAAAUk"]
[Thu Sep 17 15:10:23.740226 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:36192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/settings.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiMQAAAUc"]
[Thu Sep 17 15:10:23.740351 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:36192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/settings.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiMQAAAUc"]
[Thu Sep 17 15:10:24.028300 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:36208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/shadow.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiNgAAATc"]
[Thu Sep 17 15:10:24.028406 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:36208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/shadow.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiNgAAATc"]
[Thu Sep 17 15:10:24.034555 2026] [security2:error] [pid 955873:tid 956118] [client 4.240.114.86:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiNwAAAX0"], referer: binance.com
[Thu Sep 17 15:10:24.075518 2026] [security2:error] [pid 955873:tid 956030] [client 193.56.116.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiNQABJTQ"]
[Thu Sep 17 15:10:24.150476 2026] [security2:error] [pid 955873:tid 956129] [client 35.244.43.255:37900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/pinfo.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOAAAAYg"]
[Thu Sep 17 15:10:24.206194 2026] [security2:error] [pid 955873:tid 956078] [client 45.169.98.18:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOgAAAVU"]
[Thu Sep 17 15:10:24.206314 2026] [security2:error] [pid 955873:tid 956078] [client 45.169.98.18:52292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOgAAAVU"]
[Thu Sep 17 15:10:24.306445 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:36224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/spacing.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOwAAAT4"]
[Thu Sep 17 15:10:24.306588 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:36224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/spacing.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOwAAAT4"]
[Thu Sep 17 15:10:24.591848 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/states.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiQgAAAWQ"]
[Thu Sep 17 15:10:24.591963 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:36232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/states.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiQgAAAWQ"]
[Thu Sep 17 15:10:24.885441 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:36244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiRQAAASA"]
[Thu Sep 17 15:10:24.885556 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:36244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiRQAAASA"]
[Thu Sep 17 15:10:24.892147 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:37246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/test.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiRwAAASM"]
[Thu Sep 17 15:10:25.167558 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:36246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxXQRFTPRVSLOsRVhoiSQAAAXk"]
[Thu Sep 17 15:10:25.291399 2026] [security2:error] [pid 955873:tid 956052] [client 185.55.149.49:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiTAAAATs"]
[Thu Sep 17 15:10:25.291520 2026] [security2:error] [pid 955873:tid 956052] [client 185.55.149.49:57900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiTAAAATs"]
[Thu Sep 17 15:10:25.620856 2026] [autoindex:error] [pid 955873:tid 956010] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:25.621609 2026] [security2:error] [pid 955873:tid 956010] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/cgi-sys/403.html"] [unique_id "aqxXQRFTPRVSLOsRVhoiVAAAARE"]
[Thu Sep 17 15:10:25.626060 2026] [authz_core:error] [pid 955873:tid 956123] [client 143.244.57.120:40074] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/html-api/error_log
[Thu Sep 17 15:10:25.629714 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxXQRFTPRVSLOsRVhoiVQAAAYI"]
[Thu Sep 17 15:10:25.779587 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-active-formatting-elements.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiWQAAATQ"]
[Thu Sep 17 15:10:25.779755 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:36246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-active-formatting-elements.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiWQAAATQ"]
[Thu Sep 17 15:10:25.826056 2026] [autoindex:error] [pid 955873:tid 956014] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:25.826736 2026] [security2:error] [pid 955873:tid 956014] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/"] [unique_id "aqxXQRFTPRVSLOsRVhoiWwAAARU"]
[Thu Sep 17 15:10:25.837202 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:37256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiVwAAAWA"]
[Thu Sep 17 15:10:25.908394 2026] [security2:error] [pid 955873:tid 956041] [client 114.10.146.139:62936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiWgABMB4"]
[Thu Sep 17 15:10:25.976987 2026] [security2:error] [pid 955873:tid 956127] [client 162.241.226.11:39054] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiXwAAAYY"]
[Thu Sep 17 15:10:26.001014 2026] [security2:error] [pid 955873:tid 956085] [client 34.44.196.215:12176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiUQABXC0"]
[Thu Sep 17 15:10:26.018315 2026] [autoindex:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.018845 2026] [security2:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/css/"] [unique_id "aqxXQhFTPRVSLOsRVhoiYAAAAS4"]
[Thu Sep 17 15:10:26.070973 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:36252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-attribute-token.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYQAAARY"]
[Thu Sep 17 15:10:26.071106 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:36252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-attribute-token.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYQAAARY"]
[Thu Sep 17 15:10:26.072479 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/p.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYgAAAQo"]
[Thu Sep 17 15:10:26.226013 2026] [autoindex:error] [pid 955873:tid 956057] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.226540 2026] [security2:error] [pid 955873:tid 956057] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxXQhFTPRVSLOsRVhoiZAAAAUA"]
[Thu Sep 17 15:10:26.288589 2026] [security2:error] [pid 955873:tid 956105] [client 156.192.234.52:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZQAAAXA"]
[Thu Sep 17 15:10:26.292367 2026] [security2:error] [pid 955873:tid 956105] [client 156.192.234.52:59296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZQAAAXA"]
[Thu Sep 17 15:10:26.364271 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-decoder.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZwAAAUU"]
[Thu Sep 17 15:10:26.364407 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:36256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-decoder.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZwAAAUU"]
[Thu Sep 17 15:10:26.417481 2026] [autoindex:error] [pid 955873:tid 956104] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.418133 2026] [security2:error] [pid 955873:tid 956104] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxXQhFTPRVSLOsRVhoiaAAAAW8"]
[Thu Sep 17 15:10:26.457438 2026] [security2:error] [pid 955873:tid 956016] [client 34.44.196.215:12176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYwABFzs"]
[Thu Sep 17 15:10:26.569991 2026] [ssl:error] [pid 955873:tid 956126] [client 199.45.154.55:40656] AH02032: Hostname box5305.bluehost.com (default host as no SNI was provided) and hostname mail.daprayer.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Sep 17 15:10:26.616642 2026] [autoindex:error] [pid 955873:tid 956108] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.617234 2026] [security2:error] [pid 955873:tid 956108] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxXQhFTPRVSLOsRVhoibgAAAXM"]
[Thu Sep 17 15:10:26.654193 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:36272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-doctype-info.php"] [unique_id "aqxXQhFTPRVSLOsRVhoicAAAAUY"]
[Thu Sep 17 15:10:26.654309 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:36272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-doctype-info.php"] [unique_id "aqxXQhFTPRVSLOsRVhoicAAAAUY"]
[Thu Sep 17 15:10:26.790737 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:37260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/debug.php"] [unique_id "aqxXQhFTPRVSLOsRVhoicQAAAXQ"]
[Thu Sep 17 15:10:26.821201 2026] [autoindex:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.821684 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxXQhFTPRVSLOsRVhoicgAAATc"]
[Thu Sep 17 15:10:26.902746 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:64354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoieAAAAUE"]
[Thu Sep 17 15:10:26.902849 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:64354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoieAAAAUE"]
[Thu Sep 17 15:10:26.919224 2026] [security2:error] [pid 955873:tid 956084] [client 5.189.145.112:49264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxXQhFTPRVSLOsRVhoieQAAAVs"], referer: binance.com
[Thu Sep 17 15:10:26.936436 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-open-elements.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiewAAAYg"]
[Thu Sep 17 15:10:26.936531 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-open-elements.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiewAAAYg"]
[Thu Sep 17 15:10:27.026400 2026] [autoindex:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:27.027090 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/Text/"] [unique_id "aqxXQxFTPRVSLOsRVhoifAAAAXc"]
[Thu Sep 17 15:10:27.069302 2026] [security2:error] [pid 955873:tid 956043] [client 57.141.14.108:20558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiegABMkk"]
[Thu Sep 17 15:10:27.107392 2026] [security2:error] [pid 955873:tid 956118] [client 115.244.164.14:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQxFTPRVSLOsRVhoifgAAAX0"]
[Thu Sep 17 15:10:27.107478 2026] [security2:error] [pid 955873:tid 956118] [client 115.244.164.14:63359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQxFTPRVSLOsRVhoifgAAAX0"]
[Thu Sep 17 15:10:27.223482 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor-state.php"] [unique_id "aqxXQxFTPRVSLOsRVhoigwAAAYc"]
[Thu Sep 17 15:10:27.223597 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:36294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor-state.php"] [unique_id "aqxXQxFTPRVSLOsRVhoigwAAAYc"]
[Thu Sep 17 15:10:27.432711 2026] [security2:error] [pid 955873:tid 956037] [client 34.44.196.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxXQxFTPRVSLOsRVhoifwAAASw"]
[Thu Sep 17 15:10:27.501490 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor.php"] [unique_id "aqxXQxFTPRVSLOsRVhoihwAAAVg"]
[Thu Sep 17 15:10:27.501588 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:36310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor.php"] [unique_id "aqxXQxFTPRVSLOsRVhoihwAAAVg"]
[Thu Sep 17 15:10:27.513890 2026] [security2:error] [pid 955873:tid 956038] [client 35.244.43.255:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXQxFTPRVSLOsRVhoiiAAAAS0"]
[Thu Sep 17 15:10:27.793170 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-span.php"] [unique_id "aqxXQxFTPRVSLOsRVhoijgAAARk"]
[Thu Sep 17 15:10:27.793307 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:36316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-span.php"] [unique_id "aqxXQxFTPRVSLOsRVhoijgAAARk"]
[Thu Sep 17 15:10:27.887876 2026] [authz_core:error] [pid 955873:tid 956098] [client 169.58.197.253:63629] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:10:28.076958 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-stack-event.php"] [unique_id "aqxXRBFTPRVSLOsRVhoikAAAARE"]
[Thu Sep 17 15:10:28.077112 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-stack-event.php"] [unique_id "aqxXRBFTPRVSLOsRVhoikAAAARE"]
[Thu Sep 17 15:10:28.247100 2026] [security2:error] [pid 955873:tid 956121] [client 35.244.43.255:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXRBFTPRVSLOsRVhoilwAAAYA"]
[Thu Sep 17 15:10:28.366190 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-tag-processor.php"] [unique_id "aqxXRBFTPRVSLOsRVhoimAAAAR0"]
[Thu Sep 17 15:10:28.366270 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-tag-processor.php"] [unique_id "aqxXRBFTPRVSLOsRVhoimAAAAR0"]
[Thu Sep 17 15:10:28.643275 2026] [security2:error] [pid 955873:tid 956087] [client 4.240.114.86:64244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxXRBFTPRVSLOsRVhoioAAAAV4"], referer: binance.com
[Thu Sep 17 15:10:28.654454 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-text-replacement.php"] [unique_id "aqxXRBFTPRVSLOsRVhoioQAAAXw"]
[Thu Sep 17 15:10:28.654568 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-text-replacement.php"] [unique_id "aqxXRBFTPRVSLOsRVhoioQAAAXw"]
[Thu Sep 17 15:10:28.714815 2026] [security2:error] [pid 955873:tid 956077] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXQxFTPRVSLOsRVhoiggAAAVQ"]
[Thu Sep 17 15:10:28.714843 2026] [security2:error] [pid 955873:tid 956077] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXQxFTPRVSLOsRVhoiggAAAVQ"]
[Thu Sep 17 15:10:28.937928 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:36356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-token.php"] [unique_id "aqxXRBFTPRVSLOsRVhoipwAAAXQ"]
[Thu Sep 17 15:10:28.938046 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:36356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-token.php"] [unique_id "aqxXRBFTPRVSLOsRVhoipwAAAXQ"]
[Thu Sep 17 15:10:28.975897 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXRBFTPRVSLOsRVhoiqAAAAXM"]
[Thu Sep 17 15:10:29.112089 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqQAAATc"]
[Thu Sep 17 15:10:29.112114 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqQAAATc"]
[Thu Sep 17 15:10:29.224934 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:36372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-unsupported-exception.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqwAAAVs"]
[Thu Sep 17 15:10:29.225057 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:36372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-unsupported-exception.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqwAAAVs"]
[Thu Sep 17 15:10:29.403943 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoirAAAAXo"]
[Thu Sep 17 15:10:29.403972 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoirAAAAXo"]
[Thu Sep 17 15:10:29.512387 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:36380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/html5-named-character-references.php"] [unique_id "aqxXRRFTPRVSLOsRVhoisAAAATI"]
[Thu Sep 17 15:10:29.512508 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:36380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/html5-named-character-references.php"] [unique_id "aqxXRRFTPRVSLOsRVhoisAAAATI"]
[Thu Sep 17 15:10:29.604482 2026] [autoindex:error] [pid 955873:tid 956099] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:29.605007 2026] [security2:error] [pid 955873:tid 956099] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxXRRFTPRVSLOsRVhoisgAAAWo"]
[Thu Sep 17 15:10:29.695212 2026] [security2:error] [pid 955873:tid 956033] [client 35.244.43.255:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXRRFTPRVSLOsRVhoitAAAASg"]
[Thu Sep 17 15:10:29.793970 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/"] [unique_id "aqxXRRFTPRVSLOsRVhoitQAAAX0"]
[Thu Sep 17 15:10:29.818878 2026] [autoindex:error] [pid 955873:tid 956128] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:29.819331 2026] [security2:error] [pid 955873:tid 956128] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXRRFTPRVSLOsRVhoitgAAAYc"]
[Thu Sep 17 15:10:30.021113 2026] [security2:error] [pid 955873:tid 956050] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxXRhFTPRVSLOsRVhoiwAAAATk"]
[Thu Sep 17 15:10:30.052944 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/"] [unique_id "aqxXRRFTPRVSLOsRVhoivQAAASw"]
[Thu Sep 17 15:10:30.219172 2026] [autoindex:error] [pid 955873:tid 956081] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:30.219714 2026] [security2:error] [pid 955873:tid 956081] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxXRhFTPRVSLOsRVhoiwgAAAVg"]
[Thu Sep 17 15:10:30.353549 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "aqxXRhFTPRVSLOsRVhoixQAAAXk"]
[Thu Sep 17 15:10:30.424987 2026] [autoindex:error] [pid 955873:tid 956113] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:30.425500 2026] [security2:error] [pid 955873:tid 956113] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/customize/"] [unique_id "aqxXRhFTPRVSLOsRVhoixgAAAXg"]
[Thu Sep 17 15:10:30.427976 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXRhFTPRVSLOsRVhoixwAAAV0"]
[Thu Sep 17 15:10:30.509727 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "aqxXRhFTPRVSLOsRVhoiygAAATs"]
[Thu Sep 17 15:10:30.651942 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/codemirror/wp-includes/js/"] [unique_id "aqxXRhFTPRVSLOsRVhoiywAAAX4"]
[Thu Sep 17 15:10:30.844235 2026] [autoindex:error] [pid 955873:tid 956092] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:30.844735 2026] [security2:error] [pid 955873:tid 956092] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxXRhFTPRVSLOsRVhoi2AAAAWM"]
[Thu Sep 17 15:10:31.023995 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRhFTPRVSLOsRVhoi1wAAARA"]
[Thu Sep 17 15:10:31.024022 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRhFTPRVSLOsRVhoi1wAAARA"]
[Thu Sep 17 15:10:31.032808 2026] [autoindex:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:31.033296 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/images/"] [unique_id "aqxXRxFTPRVSLOsRVhoi2wAAAXU"]
[Thu Sep 17 15:10:31.226725 2026] [autoindex:error] [pid 955873:tid 956047] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:31.227188 2026] [security2:error] [pid 955873:tid 956047] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/.well-known/"] [unique_id "aqxXRxFTPRVSLOsRVhoi3gAAATY"]
[Thu Sep 17 15:10:31.298033 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/crop/"] [unique_id "aqxXRxFTPRVSLOsRVhoi5QAAAQo"]
[Thu Sep 17 15:10:31.455407 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/crop/"] [unique_id "aqxXRxFTPRVSLOsRVhoi6gAAARo"]
[Thu Sep 17 15:10:31.511561 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi6AAAAXY"]
[Thu Sep 17 15:10:31.511590 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi6AAAAXY"]
[Thu Sep 17 15:10:31.618361 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/crop/wp-includes/js/"] [unique_id "aqxXRxFTPRVSLOsRVhoi7gAAARc"]
[Thu Sep 17 15:10:31.695652 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:42208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8AAAASs"]
[Thu Sep 17 15:10:31.706680 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:42208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8AAAASs"]
[Thu Sep 17 15:10:31.784571 2026] [security2:error] [pid 955873:tid 956105] [client 195.2.78.191:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.78.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi9wAAAXA"], referer: https://melissa-gonzales.com/
[Thu Sep 17 15:10:31.794804 2026] [autoindex:error] [pid 955873:tid 956010] [client 43.164.133.138:59022] AH01276: Cannot serve directory /home3/stayatsc/public_html/wp-content/plugins/the-events-calendar/build/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.schillinghausmuenster.com/wp-content/plugins/the-events-calendar/build/js
[Thu Sep 17 15:10:31.807132 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8gAAAYU"]
[Thu Sep 17 15:10:31.807159 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8gAAAYU"]
[Thu Sep 17 15:10:31.995867 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi9gAAAXQ"]
[Thu Sep 17 15:10:31.995894 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi9gAAAXQ"]
[Thu Sep 17 15:10:32.004426 2026] [autoindex:error] [pid 955873:tid 956084] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:32.004922 2026] [security2:error] [pid 955873:tid 956084] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxXRxFTPRVSLOsRVhoi_QAAAVs"]
[Thu Sep 17 15:10:32.147165 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/"] [unique_id "aqxXSBFTPRVSLOsRVhoi_wAAAWU"]
[Thu Sep 17 15:10:32.163955 2026] [security2:error] [pid 955873:tid 956063] [client 151.247.123.109:49355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.dieselrepair.shop"] [uri "/wp-login.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi-wAAAUY"], referer: https://www.dieselrepair.shop/diesel-service-locator/
[Thu Sep 17 15:10:32.208030 2026] [cgid:error] [pid 955873:tid 956035] [client 82.102.18.118:35210] AH01265: stderr from /home2/frenchz8/public_html/website_beaa9689/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:10:32.208512 2026] [security2:error] [pid 955873:tid 956035] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/cgi-bin/"] [unique_id "aqxXSBFTPRVSLOsRVhojAAAAASo"]
[Thu Sep 17 15:10:32.388973 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/"] [unique_id "aqxXSBFTPRVSLOsRVhojAQAAARs"]
[Thu Sep 17 15:10:32.501996 2026] [security2:error] [pid 955873:tid 956055] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojBAAAAT4"]
[Thu Sep 17 15:10:32.502022 2026] [security2:error] [pid 955873:tid 956055] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojBAAAAT4"]
[Thu Sep 17 15:10:32.541320 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/wp-includes/js/"] [unique_id "aqxXSBFTPRVSLOsRVhojCgAAASg"]
[Thu Sep 17 15:10:32.579826 2026] [security2:error] [pid 955873:tid 956118] [client 4.240.114.86:50273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDAAAAX0"], referer: binance.com
[Thu Sep 17 15:10:32.847275 2026] [security2:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDwAAASw"]
[Thu Sep 17 15:10:32.847309 2026] [security2:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDwAAASw"]
[Thu Sep 17 15:10:32.946930 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDgAAATk"]
[Thu Sep 17 15:10:32.946956 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDgAAATk"]
[Thu Sep 17 15:10:33.084991 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/development/"] [unique_id "aqxXSRFTPRVSLOsRVhojHAAAAWk"]
[Thu Sep 17 15:10:33.116101 2026] [security2:error] [pid 955873:tid 956005] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojGQAAAQw"]
[Thu Sep 17 15:10:33.116143 2026] [security2:error] [pid 955873:tid 956005] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojGQAAAQw"]
[Thu Sep 17 15:10:33.242172 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/development/"] [unique_id "aqxXSRFTPRVSLOsRVhojIAAAAU0"]
[Thu Sep 17 15:10:33.248811 2026] [security2:error] [pid 955873:tid 956073] [client 35.244.43.255:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXSRFTPRVSLOsRVhojIQAAAVA"]
[Thu Sep 17 15:10:33.267490 2026] [security2:error] [pid 955873:tid 956093] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojFQAAAWQ"]
[Thu Sep 17 15:10:33.393003 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/development/wp-includes/js/dist/"] [unique_id "aqxXSRFTPRVSLOsRVhojKQAAAYE"]
[Thu Sep 17 15:10:33.411157 2026] [security2:error] [pid 955873:tid 956121] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojKAAAAYA"]
[Thu Sep 17 15:10:33.411177 2026] [security2:error] [pid 955873:tid 956121] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojKAAAAYA"]
[Thu Sep 17 15:10:33.701748 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLgAAAQ0"]
[Thu Sep 17 15:10:33.701785 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLgAAAQ0"]
[Thu Sep 17 15:10:33.737519 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLQAAAVY"]
[Thu Sep 17 15:10:33.737543 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLQAAAVY"]
[Thu Sep 17 15:10:33.919847 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/"] [unique_id "aqxXSRFTPRVSLOsRVhojOAAAAR0"]
[Thu Sep 17 15:10:34.004123 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojNwAAAVk"]
[Thu Sep 17 15:10:34.004157 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojNwAAAVk"]
[Thu Sep 17 15:10:34.056167 2026] [security2:error] [pid 955873:tid 956015] [client 35.244.43.255:37312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojOgAAARY"]
[Thu Sep 17 15:10:34.158152 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/"] [unique_id "aqxXShFTPRVSLOsRVhojOwAAARE"]
[Thu Sep 17 15:10:34.294041 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:37312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/php-info.php"] [unique_id "aqxXShFTPRVSLOsRVhojPgAAAS4"]
[Thu Sep 17 15:10:34.296993 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/wp-includes/js/dist/"] [unique_id "aqxXShFTPRVSLOsRVhojPwAAASU"]
[Thu Sep 17 15:10:34.306384 2026] [security2:error] [pid 955873:tid 956089] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojPQAAAWA"]
[Thu Sep 17 15:10:34.306408 2026] [security2:error] [pid 955873:tid 956089] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojPQAAAWA"]
[Thu Sep 17 15:10:34.606811 2026] [security2:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRgAAAR8"]
[Thu Sep 17 15:10:34.606839 2026] [security2:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRgAAAR8"]
[Thu Sep 17 15:10:34.638273 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRQAAAUw"]
[Thu Sep 17 15:10:34.638298 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRQAAAUw"]
[Thu Sep 17 15:10:34.653267 2026] [security2:error] [pid 955873:tid 956041] [client 5.189.145.112:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxXShFTPRVSLOsRVhojSAAAATA"], referer: binance.com
[Thu Sep 17 15:10:34.716423 2026] [security2:error] [pid 955873:tid 956094] [client 45.169.98.18:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXShFTPRVSLOsRVhojSQAAAWU"]
[Thu Sep 17 15:10:34.716530 2026] [security2:error] [pid 955873:tid 956094] [client 45.169.98.18:52849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXShFTPRVSLOsRVhojSQAAAWU"]
[Thu Sep 17 15:10:34.821482 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/a11y/"] [unique_id "aqxXShFTPRVSLOsRVhojSwAAARs"]
[Thu Sep 17 15:10:34.920730 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojSgAAAXc"]
[Thu Sep 17 15:10:34.920759 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojSgAAAXc"]
[Thu Sep 17 15:10:34.968968 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/a11y/index.js"] [unique_id "aqxXShFTPRVSLOsRVhojUQAAARI"]
[Thu Sep 17 15:10:35.053798 2026] [security2:error] [pid 955873:tid 956043] [client 35.244.43.255:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpversion.php"] [unique_id "aqxXSxFTPRVSLOsRVhojVQAAATI"]
[Thu Sep 17 15:10:35.108182 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/abilities/"] [unique_id "aqxXSxFTPRVSLOsRVhojVwAAAT0"]
[Thu Sep 17 15:10:35.215987 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojWAAAAWY"]
[Thu Sep 17 15:10:35.216017 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojWAAAAWY"]
[Thu Sep 17 15:10:35.392605 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/abilities/index.js"] [unique_id "aqxXSxFTPRVSLOsRVhojWQAAAVI"]
[Thu Sep 17 15:10:35.489422 2026] [security2:error] [pid 955873:tid 956128] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env"] [unique_id "aqxXSxFTPRVSLOsRVhojXwAAAYc"]
[Thu Sep 17 15:10:35.508929 2026] [security2:error] [pid 955873:tid 956052] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojXAAAATs"]
[Thu Sep 17 15:10:35.508963 2026] [security2:error] [pid 955873:tid 956052] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojXAAAATs"]
[Thu Sep 17 15:10:35.667946 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/"] [unique_id "aqxXSxFTPRVSLOsRVhojYgAAAQw"]
[Thu Sep 17 15:10:35.761457 2026] [security2:error] [pid 955873:tid 956049] [client 35.244.43.255:60702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/_phpinfo.php"] [unique_id "aqxXSxFTPRVSLOsRVhojZAAAATg"]
[Thu Sep 17 15:10:35.830887 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/"] [unique_id "aqxXSxFTPRVSLOsRVhojZQAAAWI"]
[Thu Sep 17 15:10:35.933146 2026] [security2:error] [pid 955873:tid 956032] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojZgAAASc"]
[Thu Sep 17 15:10:35.933171 2026] [security2:error] [pid 955873:tid 956032] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojZgAAASc"]
[Thu Sep 17 15:10:35.955745 2026] [security2:error] [pid 955873:tid 956092] [client 185.55.149.49:58533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXSxFTPRVSLOsRVhojaQAAAWM"]
[Thu Sep 17 15:10:35.955900 2026] [security2:error] [pid 955873:tid 956092] [client 185.55.149.49:58533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXSxFTPRVSLOsRVhojaQAAAWM"]
[Thu Sep 17 15:10:35.972704 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/wp-includes/js/dist/script-modules/"] [unique_id "aqxXSxFTPRVSLOsRVhojawAAAXU"]
[Thu Sep 17 15:10:36.096338 2026] [security2:error] [pid 955873:tid 956098] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojYQAAAWk"]
[Thu Sep 17 15:10:36.230833 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbQAAAX8"]
[Thu Sep 17 15:10:36.230857 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbQAAAX8"]
[Thu Sep 17 15:10:36.331295 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbgAAATY"]
[Thu Sep 17 15:10:36.331318 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbgAAATY"]
[Thu Sep 17 15:10:36.470488 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/"] [unique_id "aqxXTBFTPRVSLOsRVhojcwAAATQ"]
[Thu Sep 17 15:10:36.486344 2026] [security2:error] [pid 955873:tid 956006] [client 35.244.43.255:60718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXTBFTPRVSLOsRVhojdAAAAQ0"]
[Thu Sep 17 15:10:36.505004 2026] [security2:error] [pid 955873:tid 956088] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojcAAAAV8"]
[Thu Sep 17 15:10:36.505030 2026] [security2:error] [pid 955873:tid 956088] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojcAAAAV8"]
[Thu Sep 17 15:10:36.655724 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/"] [unique_id "aqxXTBFTPRVSLOsRVhojdQAAAU4"]
[Thu Sep 17 15:10:36.800609 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/wp-includes/js/dist/script-modules/block-editor/"] [unique_id "aqxXTBFTPRVSLOsRVhojeQAAAWw"]
[Thu Sep 17 15:10:36.812266 2026] [security2:error] [pid 955873:tid 956046] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojdwAAATU"]
[Thu Sep 17 15:10:36.812291 2026] [security2:error] [pid 955873:tid 956046] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojdwAAATU"]
[Thu Sep 17 15:10:36.845714 2026] [security2:error] [pid 955873:tid 956079] [client 156.192.234.52:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTBFTPRVSLOsRVhojegAAAVY"]
[Thu Sep 17 15:10:36.845848 2026] [security2:error] [pid 955873:tid 956079] [client 156.192.234.52:59947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTBFTPRVSLOsRVhojegAAAVY"]
[Thu Sep 17 15:10:37.108806 2026] [security2:error] [pid 955873:tid 956105] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojfwAAAXA"]
[Thu Sep 17 15:10:37.108845 2026] [security2:error] [pid 955873:tid 956105] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojfwAAAXA"]
[Thu Sep 17 15:10:37.135783 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojfQAAAT8"]
[Thu Sep 17 15:10:37.135810 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojfQAAAT8"]
[Thu Sep 17 15:10:37.186213 2026] [security2:error] [pid 955873:tid 956072] [client 4.240.114.86:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxXTRFTPRVSLOsRVhojgwAAAU8"], referer: binance.com
[Thu Sep 17 15:10:37.217042 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:60730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/server-info.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhQAAAVk"]
[Thu Sep 17 15:10:37.277951 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/fit-text-frontend.min.asset.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhwAAATE"]
[Thu Sep 17 15:10:37.278063 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/fit-text-frontend.min.asset.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhwAAATE"]
[Thu Sep 17 15:10:37.419306 2026] [security2:error] [pid 955873:tid 956065] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojiAAAAUg"]
[Thu Sep 17 15:10:37.419329 2026] [security2:error] [pid 955873:tid 956065] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojiAAAAUg"]
[Thu Sep 17 15:10:37.562816 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXTRFTPRVSLOsRVhojjQAAAQ8"]
[Thu Sep 17 15:10:37.602515 2026] [security2:error] [pid 955873:tid 956023] [client 115.244.164.14:64080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjwAAAR4"]
[Thu Sep 17 15:10:37.602596 2026] [security2:error] [pid 955873:tid 956023] [client 115.244.164.14:64080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjwAAAR4"]
[Thu Sep 17 15:10:37.681454 2026] [security2:error] [pid 955873:tid 956057] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhgAAAUA"]
[Thu Sep 17 15:10:37.693982 2026] [security2:error] [pid 955873:tid 956109] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjgAAAXQ"]
[Thu Sep 17 15:10:37.694017 2026] [security2:error] [pid 955873:tid 956109] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjgAAAXQ"]
[Thu Sep 17 15:10:37.777562 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXTRFTPRVSLOsRVhojkAAAAWU"]
[Thu Sep 17 15:10:37.915306 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/wp-includes/js/dist/script-modules/"] [unique_id "aqxXTRFTPRVSLOsRVhojlAAAAWo"]
[Thu Sep 17 15:10:37.947489 2026] [security2:error] [pid 955873:tid 956035] [client 35.244.43.255:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/server-status.php"] [unique_id "aqxXTRFTPRVSLOsRVhojlQAAASo"]
[Thu Sep 17 15:10:37.978406 2026] [security2:error] [pid 955873:tid 956064] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojkQAAAUc"]
[Thu Sep 17 15:10:37.978436 2026] [security2:error] [pid 955873:tid 956064] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojkQAAAUc"]
[Thu Sep 17 15:10:38.051260 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXThFTPRVSLOsRVhojlwAAATA"]
[Thu Sep 17 15:10:38.051374 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:64948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXThFTPRVSLOsRVhojlwAAATA"]
[Thu Sep 17 15:10:38.286211 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmQAAARI"]
[Thu Sep 17 15:10:38.286239 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmQAAARI"]
[Thu Sep 17 15:10:38.337445 2026] [security2:error] [pid 955873:tid 956021] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmwAAARw"]
[Thu Sep 17 15:10:38.337467 2026] [security2:error] [pid 955873:tid 956021] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmwAAARw"]
[Thu Sep 17 15:10:38.429271 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/"] [unique_id "aqxXThFTPRVSLOsRVhojogAAAYM"]
[Thu Sep 17 15:10:38.476413 2026] [security2:error] [pid 955873:tid 956051] [client 172.86.81.177:51412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojiQAAATo"], referer: http://mail.thephoenixprojects.org/.git/config
[Thu Sep 17 15:10:38.589239 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/"] [unique_id "aqxXThFTPRVSLOsRVhojpAAAAXg"]
[Thu Sep 17 15:10:38.609431 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojowAAAWY"]
[Thu Sep 17 15:10:38.609456 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojowAAAWY"]
[Thu Sep 17 15:10:38.735058 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXThFTPRVSLOsRVhojqAAAAQw"]
[Thu Sep 17 15:10:38.845198 2026] [security2:error] [pid 955873:tid 956050] [client 35.244.43.255:60754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojpwAAATk"]
[Thu Sep 17 15:10:38.904651 2026] [security2:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojqgAAATg"]
[Thu Sep 17 15:10:38.904713 2026] [security2:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojqgAAATg"]
[Thu Sep 17 15:10:39.073072 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojrAAAASc"]
[Thu Sep 17 15:10:39.073102 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojrAAAASc"]
[Thu Sep 17 15:10:39.169352 2026] [security2:error] [pid 955873:tid 956053] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojqQAAATw"]
[Thu Sep 17 15:10:39.181097 2026] [security2:error] [pid 955873:tid 956107] [client 35.244.43.255:60754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsAAAAXI"]
[Thu Sep 17 15:10:39.210608 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsQAAAVA"]
[Thu Sep 17 15:10:39.210636 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsQAAAVA"]
[Thu Sep 17 15:10:39.217398 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/view.min.asset.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsgAAAWQ"]
[Thu Sep 17 15:10:39.217480 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/view.min.asset.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsgAAAWQ"]
[Thu Sep 17 15:10:39.434412 2026] [security2:error] [pid 955873:tid 956059] [client 35.244.43.255:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXTxFTPRVSLOsRVhojtgAAAUI"]
[Thu Sep 17 15:10:39.515243 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojtQAAAQ0"]
[Thu Sep 17 15:10:39.515272 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojtQAAAQ0"]
[Thu Sep 17 15:10:39.554954 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:60422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/"] [unique_id "aqxXTxFTPRVSLOsRVhojuQAAAWE"]
[Thu Sep 17 15:10:39.599388 2026] [security2:error] [pid 955873:tid 956013] [client 190.114.33.243:30544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojuAABFAI"]
[Thu Sep 17 15:10:39.725091 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/"] [unique_id "aqxXTxFTPRVSLOsRVhojvQAAARc"]
[Thu Sep 17 15:10:39.793333 2026] [security2:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojvgAAAWw"]
[Thu Sep 17 15:10:39.793354 2026] [security2:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojvgAAAWw"]
[Thu Sep 17 15:10:39.839608 2026] [security2:error] [pid 955873:tid 956015] [client 127.0.0.1:40822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXTxFTPRVSLOsRVhojxAAAARY"]
[Thu Sep 17 15:10:39.839608 2026] [security2:error] [pid 955873:tid 956036] [client 74.7.228.32:37262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tazbodywork.com"] [uri "/robots.txt"] [unique_id "aqxXTxFTPRVSLOsRVhojwwAAASs"]
[Thu Sep 17 15:10:39.863134 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:60422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXTxFTPRVSLOsRVhojyAAAAR0"]
[Thu Sep 17 15:10:40.098843 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojzQAAAYY"]
[Thu Sep 17 15:10:40.098868 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojzQAAAYY"]
[Thu Sep 17 15:10:40.173018 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj0QAAAVk"]
[Thu Sep 17 15:10:40.219616 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhojzwAAAWg"]
[Thu Sep 17 15:10:40.219644 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhojzwAAAWg"]
[Thu Sep 17 15:10:40.356757 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/view.min.asset.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj1AAAARM"]
[Thu Sep 17 15:10:40.356873 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:60422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/view.min.asset.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj1AAAARM"]
[Thu Sep 17 15:10:40.401878 2026] [security2:error] [pid 955873:tid 956102] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj0gAAAW0"]
[Thu Sep 17 15:10:40.401909 2026] [security2:error] [pid 955873:tid 956102] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj0gAAAW0"]
[Thu Sep 17 15:10:40.637140 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/"] [unique_id "aqxXUBFTPRVSLOsRVhoj2gAAAXo"]
[Thu Sep 17 15:10:40.697518 2026] [security2:error] [pid 955873:tid 956025] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj2QAAASA"]
[Thu Sep 17 15:10:40.697543 2026] [security2:error] [pid 955873:tid 956025] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj2QAAASA"]
[Thu Sep 17 15:10:40.808220 2026] [security2:error] [pid 955873:tid 956008] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj1QAAAQ8"]
[Thu Sep 17 15:10:40.809381 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/"] [unique_id "aqxXUBFTPRVSLOsRVhoj2wAAASo"]
[Thu Sep 17 15:10:40.891678 2026] [security2:error] [pid 955873:tid 956057] [client 35.244.43.255:60770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj3AAAAUA"]
[Thu Sep 17 15:10:40.949156 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:56126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXUBFTPRVSLOsRVhoj3gAAATA"]
[Thu Sep 17 15:10:41.020545 2026] [security2:error] [pid 955873:tid 956129] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj3QAAAYg"]
[Thu Sep 17 15:10:41.020574 2026] [security2:error] [pid 955873:tid 956129] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj3QAAAYg"]
[Thu Sep 17 15:10:41.256400 2026] [autoindex:error] [pid 955873:tid 956118] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:41.257550 2026] [security2:error] [pid 955873:tid 956118] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/css/"] [unique_id "aqxXURFTPRVSLOsRVhoj4gAAAX0"]
[Thu Sep 17 15:10:41.282912 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj4QAAATM"]
[Thu Sep 17 15:10:41.282937 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj4QAAATM"]
[Thu Sep 17 15:10:41.421639 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/view.min.asset.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5AAAAXg"]
[Thu Sep 17 15:10:41.421755 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:56126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/view.min.asset.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5AAAAXg"]
[Thu Sep 17 15:10:41.531566 2026] [security2:error] [pid 955873:tid 956051] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5QAAATo"]
[Thu Sep 17 15:10:41.531596 2026] [security2:error] [pid 955873:tid 956051] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5QAAATo"]
[Thu Sep 17 15:10:41.613270 2026] [security2:error] [pid 955873:tid 956026] [client 35.244.43.255:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXURFTPRVSLOsRVhoj6gAAASE"]
[Thu Sep 17 15:10:41.712441 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:56136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/"] [unique_id "aqxXURFTPRVSLOsRVhoj7QAAASQ"]
[Thu Sep 17 15:10:41.719003 2026] [security2:error] [pid 955873:tid 956106] [client 212.200.27.78:37492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj6QABcRw"]
[Thu Sep 17 15:10:41.830693 2026] [security2:error] [pid 955873:tid 956038] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj7gAAAS0"]
[Thu Sep 17 15:10:41.830733 2026] [security2:error] [pid 955873:tid 956038] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj7gAAAS0"]
[Thu Sep 17 15:10:41.878572 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/"] [unique_id "aqxXURFTPRVSLOsRVhoj7wAAAW4"]
[Thu Sep 17 15:10:41.929549 2026] [security2:error] [pid 955873:tid 956009] [client 5.189.145.112:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxXURFTPRVSLOsRVhoj8AAAARA"], referer: binance.com
[Thu Sep 17 15:10:42.016874 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXUhFTPRVSLOsRVhoj9AAAAYQ"]
[Thu Sep 17 15:10:42.088365 2026] [autoindex:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.088879 2026] [security2:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/maint/"] [unique_id "aqxXUhFTPRVSLOsRVhoj8wAAATg"]
[Thu Sep 17 15:10:42.137470 2026] [security2:error] [pid 955873:tid 956054] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj7AAAAT0"]
[Thu Sep 17 15:10:42.219826 2026] [security2:error] [pid 955873:tid 956033] [client 154.190.208.131:41520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj-AAAASg"]
[Thu Sep 17 15:10:42.220165 2026] [security2:error] [pid 955873:tid 956033] [client 154.190.208.131:41520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj-AAAASg"]
[Thu Sep 17 15:10:42.328199 2026] [security2:error] [pid 955873:tid 956098] [client 35.244.43.255:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj-gAAAWk"]
[Thu Sep 17 15:10:42.335466 2026] [authz_core:error] [pid 955873:tid 956107] [client 82.102.18.118:35210] AH01630: client denied by server configuration: /home2/frenchz8/public_html/website_beaa9689/wp-content/plugins/akismet/
[Thu Sep 17 15:10:42.336806 2026] [security2:error] [pid 955873:tid 956107] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxXUhFTPRVSLOsRVhoj-wAAAXI"]
[Thu Sep 17 15:10:42.374333 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj9wAAAUs"]
[Thu Sep 17 15:10:42.374360 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj9wAAAUs"]
[Thu Sep 17 15:10:42.518370 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/view.min.asset.php"] [unique_id "aqxXUhFTPRVSLOsRVhokAAAAAYE"]
[Thu Sep 17 15:10:42.518470 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/view.min.asset.php"] [unique_id "aqxXUhFTPRVSLOsRVhokAAAAAYE"]
[Thu Sep 17 15:10:42.525556 2026] [autoindex:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.526096 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/assets/"] [unique_id "aqxXUhFTPRVSLOsRVhoj_gAAAXU"]
[Thu Sep 17 15:10:42.718048 2026] [autoindex:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.718551 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxXUhFTPRVSLOsRVhokBQAAAXY"]
[Thu Sep 17 15:10:42.798637 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:56152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/"] [unique_id "aqxXUhFTPRVSLOsRVhokBgAAAXw"]
[Thu Sep 17 15:10:42.921308 2026] [autoindex:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.922103 2026] [security2:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxXUhFTPRVSLOsRVhokBwAAAWw"]
[Thu Sep 17 15:10:42.960107 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/"] [unique_id "aqxXUhFTPRVSLOsRVhokCAAAAXA"]
[Thu Sep 17 15:10:43.060943 2026] [security2:error] [pid 955873:tid 956079] [client 35.244.43.255:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXUxFTPRVSLOsRVhokDQAAAVY"]
[Thu Sep 17 15:10:43.099166 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:56152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXUxFTPRVSLOsRVhokDgAAATY"]
[Thu Sep 17 15:10:43.261136 2026] [security2:error] [pid 955873:tid 956048] [client 4.240.114.86:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxXUxFTPRVSLOsRVhokEgAAATc"], referer: binance.com
[Thu Sep 17 15:10:43.366099 2026] [autoindex:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.366652 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxXUxFTPRVSLOsRVhokFwAAAVk"]
[Thu Sep 17 15:10:43.443726 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUxFTPRVSLOsRVhokEQAAAUk"]
[Thu Sep 17 15:10:43.443758 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUxFTPRVSLOsRVhokEQAAAUk"]
[Thu Sep 17 15:10:43.444041 2026] [security2:error] [pid 955873:tid 956022] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXUxFTPRVSLOsRVhokCwAAAR0"]
[Thu Sep 17 15:10:43.541188 2026] [autoindex:error] [pid 955873:tid 956012] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.541753 2026] [security2:error] [pid 955873:tid 956012] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/js/"] [unique_id "aqxXUxFTPRVSLOsRVhokGgAAARM"]
[Thu Sep 17 15:10:43.617346 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:56152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/view.min.asset.php"] [unique_id "aqxXUxFTPRVSLOsRVhokHAAAAVs"]
[Thu Sep 17 15:10:43.617496 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:56152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/view.min.asset.php"] [unique_id "aqxXUxFTPRVSLOsRVhokHAAAAVs"]
[Thu Sep 17 15:10:43.736263 2026] [autoindex:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.736736 2026] [security2:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxXUxFTPRVSLOsRVhokHQAAAR8"]
[Thu Sep 17 15:10:43.898441 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:56164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/"] [unique_id "aqxXUxFTPRVSLOsRVhokIQAAARI"]
[Thu Sep 17 15:10:43.949505 2026] [security2:error] [pid 955873:tid 956030] [client 35.244.43.255:60806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXUxFTPRVSLOsRVhokIwAAASU"]
[Thu Sep 17 15:10:43.955459 2026] [autoindex:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.956220 2026] [security2:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxXUxFTPRVSLOsRVhokIgAAASw"]
[Thu Sep 17 15:10:44.033276 2026] [security2:error] [pid 955873:tid 956052] [client 3.82.141.143:54918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php~"] [unique_id "aqxXVBFTPRVSLOsRVhokMgAAATs"]
[Thu Sep 17 15:10:44.033368 2026] [security2:error] [pid 955873:tid 956051] [client 3.82.141.143:54900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php"] [unique_id "aqxXVBFTPRVSLOsRVhokMAAAATo"]
[Thu Sep 17 15:10:44.033943 2026] [security2:error] [pid 955873:tid 956026] [client 3.82.141.143:54904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php.save"] [unique_id "aqxXVBFTPRVSLOsRVhokMwAAASE"]
[Thu Sep 17 15:10:44.034751 2026] [security2:error] [pid 955873:tid 956038] [client 3.82.141.143:54912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXVBFTPRVSLOsRVhokNgAAAS0"]
[Thu Sep 17 15:10:44.036462 2026] [security2:error] [pid 955873:tid 956029] [client 3.82.141.143:54736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/config.php"] [unique_id "aqxXVBFTPRVSLOsRVhokOAAAASQ"]
[Thu Sep 17 15:10:44.046944 2026] [security2:error] [pid 955873:tid 956096] [client 3.82.141.143:54902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php.old"] [unique_id "aqxXVBFTPRVSLOsRVhokSAAAAWc"]
[Thu Sep 17 15:10:44.065169 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/"] [unique_id "aqxXVBFTPRVSLOsRVhokOQAAAQo"]
[Thu Sep 17 15:10:44.143415 2026] [autoindex:error] [pid 955873:tid 956083] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:44.143925 2026] [security2:error] [pid 955873:tid 956083] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxXVBFTPRVSLOsRVhokVQAAAVo"]
[Thu Sep 17 15:10:44.277403 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:56164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVBFTPRVSLOsRVhokVgAAAUE"]
[Thu Sep 17 15:10:44.503107 2026] [security2:error] [pid 955873:tid 956064] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env.bak"] [unique_id "aqxXVBFTPRVSLOsRVhokWQAAAUc"]
[Thu Sep 17 15:10:44.534001 2026] [security2:error] [pid 955873:tid 956078] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokVwAAAVU"]
[Thu Sep 17 15:10:44.534023 2026] [security2:error] [pid 955873:tid 956078] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokVwAAAVU"]
[Thu Sep 17 15:10:44.636167 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokWAAAAUY"]
[Thu Sep 17 15:10:44.636214 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokWAAAAUY"]
[Thu Sep 17 15:10:44.662118 2026] [security2:error] [pid 955873:tid 956094] [client 35.244.43.255:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXVBFTPRVSLOsRVhokYwAAAWU"]
[Thu Sep 17 15:10:44.726889 2026] [autoindex:error] [pid 955873:tid 956076] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:44.727445 2026] [security2:error] [pid 955873:tid 956076] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxXVBFTPRVSLOsRVhokZAAAAVM"]
[Thu Sep 17 15:10:44.773498 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:56164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/view.min.asset.php"] [unique_id "aqxXVBFTPRVSLOsRVhokZQAAARo"]
[Thu Sep 17 15:10:44.773604 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:56164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/view.min.asset.php"] [unique_id "aqxXVBFTPRVSLOsRVhokZQAAARo"]
[Thu Sep 17 15:10:44.786934 2026] [security2:error] [pid 955873:tid 956044] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env.backup"] [unique_id "aqxXVBFTPRVSLOsRVhokZgAAATM"]
[Thu Sep 17 15:10:44.951703 2026] [autoindex:error] [pid 955873:tid 956093] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:44.952208 2026] [security2:error] [pid 955873:tid 956093] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxXVBFTPRVSLOsRVhokZwAAAWQ"]
[Thu Sep 17 15:10:45.062221 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:56172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/"] [unique_id "aqxXVRFTPRVSLOsRVhokbQAAAWc"]
[Thu Sep 17 15:10:45.128541 2026] [autoindex:error] [pid 955873:tid 956003] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.129029 2026] [security2:error] [pid 955873:tid 956003] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxXVRFTPRVSLOsRVhokbgAAAQo"]
[Thu Sep 17 15:10:45.170329 2026] [security2:error] [pid 955873:tid 956080] [client 45.169.98.18:53403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVRFTPRVSLOsRVhokcAAAAVc"]
[Thu Sep 17 15:10:45.170429 2026] [security2:error] [pid 955873:tid 956080] [client 45.169.98.18:53403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVRFTPRVSLOsRVhokcAAAAVc"]
[Thu Sep 17 15:10:45.238761 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/"] [unique_id "aqxXVRFTPRVSLOsRVhokcwAAARU"]
[Thu Sep 17 15:10:45.379163 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:56172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVRFTPRVSLOsRVhokeAAAAWY"]
[Thu Sep 17 15:10:45.381782 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php~"] [unique_id "aqxXVRFTPRVSLOsRVhokeQAAAXg"]
[Thu Sep 17 15:10:45.409503 2026] [autoindex:error] [pid 955873:tid 956079] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.410054 2026] [security2:error] [pid 955873:tid 956079] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxXVRFTPRVSLOsRVhokegAAAVY"]
[Thu Sep 17 15:10:45.425528 2026] [security2:error] [pid 955873:tid 956090] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokaAAAAWE"]
[Thu Sep 17 15:10:45.633224 2026] [autoindex:error] [pid 955873:tid 956054] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.633772 2026] [security2:error] [pid 955873:tid 956054] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxXVRFTPRVSLOsRVhokgQAAAT0"]
[Thu Sep 17 15:10:45.739479 2026] [security2:error] [pid 955873:tid 956089] [client 169.58.197.253:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxXVRFTPRVSLOsRVhokgwAAAWA"], referer: binance.com
[Thu Sep 17 15:10:45.772551 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVRFTPRVSLOsRVhokfwAAAYU"]
[Thu Sep 17 15:10:45.772575 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVRFTPRVSLOsRVhokfwAAAYU"]
[Thu Sep 17 15:10:45.773982 2026] [security2:error] [pid 955873:tid 956123] [client 45.18.242.176:36767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXVRFTPRVSLOsRVhokggABgms"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:10:45.841111 2026] [autoindex:error] [pid 955873:tid 956067] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.841611 2026] [security2:error] [pid 955873:tid 956067] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxXVRFTPRVSLOsRVhokhgAAAUo"]
[Thu Sep 17 15:10:45.916930 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:56172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/view.min.asset.php"] [unique_id "aqxXVRFTPRVSLOsRVhokigAAAUE"]
[Thu Sep 17 15:10:45.917034 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:56172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/view.min.asset.php"] [unique_id "aqxXVRFTPRVSLOsRVhokigAAAUE"]
[Thu Sep 17 15:10:46.072653 2026] [autoindex:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:46.073174 2026] [security2:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxXVhFTPRVSLOsRVhokkgAAAS4"]
[Thu Sep 17 15:10:46.109617 2026] [security2:error] [pid 955873:tid 956075] [client 35.244.43.255:47346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/info.php.bak"] [unique_id "aqxXVhFTPRVSLOsRVhoklgAAAVI"]
[Thu Sep 17 15:10:46.197951 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/"] [unique_id "aqxXVhFTPRVSLOsRVhokmQAAAWg"]
[Thu Sep 17 15:10:46.341199 2026] [autoindex:error] [pid 955873:tid 956023] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:46.341679 2026] [security2:error] [pid 955873:tid 956023] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxXVhFTPRVSLOsRVhokmwAAAR4"]
[Thu Sep 17 15:10:46.349737 2026] [security2:error] [pid 955873:tid 956114] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env.old"] [unique_id "aqxXVhFTPRVSLOsRVhoknQAAAXk"]
[Thu Sep 17 15:10:46.355815 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/"] [unique_id "aqxXVhFTPRVSLOsRVhoknAAAAXc"]
[Thu Sep 17 15:10:46.499751 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVhFTPRVSLOsRVhokngAAAS8"]
[Thu Sep 17 15:10:46.641134 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokoQAAAYY"]
[Thu Sep 17 15:10:46.641164 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokoQAAAYY"]
[Thu Sep 17 15:10:46.648564 2026] [security2:error] [pid 955873:tid 956042] [client 185.55.149.49:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqwAAATE"]
[Thu Sep 17 15:10:46.648680 2026] [security2:error] [pid 955873:tid 956042] [client 185.55.149.49:59179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqwAAATE"]
[Thu Sep 17 15:10:46.843496 2026] [security2:error] [pid 955873:tid 956076] [client 35.244.43.255:47362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXVhFTPRVSLOsRVhoksAAAAVM"]
[Thu Sep 17 15:10:46.868753 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqgAAARw"]
[Thu Sep 17 15:10:46.868781 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqgAAARw"]
[Thu Sep 17 15:10:46.940132 2026] [security2:error] [pid 955873:tid 956011] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokrwAAARI"]
[Thu Sep 17 15:10:46.940155 2026] [security2:error] [pid 955873:tid 956011] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokrwAAARI"]
[Thu Sep 17 15:10:47.007082 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/view.min.asset.php"] [unique_id "aqxXVxFTPRVSLOsRVhokswAAATo"]
[Thu Sep 17 15:10:47.007224 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/view.min.asset.php"] [unique_id "aqxXVxFTPRVSLOsRVhokswAAATo"]
[Thu Sep 17 15:10:47.070297 2026] [security2:error] [pid 955873:tid 956020] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqQAAARs"]
[Thu Sep 17 15:10:47.110727 2026] [security2:error] [pid 955873:tid 956013] [client 127.0.0.1:10392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXVxFTPRVSLOsRVhoktgAAARQ"]
[Thu Sep 17 15:10:47.110733 2026] [security2:error] [pid 955873:tid 956029] [client 74.7.244.9:43658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.newyearworks.com"] [uri "/robots.txt"] [unique_id "aqxXVxFTPRVSLOsRVhoktAAAASQ"]
[Thu Sep 17 15:10:47.290801 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:56180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/"] [unique_id "aqxXVxFTPRVSLOsRVhokuwAAAS0"]
[Thu Sep 17 15:10:47.396995 2026] [security2:error] [pid 955873:tid 956028] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhokugAAASM"]
[Thu Sep 17 15:10:47.397023 2026] [security2:error] [pid 955873:tid 956028] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhokugAAASM"]
[Thu Sep 17 15:10:47.399559 2026] [security2:error] [pid 955873:tid 956052] [client 156.192.234.52:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVxFTPRVSLOsRVhokwwAAATs"]
[Thu Sep 17 15:10:47.399688 2026] [security2:error] [pid 955873:tid 956052] [client 156.192.234.52:60558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVxFTPRVSLOsRVhokwwAAATs"]
[Thu Sep 17 15:10:47.451205 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/"] [unique_id "aqxXVxFTPRVSLOsRVhokxQAAAVg"]
[Thu Sep 17 15:10:47.568034 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:47376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXVxFTPRVSLOsRVhokzgAAAV0"]
[Thu Sep 17 15:10:47.593010 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVxFTPRVSLOsRVhokzwAAAQs"]
[Thu Sep 17 15:10:47.839522 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0AAAAVA"]
[Thu Sep 17 15:10:47.839553 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0AAAAVA"]
[Thu Sep 17 15:10:47.922222 2026] [security2:error] [pid 955873:tid 956097] [client 45.18.242.176:44589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0wABaDA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=3&hideliu=1&limit=100&target=VOC_Company&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:10:47.986357 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0QAAAYQ"]
[Thu Sep 17 15:10:47.986382 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0QAAAYQ"]
[Thu Sep 17 15:10:48.119800 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok2wAAAXo"]
[Thu Sep 17 15:10:48.119833 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok2wAAAXo"]
[Thu Sep 17 15:10:48.126314 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/view.min.asset.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4QAAAYE"]
[Thu Sep 17 15:10:48.126416 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/view.min.asset.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4QAAAYE"]
[Thu Sep 17 15:10:48.181484 2026] [security2:error] [pid 955873:tid 956024] [client 115.244.164.14:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4gAAAR8"]
[Thu Sep 17 15:10:48.181584 2026] [security2:error] [pid 955873:tid 956024] [client 115.244.164.14:64718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4gAAAR8"]
[Thu Sep 17 15:10:48.215926 2026] [security2:error] [pid 955873:tid 956102] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0gAAAW0"]
[Thu Sep 17 15:10:48.305866 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXWBFTPRVSLOsRVhok5QAAAVE"]
[Thu Sep 17 15:10:48.413037 2026] [security2:error] [pid 955873:tid 956041] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok5AAAATA"]
[Thu Sep 17 15:10:48.413061 2026] [security2:error] [pid 955873:tid 956041] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok5AAAATA"]
[Thu Sep 17 15:10:48.415814 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/boot/"] [unique_id "aqxXWBFTPRVSLOsRVhok7QAAATo"]
[Thu Sep 17 15:10:48.573358 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/boot/index.js"] [unique_id "aqxXWBFTPRVSLOsRVhok9QAAASQ"]
[Thu Sep 17 15:10:48.736089 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok-AAAAX8"]
[Thu Sep 17 15:10:48.736126 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok-AAAAX8"]
[Thu Sep 17 15:10:48.852573 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/connectors/"] [unique_id "aqxXWBFTPRVSLOsRVhok_AAAAU4"]
[Thu Sep 17 15:10:48.999795 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/connectors/index.js"] [unique_id "aqxXWBFTPRVSLOsRVhok_wAAAYI"]
[Thu Sep 17 15:10:49.025142 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok_gAAAYU"]
[Thu Sep 17 15:10:49.025174 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok_gAAAYU"]
[Thu Sep 17 15:10:49.036407 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:47392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXWRFTPRVSLOsRVholBQAAASM"]
[Thu Sep 17 15:10:49.050057 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:49163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWRFTPRVSLOsRVholBgAAAWs"]
[Thu Sep 17 15:10:49.050802 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:49163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWRFTPRVSLOsRVholBgAAAWs"]
[Thu Sep 17 15:10:49.151735 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/content-types/"] [unique_id "aqxXWRFTPRVSLOsRVholCwAAAV4"]
[Thu Sep 17 15:10:49.318705 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholEAAAAXo"]
[Thu Sep 17 15:10:49.318741 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholEAAAAXo"]
[Thu Sep 17 15:10:49.351196 2026] [security2:error] [pid 955873:tid 956015] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok_QAAARY"]
[Thu Sep 17 15:10:49.443525 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/content-types/index.js"] [unique_id "aqxXWRFTPRVSLOsRVholEwAAAW4"]
[Thu Sep 17 15:10:49.624974 2026] [security2:error] [pid 955873:tid 956010] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholGAAAARE"]
[Thu Sep 17 15:10:49.624993 2026] [security2:error] [pid 955873:tid 956010] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholGAAAARE"]
[Thu Sep 17 15:10:49.664688 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/core-abilities/"] [unique_id "aqxXWRFTPRVSLOsRVholJAAAARw"]
[Thu Sep 17 15:10:49.765302 2026] [security2:error] [pid 955873:tid 956044] [client 35.244.43.255:47408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXWRFTPRVSLOsRVholJQAAATM"]
[Thu Sep 17 15:10:49.818607 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/core-abilities/index.js"] [unique_id "aqxXWRFTPRVSLOsRVholJgAAAVQ"]
[Thu Sep 17 15:10:49.951262 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholJwAAAVk"]
[Thu Sep 17 15:10:49.951298 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholJwAAAVk"]
[Thu Sep 17 15:10:50.022599 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/dashboard-init/"] [unique_id "aqxXWhFTPRVSLOsRVholLQAAAVc"]
[Thu Sep 17 15:10:50.177708 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/dashboard-init/index.js"] [unique_id "aqxXWhFTPRVSLOsRVholMAAAAWQ"]
[Thu Sep 17 15:10:50.227212 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholLwAAAXc"]
[Thu Sep 17 15:10:50.227243 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholLwAAAXc"]
[Thu Sep 17 15:10:50.265030 2026] [security2:error] [pid 955873:tid 956118] [client 74.7.230.38:37302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokrgABfR0"]
[Thu Sep 17 15:10:50.285461 2026] [security2:error] [pid 955873:tid 956083] [client 5.189.145.112:64219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxXWhFTPRVSLOsRVholMQAAAVo"], referer: binance.com
[Thu Sep 17 15:10:50.329316 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/edit-site-init/"] [unique_id "aqxXWhFTPRVSLOsRVholMgAAASw"]
[Thu Sep 17 15:10:50.457203 2026] [autoindex:error] [pid 955873:tid 956036] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:50.457760 2026] [security2:error] [pid 955873:tid 956036] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/images/"] [unique_id "aqxXWhFTPRVSLOsRVholMwAAASs"]
[Thu Sep 17 15:10:50.476811 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/edit-site-init/index.js"] [unique_id "aqxXWhFTPRVSLOsRVholNAAAAU4"]
[Thu Sep 17 15:10:50.488478 2026] [security2:error] [pid 955873:tid 956038] [client 35.244.43.255:47414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXWhFTPRVSLOsRVholNQAAAS0"]
[Thu Sep 17 15:10:50.628350 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity-router/"] [unique_id "aqxXWhFTPRVSLOsRVholOwAAAV0"]
[Thu Sep 17 15:10:50.640040 2026] [autoindex:error] [pid 955873:tid 956048] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:50.640580 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxXWhFTPRVSLOsRVholOgAAATc"]
[Thu Sep 17 15:10:50.779845 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity-router/index.js"] [unique_id "aqxXWhFTPRVSLOsRVholPgAAASM"]
[Thu Sep 17 15:10:50.822534 2026] [security2:error] [pid 955873:tid 956079] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholQAAAAVY"]
[Thu Sep 17 15:10:50.929243 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity/"] [unique_id "aqxXWhFTPRVSLOsRVholQQAAAWs"]
[Thu Sep 17 15:10:51.057311 2026] [security2:error] [pid 955873:tid 956050] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholOQAAATk"]
[Thu Sep 17 15:10:51.097143 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity/index.js"] [unique_id "aqxXWxFTPRVSLOsRVholRgAAAVA"]
[Thu Sep 17 15:10:51.135487 2026] [security2:error] [pid 955873:tid 956009] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholQwAAARA"]
[Thu Sep 17 15:10:51.135512 2026] [security2:error] [pid 955873:tid 956009] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholQwAAARA"]
[Thu Sep 17 15:10:51.219216 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXWxFTPRVSLOsRVholSQAAAXg"]
[Thu Sep 17 15:10:51.245629 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/latex-to-mathml/"] [unique_id "aqxXWxFTPRVSLOsRVholSgAAAYQ"]
[Thu Sep 17 15:10:51.247365 2026] [security2:error] [pid 955873:tid 956091] [client 66.248.203.10:19236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholPQAAAWI"], referer: https://sucuri.net
[Thu Sep 17 15:10:51.401037 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/latex-to-mathml/index.js"] [unique_id "aqxXWxFTPRVSLOsRVholTgAAAUo"]
[Thu Sep 17 15:10:51.530305 2026] [security2:error] [pid 955873:tid 956124] [client 74.7.244.7:58828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.alexandernovelist.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhokvwABgzo"]
[Thu Sep 17 15:10:51.554233 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/lazy-editor/"] [unique_id "aqxXWxFTPRVSLOsRVholVAAAAS8"]
[Thu Sep 17 15:10:51.744544 2026] [security2:error] [pid 955873:tid 956056] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholVwAAAT8"]
[Thu Sep 17 15:10:51.744575 2026] [security2:error] [pid 955873:tid 956056] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholVwAAAT8"]
[Thu Sep 17 15:10:51.747624 2026] [security2:error] [pid 955873:tid 956088] [client 192.175.54.146:48002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholWAAAAV8"]
[Thu Sep 17 15:10:51.756357 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/lazy-editor/index.js"] [unique_id "aqxXWxFTPRVSLOsRVholWQAAAR8"]
[Thu Sep 17 15:10:51.900631 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/registry.php"] [unique_id "aqxXWxFTPRVSLOsRVholWwAAAQo"]
[Thu Sep 17 15:10:51.900769 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/registry.php"] [unique_id "aqxXWxFTPRVSLOsRVholWwAAAQo"]
[Thu Sep 17 15:10:51.947513 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:47444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXWxFTPRVSLOsRVholXAAAAUg"]
[Thu Sep 17 15:10:52.179772 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/route/"] [unique_id "aqxXXBFTPRVSLOsRVholYgAAAUw"]
[Thu Sep 17 15:10:52.304091 2026] [security2:error] [pid 955873:tid 956019] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholYwAAARo"]
[Thu Sep 17 15:10:52.304119 2026] [security2:error] [pid 955873:tid 956019] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholYwAAARo"]
[Thu Sep 17 15:10:52.333404 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/route/index.js"] [unique_id "aqxXXBFTPRVSLOsRVholZwAAAQ4"]
[Thu Sep 17 15:10:52.435338 2026] [security2:error] [pid 955873:tid 956094] [client 206.81.7.52:36624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.timalba.com"] [uri "/.env"] [unique_id "aqxXXBFTPRVSLOsRVholaAAAAWU"]
[Thu Sep 17 15:10:52.476009 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/"] [unique_id "aqxXXBFTPRVSLOsRVholbAAAAYA"]
[Thu Sep 17 15:10:52.611972 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholbgAAAXY"]
[Thu Sep 17 15:10:52.611997 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholbgAAAXY"]
[Thu Sep 17 15:10:52.641339 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/"] [unique_id "aqxXXBFTPRVSLOsRVholcgAAAT0"]
[Thu Sep 17 15:10:52.700155 2026] [security2:error] [pid 955873:tid 956017] [client 35.244.43.255:47450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXXBFTPRVSLOsRVholdQAAARg"]
[Thu Sep 17 15:10:52.786045 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/wp-includes/js/dist/script-modules/"] [unique_id "aqxXXBFTPRVSLOsRVholdgAAASw"]
[Thu Sep 17 15:10:52.906462 2026] [security2:error] [pid 955873:tid 956020] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholaQAAARs"]
[Thu Sep 17 15:10:53.152410 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholeQAAAS0"]
[Thu Sep 17 15:10:53.152441 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholeQAAAS0"]
[Thu Sep 17 15:10:53.189812 2026] [security2:error] [pid 955873:tid 956085] [client 154.190.208.131:42238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXRFTPRVSLOsRVholfgAAAVw"]
[Thu Sep 17 15:10:53.189966 2026] [security2:error] [pid 955873:tid 956085] [client 154.190.208.131:42238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXRFTPRVSLOsRVholfgAAAVw"]
[Thu Sep 17 15:10:53.307343 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/loader.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholfwAAAQ0"]
[Thu Sep 17 15:10:53.307464 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/loader.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholfwAAAQ0"]
[Thu Sep 17 15:10:53.400448 2026] [security2:error] [pid 955873:tid 956036] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholeAAAASs"]
[Thu Sep 17 15:10:53.418123 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:47458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXXRFTPRVSLOsRVholgQAAAXM"]
[Thu Sep 17 15:10:53.419304 2026] [security2:error] [pid 955873:tid 956092] [client 162.241.226.11:17502] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXXRFTPRVSLOsRVholgAAAAWM"]
[Thu Sep 17 15:10:53.587171 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:51846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/worker.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholhQAAAUk"]
[Thu Sep 17 15:10:53.587325 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:51846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/worker.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholhQAAAUk"]
[Thu Sep 17 15:10:53.899933 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:51850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/"] [unique_id "aqxXXRFTPRVSLOsRVholiQAAAT4"]
[Thu Sep 17 15:10:54.078807 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/"] [unique_id "aqxXXhFTPRVSLOsRVholkQAAAUo"]
[Thu Sep 17 15:10:54.122247 2026] [security2:error] [pid 955873:tid 956091] [client 35.244.43.255:47474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXXhFTPRVSLOsRVhollAAAAWI"]
[Thu Sep 17 15:10:54.264918 2026] [security2:error] [pid 955873:tid 956068] [client 82.102.18.118:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholkwAAAUs"]
[Thu Sep 17 15:10:54.266640 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:51850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/wp-includes/js/dist/script-modules/"] [unique_id "aqxXXhFTPRVSLOsRVholmgAAAR4"]
[Thu Sep 17 15:10:54.558835 2026] [security2:error] [pid 955873:tid 956102] [client 105.154.201.209:40178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholnwABbQU"]
[Thu Sep 17 15:10:54.560540 2026] [security2:error] [pid 955873:tid 956126] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholkgAAAYU"]
[Thu Sep 17 15:10:54.620615 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholngAAAV8"]
[Thu Sep 17 15:10:54.620643 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholngAAAV8"]
[Thu Sep 17 15:10:54.760850 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/loader.min.asset.php"] [unique_id "aqxXXhFTPRVSLOsRVholqAAAAYY"]
[Thu Sep 17 15:10:54.760966 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:51850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/loader.min.asset.php"] [unique_id "aqxXXhFTPRVSLOsRVholqAAAAYY"]
[Thu Sep 17 15:10:54.834769 2026] [security2:error] [pid 955873:tid 956114] [client 35.244.43.255:45776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXXhFTPRVSLOsRVholqgAAAXk"]
[Thu Sep 17 15:10:55.061478 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/worker.min.asset.php"] [unique_id "aqxXXxFTPRVSLOsRVholsQAAAYA"]
[Thu Sep 17 15:10:55.061591 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/worker.min.asset.php"] [unique_id "aqxXXxFTPRVSLOsRVholsQAAAYA"]
[Thu Sep 17 15:10:55.091468 2026] [security2:error] [pid 955873:tid 956027] [client 82.102.18.118:57264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXXxFTPRVSLOsRVholswAAASI"]
[Thu Sep 17 15:10:55.091598 2026] [security2:error] [pid 955873:tid 956027] [client 82.102.18.118:57264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXXxFTPRVSLOsRVholswAAASI"]
[Thu Sep 17 15:10:55.372501 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/workflow/"] [unique_id "aqxXXxFTPRVSLOsRVholtwAAAVk"]
[Thu Sep 17 15:10:55.478299 2026] [security2:error] [pid 955873:tid 956030] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxXXxFTPRVSLOsRVholtgAAASU"]
[Thu Sep 17 15:10:55.530761 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/workflow/index.js"] [unique_id "aqxXXxFTPRVSLOsRVholvQAAAUE"]
[Thu Sep 17 15:10:55.576255 2026] [security2:error] [pid 955873:tid 956052] [client 35.244.43.255:45782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXXxFTPRVSLOsRVholvwAAATs"]
[Thu Sep 17 15:10:55.668923 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXxFTPRVSLOsRVholwgAAAQ0"]
[Thu Sep 17 15:10:55.669147 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:53962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXxFTPRVSLOsRVholwgAAAQ0"]
[Thu Sep 17 15:10:55.669948 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/vendor/"] [unique_id "aqxXXxFTPRVSLOsRVholwwAAASs"]
[Thu Sep 17 15:10:55.804602 2026] [security2:error] [pid 955873:tid 956086] [client 82.102.18.118:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxXXxFTPRVSLOsRVholwAAAAV0"]
[Thu Sep 17 15:10:55.845044 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/vendor/"] [unique_id "aqxXXxFTPRVSLOsRVholxgAAAVU"]
[Thu Sep 17 15:10:55.983949 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/vendor/wp-includes/js/dist/"] [unique_id "aqxXXxFTPRVSLOsRVholyAAAAV4"]
[Thu Sep 17 15:10:56.243783 2026] [security2:error] [pid 955873:tid 956072] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXXxFTPRVSLOsRVholxQAAAU8"]
[Thu Sep 17 15:10:56.280716 2026] [security2:error] [pid 955873:tid 956125] [client 35.244.43.255:45790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/core/phpinfo.php"] [unique_id "aqxXYBFTPRVSLOsRVholzwAAAYQ"]
[Thu Sep 17 15:10:56.332040 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVholzAAAAUo"]
[Thu Sep 17 15:10:56.332064 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVholzAAAAUo"]
[Thu Sep 17 15:10:56.348425 2026] [security2:error] [pid 955873:tid 956040] [client 179.214.126.150:7587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cherryfox.co.uk"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVhollwAAAS8"]
[Thu Sep 17 15:10:56.399289 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYBFTPRVSLOsRVhol0gAAAXU"]
[Thu Sep 17 15:10:56.399447 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:57030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYBFTPRVSLOsRVhol0gAAAXU"]
[Thu Sep 17 15:10:56.482188 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "aqxXYBFTPRVSLOsRVhol1AAAAXI"]
[Thu Sep 17 15:10:56.622332 2026] [security2:error] [pid 955873:tid 956042] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol2QAAATE"]
[Thu Sep 17 15:10:56.639534 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "aqxXYBFTPRVSLOsRVhol2gAAATE"]
[Thu Sep 17 15:10:56.779024 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/imgareaselect/wp-includes/js/"] [unique_id "aqxXYBFTPRVSLOsRVhol3gAAARk"]
[Thu Sep 17 15:10:56.825791 2026] [security2:error] [pid 955873:tid 956069] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol4AAAAUw"]
[Thu Sep 17 15:10:56.937747 2026] [security2:error] [pid 955873:tid 956088] [client 41.100.35.51:52290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol3wABXw8"]
[Thu Sep 17 15:10:57.004593 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:45804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxXYRFTPRVSLOsRVhol5wAAAXQ"]
[Thu Sep 17 15:10:57.016128 2026] [security2:error] [pid 955873:tid 956021] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/themes/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol5gAAARw"]
[Thu Sep 17 15:10:57.120255 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol4gAAAUY"]
[Thu Sep 17 15:10:57.120282 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol4gAAAUY"]
[Thu Sep 17 15:10:57.262972 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jcrop/"] [unique_id "aqxXYRFTPRVSLOsRVhol8AAAAXY"]
[Thu Sep 17 15:10:57.264527 2026] [autoindex:error] [pid 955873:tid 956022] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:57.265030 2026] [security2:error] [pid 955873:tid 956022] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/includes/"] [unique_id "aqxXYRFTPRVSLOsRVhol7QAAAR0"]
[Thu Sep 17 15:10:57.408219 2026] [security2:error] [pid 955873:tid 956099] [client 185.55.149.49:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhol8wAAAWo"]
[Thu Sep 17 15:10:57.408368 2026] [security2:error] [pid 955873:tid 956099] [client 185.55.149.49:51231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhol8wAAAWo"]
[Thu Sep 17 15:10:57.417730 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jcrop/"] [unique_id "aqxXYRFTPRVSLOsRVhol8gAAASQ"]
[Thu Sep 17 15:10:57.455618 2026] [security2:error] [pid 955873:tid 956118] [client 176.29.170.228:11356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "noanimalsaswaste.org"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholjgAAAX0"]
[Thu Sep 17 15:10:57.565292 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jcrop/wp-includes/js/"] [unique_id "aqxXYRFTPRVSLOsRVhol-gAAAYI"]
[Thu Sep 17 15:10:57.598364 2026] [security2:error] [pid 955873:tid 956003] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol9gAAAQo"]
[Thu Sep 17 15:10:57.635945 2026] [security2:error] [pid 955873:tid 956106] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol7wAAAXE"]
[Thu Sep 17 15:10:57.677030 2026] [security2:error] [pid 955873:tid 956058] [client 5.189.145.112:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_QAAAUE"], referer: binance.com
[Thu Sep 17 15:10:57.824859 2026] [security2:error] [pid 955873:tid 956037] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_wAAASw"]
[Thu Sep 17 15:10:57.911351 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_gAAAYc"]
[Thu Sep 17 15:10:57.911378 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_gAAAYc"]
[Thu Sep 17 15:10:57.935761 2026] [security2:error] [pid 955873:tid 956030] [client 156.192.234.52:61164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhomAgAAASU"]
[Thu Sep 17 15:10:57.937144 2026] [security2:error] [pid 955873:tid 956030] [client 156.192.234.52:61164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhomAgAAASU"]
[Thu Sep 17 15:10:57.939711 2026] [security2:error] [pid 955873:tid 956036] [client 82.102.18.118:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhomAAAAASs"]
[Thu Sep 17 15:10:58.060827 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/"] [unique_id "aqxXYhFTPRVSLOsRVhomCAAAAVU"]
[Thu Sep 17 15:10:58.144431 2026] [security2:error] [pid 955873:tid 956098] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomCQAAAWk"]
[Thu Sep 17 15:10:58.226035 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/"] [unique_id "aqxXYhFTPRVSLOsRVhomDAAAARM"]
[Thu Sep 17 15:10:58.364822 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/wp-includes/js/"] [unique_id "aqxXYhFTPRVSLOsRVhomFAAAAXU"]
[Thu Sep 17 15:10:58.454231 2026] [security2:error] [pid 955873:tid 956124] [client 82.102.18.118:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYhFTPRVSLOsRVhomHAAAAYM"]
[Thu Sep 17 15:10:58.454389 2026] [security2:error] [pid 955873:tid 956124] [client 82.102.18.118:57036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYhFTPRVSLOsRVhomHAAAAYM"]
[Thu Sep 17 15:10:58.468229 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomFQAAAU4"]
[Thu Sep 17 15:10:58.657687 2026] [autoindex:error] [pid 955873:tid 956008] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:58.658471 2026] [security2:error] [pid 955873:tid 956008] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxXYhFTPRVSLOsRVhomJAAAAQ8"]
[Thu Sep 17 15:10:58.702039 2026] [security2:error] [pid 955873:tid 956055] [client 115.244.164.14:65350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYhFTPRVSLOsRVhomJQAAAT4"]
[Thu Sep 17 15:10:58.702180 2026] [security2:error] [pid 955873:tid 956055] [client 115.244.164.14:65350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYhFTPRVSLOsRVhomJQAAAT4"]
[Thu Sep 17 15:10:58.733436 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomIAAAAYE"]
[Thu Sep 17 15:10:58.733465 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomIAAAAYE"]
[Thu Sep 17 15:10:58.786825 2026] [security2:error] [pid 955873:tid 956018] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomJgAAARk"]
[Thu Sep 17 15:10:58.858275 2026] [security2:error] [pid 955873:tid 956056] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomGwAAAT8"]
[Thu Sep 17 15:10:58.899936 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/ui/"] [unique_id "aqxXYhFTPRVSLOsRVhomKAAAARw"]
[Thu Sep 17 15:10:59.104145 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/ui/"] [unique_id "aqxXYxFTPRVSLOsRVhomMQAAAYA"]
[Thu Sep 17 15:10:59.112112 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomMAAAAWA"]
[Thu Sep 17 15:10:59.250493 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/ui/wp-includes/js/jquery/"] [unique_id "aqxXYxFTPRVSLOsRVhomNAAAAW8"]
[Thu Sep 17 15:10:59.435067 2026] [security2:error] [pid 955873:tid 956029] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomNQAAASQ"]
[Thu Sep 17 15:10:59.596438 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomNgAAAWU"]
[Thu Sep 17 15:10:59.596464 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomNgAAAWU"]
[Thu Sep 17 15:10:59.737043 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/"] [unique_id "aqxXYxFTPRVSLOsRVhomPwAAATs"]
[Thu Sep 17 15:10:59.772237 2026] [security2:error] [pid 955873:tid 956020] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomPQAAARs"]
[Thu Sep 17 15:10:59.903601 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/"] [unique_id "aqxXYxFTPRVSLOsRVhomQAAAATc"]
[Thu Sep 17 15:11:00.034292 2026] [security2:error] [pid 955873:tid 956031] [client 45.12.3.130:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vinoviaggio.com"] [uri "/images/images/cache.php"] [unique_id "aqxXZBFTPRVSLOsRVhomRAAAASY"]
[Thu Sep 17 15:11:00.039483 2026] [security2:error] [pid 955873:tid 956117] [client 186.105.232.15:49769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZBFTPRVSLOsRVhomRQAAAXw"]
[Thu Sep 17 15:11:00.039800 2026] [security2:error] [pid 955873:tid 956117] [client 186.105.232.15:49769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZBFTPRVSLOsRVhomRQAAAXw"]
[Thu Sep 17 15:11:00.045089 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/wp-includes/js/"] [unique_id "aqxXZBFTPRVSLOsRVhomRwAAAVo"]
[Thu Sep 17 15:11:00.090827 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomQwAAAYc"]
[Thu Sep 17 15:11:00.101507 2026] [security2:error] [pid 955873:tid 956058] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomPgAAAUE"]
[Thu Sep 17 15:11:00.418720 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSQAAAVU"]
[Thu Sep 17 15:11:00.418742 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSQAAAVU"]
[Thu Sep 17 15:11:00.421160 2026] [security2:error] [pid 955873:tid 956105] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSwAAAXA"]
[Thu Sep 17 15:11:00.558747 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/renderers/"] [unique_id "aqxXZBFTPRVSLOsRVhomUQAAAS8"]
[Thu Sep 17 15:11:00.625855 2026] [security2:error] [pid 955873:tid 956018] [client 3.82.141.143:30628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXZBFTPRVSLOsRVhomZwAAARk"]
[Thu Sep 17 15:11:00.626643 2026] [security2:error] [pid 955873:tid 956070] [client 3.82.141.143:30434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/config.php"] [unique_id "aqxXZBFTPRVSLOsRVhomaAAAAU0"]
[Thu Sep 17 15:11:00.630085 2026] [security2:error] [pid 955873:tid 956035] [client 3.82.141.143:30622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php"] [unique_id "aqxXZBFTPRVSLOsRVhomagAAASo"]
[Thu Sep 17 15:11:00.630681 2026] [security2:error] [pid 955873:tid 956042] [client 3.82.141.143:30644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php.old"] [unique_id "aqxXZBFTPRVSLOsRVhomawAAATE"]
[Thu Sep 17 15:11:00.633848 2026] [security2:error] [pid 955873:tid 956033] [client 3.82.141.143:30662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php~"] [unique_id "aqxXZBFTPRVSLOsRVhomcgAAASg"]
[Thu Sep 17 15:11:00.635550 2026] [security2:error] [pid 955873:tid 956062] [client 3.82.141.143:30650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php.save"] [unique_id "aqxXZBFTPRVSLOsRVhomeAAAAUU"]
[Thu Sep 17 15:11:00.739606 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/renderers/"] [unique_id "aqxXZBFTPRVSLOsRVhomfQAAAYA"]
[Thu Sep 17 15:11:00.745724 2026] [security2:error] [pid 955873:tid 956068] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomfAAAAUs"]
[Thu Sep 17 15:11:00.882883 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/renderers/wp-includes/js/mediaelement/"] [unique_id "aqxXZBFTPRVSLOsRVhomgAAAAX0"]
[Thu Sep 17 15:11:00.967637 2026] [security2:error] [pid 955873:tid 956014] [client 144.76.22.53:37344] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSgAAARU"]
[Thu Sep 17 15:11:01.092903 2026] [security2:error] [pid 955873:tid 956123] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomggAAAYI"]
[Thu Sep 17 15:11:01.272870 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhQAAASY"]
[Thu Sep 17 15:11:01.272894 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhQAAASY"]
[Thu Sep 17 15:11:01.291879 2026] [security2:error] [pid 955873:tid 956095] [client 104.28.198.244:23021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhwAAAWY"]
[Thu Sep 17 15:11:01.382002 2026] [security2:error] [pid 955873:tid 956080] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomfwAAAVc"]
[Thu Sep 17 15:11:01.419208 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/plupload/"] [unique_id "aqxXZRFTPRVSLOsRVhomkAAAAVU"]
[Thu Sep 17 15:11:01.442232 2026] [security2:error] [pid 955873:tid 956009] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhomiwAAARA"]
[Thu Sep 17 15:11:01.472422 2026] [security2:error] [pid 955873:tid 956095] [client 104.28.198.244:23021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhwAAAWY"]
[Thu Sep 17 15:11:01.588532 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/plupload/"] [unique_id "aqxXZRFTPRVSLOsRVhomlQAAAU0"]
[Thu Sep 17 15:11:01.623264 2026] [security2:error] [pid 955873:tid 956105] [client 114.119.156.134:64407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jumpplot.com"] [uri "/about-us"] [unique_id "aqxXZRFTPRVSLOsRVhommAAAAXA"], referer: https://jumpplot.com/about-us
[Thu Sep 17 15:11:01.738387 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/plupload/wp-includes/js/"] [unique_id "aqxXZRFTPRVSLOsRVhommgAAAUU"]
[Thu Sep 17 15:11:01.771688 2026] [security2:error] [pid 955873:tid 956035] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhommQAAASo"]
[Thu Sep 17 15:11:02.052780 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00493: SIGUSR1 received. Doing graceful restart
[Thu Sep 17 15:11:02.093311 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZhFTPRVSLOsRVhomnQAAAR0"]
[Thu Sep 17 15:11:02.177439 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhommwAAAUo"]
[Thu Sep 17 15:11:02.177470 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhommwAAAUo"]
[Thu Sep 17 15:11:03.197894 2026] [security2:error] [pid 955873:tid 956112] [client 47.79.201.54:14000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxXZhFTPRVSLOsRVhomngAAAXc"], referer: https://www.google.com/
[Thu Sep 17 15:11:03.200683 2026] [:notice] [pid 955834:tid 955834] [host root@box5305.bluehost.com] mod_lsapi: Selfstarter 955834 stopped
[Thu Sep 17 15:11:04.604465 2026] [security2:error] [pid 955873:tid 956096] [client 40.77.167.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.realdubrovnikexperience.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomOQAAAWc"]
[Thu Sep 17 15:11:05.868315 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi: version 1.1-92
[Thu Sep 17 15:11:05.873741 2026] [:notice] [pid 971056:tid 971056] [host root@box5305.bluehost.com] mod_lsapi: Selfstarter 971056 started
[Thu Sep 17 15:11:05.923070 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.930287 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.959368 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.961839 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.962414 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.966394 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.978727 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.989211 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.989795 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.990786 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.991365 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.991769 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.992574 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.022179 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.022575 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.023125 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.026052 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.041968 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.042322 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.057429 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.071517 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.093589 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.094075 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.094429 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.097049 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.099517 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.115063 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.116887 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.117384 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.117896 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.118369 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.118847 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.119338 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.119856 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.120217 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.140277 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.160495 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.161333 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.164327 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.179597 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.190426 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.201432 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.202031 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.205949 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.207436 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.216919 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.218937 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.227749 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.229893 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.238226 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.239748 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.242160 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.247284 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.254820 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.257283 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.261014 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.265435 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.266544 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.283080 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.294550 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.295435 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.296788 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.300112 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.312546 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.319283 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.320528 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.321516 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.322321 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.322732 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.323293 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.325809 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.340628 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.341533 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.398410 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.404093 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.404657 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.406603 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.445745 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.457730 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.483592 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.499156 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:11:06.754472 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:11:06.759318 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:11:06.759332 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:11:07.811323 2026] [http2:info] [pid 971102:tid 971102] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:11:07.832047 2026] [security2:error] [pid 971102:tid 971240] [client 5.189.145.112:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxXa-cL08BTTQixEnowbAAAAAY"], referer: binance.com
[Thu Sep 17 15:11:07.832855 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/swfupload/"] [unique_id "aqxXa-cL08BTTQixEnowagAAAAM"]
[Thu Sep 17 15:11:07.833717 2026] [security2:error] [pid 971102:tid 971246] [client 162.241.226.11:29432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alloracart.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxXa-cL08BTTQixEnowbgAAAAw"]
[Thu Sep 17 15:11:07.834793 2026] [security2:error] [pid 971102:tid 971254] [client 137.131.43.163:58903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milehighmuse.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxXa-cL08BTTQixEnowbwAAABQ"]
[Thu Sep 17 15:11:07.875445 2026] [security2:error] [pid 971102:tid 971274] [client 137.131.43.163:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "milehighmuse.com"] [uri "/xmlrpc.php"] [unique_id "aqxXa-cL08BTTQixEnoweQAAACg"]
[Thu Sep 17 15:11:07.880508 2026] [authz_core:error] [pid 971102:tid 971275] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:11:07.972061 2026] [security2:error] [pid 971102:tid 971262] [client 45.169.98.18:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXa-cL08BTTQixEnowiAAAABw"]
[Thu Sep 17 15:11:07.972210 2026] [security2:error] [pid 971102:tid 971262] [client 45.169.98.18:54513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXa-cL08BTTQixEnowiAAAABw"]
[Thu Sep 17 15:11:08.024224 2026] [security2:error] [pid 971102:tid 971253] [client 114.119.151.67:36623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenniferniesslein.com"] [uri "/feed"] [unique_id "aqxXbOcL08BTTQixEnowjgAAABM"], referer: https://jenniferniesslein.com/feed
[Thu Sep 17 15:11:08.067446 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env~"] [unique_id "aqxXbOcL08BTTQixEnowkQAAAB0"]
[Thu Sep 17 15:11:08.140867 2026] [security2:error] [pid 971102:tid 971283] [client 185.55.149.49:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowlgAAADE"]
[Thu Sep 17 15:11:08.140985 2026] [security2:error] [pid 971102:tid 971283] [client 185.55.149.49:51867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowlgAAADE"]
[Thu Sep 17 15:11:08.258448 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowmgAAAAg"]
[Thu Sep 17 15:11:08.258579 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:41546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowmgAAAAg"]
[Thu Sep 17 15:11:08.322101 2026] [security2:error] [pid 971102:tid 971105] [remote 57.141.14.47:45464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxXa-cL08BTTQixEnowcwAAIAE"]
[Thu Sep 17 15:11:08.455175 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/swfupload/"] [unique_id "aqxXbOcL08BTTQixEnowngAAAEU"]
[Thu Sep 17 15:11:08.531095 2026] [security2:error] [pid 971102:tid 971305] [client 156.192.234.52:61777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowowAAAEc"]
[Thu Sep 17 15:11:08.531245 2026] [security2:error] [pid 971102:tid 971305] [client 156.192.234.52:61777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowowAAAEc"]
[Thu Sep 17 15:11:08.600197 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/swfupload/wp-includes/js/"] [unique_id "aqxXbOcL08BTTQixEnowpAAAAGY"]
[Thu Sep 17 15:11:08.703901 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowlwAAAE0"]
[Thu Sep 17 15:11:08.752487 2026] [security2:error] [pid 971102:tid 971267] [client 47.79.200.222:61496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowpgAAACE"], referer: https://www.google.com/
[Thu Sep 17 15:11:09.103103 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowpwAAAGw"]
[Thu Sep 17 15:11:09.103131 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowpwAAAGw"]
[Thu Sep 17 15:11:09.312051 2026] [security2:error] [pid 971102:tid 971352] [client 115.244.164.14:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbecL08BTTQixEnowtgAAAHY"]
[Thu Sep 17 15:11:09.312210 2026] [security2:error] [pid 971102:tid 971352] [client 115.244.164.14:49606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbecL08BTTQixEnowtgAAAHY"]
[Thu Sep 17 15:11:09.420796 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/thickbox/"] [unique_id "aqxXbecL08BTTQixEnowugAAAAw"]
[Thu Sep 17 15:11:09.582317 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/thickbox/"] [unique_id "aqxXbecL08BTTQixEnowwAAAACg"]
[Thu Sep 17 15:11:09.728180 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/thickbox/wp-includes/js/"] [unique_id "aqxXbecL08BTTQixEnowwgAAADM"]
[Thu Sep 17 15:11:10.070102 2026] [security2:error] [pid 971102:tid 971275] [client 135.135.37.144:58147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXbecL08BTTQixEnowyQAAACk"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:11:10.091838 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbecL08BTTQixEnowxgAAAD0"]
[Thu Sep 17 15:11:10.091862 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbecL08BTTQixEnowxgAAAD0"]
[Thu Sep 17 15:11:10.240473 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/"] [unique_id "aqxXbucL08BTTQixEnowzAAAAEY"]
[Thu Sep 17 15:11:10.241839 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXbecL08BTTQixEnowxQAAADw"]
[Thu Sep 17 15:11:10.242751 2026] [security2:error] [pid 971102:tid 971259] [client 137.131.43.163:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "milehighmuse.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnowzQAAABk"]
[Thu Sep 17 15:11:10.242844 2026] [security2:error] [pid 971102:tid 971259] [client 137.131.43.163:51640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "milehighmuse.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnowzQAAABk"]
[Thu Sep 17 15:11:10.421432 2026] [security2:error] [pid 971102:tid 971300] [client 135.135.37.144:58147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXbucL08BTTQixEnowzwAAAEI"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:11:10.458881 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/"] [unique_id "aqxXbucL08BTTQixEnow0AAAADc"]
[Thu Sep 17 15:11:10.602501 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/wp-includes/js/"] [unique_id "aqxXbucL08BTTQixEnow0wAAAEo"]
[Thu Sep 17 15:11:10.886802 2026] [security2:error] [pid 971102:tid 971290] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env"] [unique_id "aqxXbucL08BTTQixEnow1QAAADg"]
[Thu Sep 17 15:11:10.935219 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbucL08BTTQixEnow1AAAAEs"]
[Thu Sep 17 15:11:10.935241 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbucL08BTTQixEnow1AAAAEs"]
[Thu Sep 17 15:11:10.989964 2026] [security2:error] [pid 971102:tid 971276] [client 104.28.198.244:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnow1wAAACo"]
[Thu Sep 17 15:11:10.990141 2026] [security2:error] [pid 971102:tid 971276] [client 104.28.198.244:22715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnow1wAAACo"]
[Thu Sep 17 15:11:11.048655 2026] [security2:error] [pid 971102:tid 971314] [client 162.241.226.11:29436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alloracart.com"] [uri "/wp-cron.php"] [unique_id "aqxXb-cL08BTTQixEnow2gAAAFA"]
[Thu Sep 17 15:11:11.059311 2026] [security2:error] [pid 971102:tid 971240] [client 186.105.232.15:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXb-cL08BTTQixEnow2QAAAAY"]
[Thu Sep 17 15:11:11.059440 2026] [security2:error] [pid 971102:tid 971240] [client 186.105.232.15:50358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXb-cL08BTTQixEnow2QAAAAY"]
[Thu Sep 17 15:11:11.080327 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "aqxXb-cL08BTTQixEnow3AAAAAg"]
[Thu Sep 17 15:11:11.180088 2026] [security2:error] [pid 971102:tid 971310] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXbucL08BTTQixEnow1gAAAEw"]
[Thu Sep 17 15:11:11.241316 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "aqxXb-cL08BTTQixEnow3gAAAFU"]
[Thu Sep 17 15:11:11.360701 2026] [security2:error] [pid 971102:tid 971327] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow3wAAAF0"]
[Thu Sep 17 15:11:11.384254 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/langs/wp-includes/js/tinymce/"] [unique_id "aqxXb-cL08BTTQixEnow4QAAAF4"]
[Thu Sep 17 15:11:11.533077 2026] [security2:error] [pid 971102:tid 971329] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4gAAAF8"]
[Thu Sep 17 15:11:11.712091 2026] [security2:error] [pid 971102:tid 971280] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow5AAAAC4"]
[Thu Sep 17 15:11:11.719317 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4AAAAFg"]
[Thu Sep 17 15:11:11.722474 2026] [security2:error] [pid 971102:tid 971331] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4wAAAGE"]
[Thu Sep 17 15:11:11.722487 2026] [security2:error] [pid 971102:tid 971331] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4wAAAGE"]
[Thu Sep 17 15:11:11.867355 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXb-cL08BTTQixEnow5wAAAGU"]
[Thu Sep 17 15:11:11.877715 2026] [security2:error] [pid 971102:tid 971293] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow5gAAADs"]
[Thu Sep 17 15:11:11.967091 2026] [security2:error] [pid 971102:tid 971336] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env.backup"] [unique_id "aqxXb-cL08BTTQixEnow6QAAAGY"]
[Thu Sep 17 15:11:12.007115 2026] [security2:error] [pid 971102:tid 971323] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env.bak"] [unique_id "aqxXcOcL08BTTQixEnow6gAAAFk"]
[Thu Sep 17 15:11:12.047577 2026] [security2:error] [pid 971102:tid 971321] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env.old"] [unique_id "aqxXcOcL08BTTQixEnow7AAAAFc"]
[Thu Sep 17 15:11:12.155130 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcOcL08BTTQixEnow6wAAAFs"]
[Thu Sep 17 15:11:12.191275 2026] [security2:error] [pid 971102:tid 971337] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXcOcL08BTTQixEnow7QAAAGc"]
[Thu Sep 17 15:11:12.267112 2026] [security2:error] [pid 971102:tid 971320] [client 144.172.93.238:13974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.93.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mindmappower.com"] [uri "/.env.php"] [unique_id "aqxXcOcL08BTTQixEnow7wAAAFY"]
[Thu Sep 17 15:11:12.297602 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wp-includes/js/tinymce/"] [unique_id "aqxXcOcL08BTTQixEnow8AAAAGg"]
[Thu Sep 17 15:11:12.629322 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcOcL08BTTQixEnow9AAAACY"]
[Thu Sep 17 15:11:12.629355 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcOcL08BTTQixEnow9AAAACY"]
[Thu Sep 17 15:11:12.759628 2026] [security2:error] [pid 971102:tid 971352] [client 144.172.93.238:1656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.93.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mindmappower.com"] [uri "/.env.php"] [unique_id "aqxXcOcL08BTTQixEnoxAQAAAHY"]
[Thu Sep 17 15:11:12.762830 2026] [authz_core:error] [pid 971102:tid 971250] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:11:12.770418 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/charmap/"] [unique_id "aqxXcOcL08BTTQixEnoxAgAAAA8"]
[Thu Sep 17 15:11:12.843578 2026] [security2:error] [pid 971102:tid 971265] [client 162.241.226.11:43206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alloracart.com"] [uri "/wp-cron.php"] [unique_id "aqxXcOcL08BTTQixEnoxAwAAAB8"]
[Thu Sep 17 15:11:12.940658 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/charmap/"] [unique_id "aqxXcOcL08BTTQixEnoxBgAAABs"]
[Thu Sep 17 15:11:13.120596 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/charmap/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcecL08BTTQixEnoxCAAAAHg"]
[Thu Sep 17 15:11:13.450462 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcecL08BTTQixEnoxDAAAAHQ"]
[Thu Sep 17 15:11:13.450486 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcecL08BTTQixEnoxDAAAAHQ"]
[Thu Sep 17 15:11:13.594170 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXcecL08BTTQixEnoxCwAAADI"]
[Thu Sep 17 15:11:13.594931 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/colorpicker/"] [unique_id "aqxXcecL08BTTQixEnoxEAAAAA0"]
[Thu Sep 17 15:11:13.982034 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/colorpicker/"] [unique_id "aqxXcecL08BTTQixEnoxFgAAAB4"]
[Thu Sep 17 15:11:14.138731 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/colorpicker/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcucL08BTTQixEnoxGgAAAAc"]
[Thu Sep 17 15:11:14.472124 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxGwAAAD8"]
[Thu Sep 17 15:11:14.472152 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxGwAAAD8"]
[Thu Sep 17 15:11:14.615626 2026] [security2:error] [pid 971102:tid 971278] [client 154.190.208.131:42174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXcucL08BTTQixEnoxIQAAACw"]
[Thu Sep 17 15:11:14.615742 2026] [security2:error] [pid 971102:tid 971278] [client 154.190.208.131:42174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXcucL08BTTQixEnoxIQAAACw"]
[Thu Sep 17 15:11:14.619955 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/"] [unique_id "aqxXcucL08BTTQixEnoxIgAAADQ"]
[Thu Sep 17 15:11:14.781527 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/"] [unique_id "aqxXcucL08BTTQixEnoxJQAAAEw"]
[Thu Sep 17 15:11:14.931258 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcucL08BTTQixEnoxJwAAAFU"]
[Thu Sep 17 15:11:15.015005 2026] [core:crit] [pid 971102:tid 971251] (13)Permission denied: [client 43.157.43.147:35982] AH00529: /home1/awesone8/public_html/comicsutra.com/cs/news/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/awesone8/public_html/comicsutra.com/cs/news/' is executable
[Thu Sep 17 15:11:15.080745 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxJAAAACA"]
[Thu Sep 17 15:11:15.091274 2026] [security2:error] [pid 971102:tid 971327] [client 200.26.224.146:47034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXcucL08BTTQixEnoxKQAAXRg"], referer: https://www.yahoo.com/
[Thu Sep 17 15:11:15.138053 2026] [security2:error] [pid 971102:tid 971329] [client 34.94.67.131:54016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXc-cL08BTTQixEnoxLwAAAF8"]
[Thu Sep 17 15:11:15.309349 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxLgAAAEc"]
[Thu Sep 17 15:11:15.309371 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxLgAAAEc"]
[Thu Sep 17 15:11:15.451320 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aqxXc-cL08BTTQixEnoxMgAAAGQ"]
[Thu Sep 17 15:11:15.610384 2026] [security2:error] [pid 971102:tid 971337] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aqxXc-cL08BTTQixEnoxNgAAAGc"]
[Thu Sep 17 15:11:15.645312 2026] [security2:error] [pid 971102:tid 971336] [client 34.94.67.131:54024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXc-cL08BTTQixEnoxOAAAAGY"]
[Thu Sep 17 15:11:15.735819 2026] [authz_core:error] [pid 971102:tid 971338] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:11:15.753457 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/wp-includes/js/tinymce/plugins/compat3x/"] [unique_id "aqxXc-cL08BTTQixEnoxPAAAAHE"]
[Thu Sep 17 15:11:15.813005 2026] [security2:error] [pid 971102:tid 971257] [client 5.189.145.112:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxXc-cL08BTTQixEnoxPgAAABc"], referer: binance.com
[Thu Sep 17 15:11:15.901964 2026] [security2:error] [pid 971102:tid 971358] [client 34.94.67.131:54040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXc-cL08BTTQixEnoxQQAAAHw"]
[Thu Sep 17 15:11:16.047252 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/app/.env"] [unique_id "aqxXdOcL08BTTQixEnoxRAAAAHk"]
[Thu Sep 17 15:11:16.100788 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxQgAAAHs"]
[Thu Sep 17 15:11:16.100812 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxQgAAAHs"]
[Thu Sep 17 15:11:16.245156 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/directionality/"] [unique_id "aqxXdOcL08BTTQixEnoxRQAAAAw"]
[Thu Sep 17 15:11:16.327574 2026] [security2:error] [pid 971102:tid 971274] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/apps/.env"] [unique_id "aqxXdOcL08BTTQixEnoxRgAAACg"]
[Thu Sep 17 15:11:16.402610 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/directionality/"] [unique_id "aqxXdOcL08BTTQixEnoxSQAAAC0"]
[Thu Sep 17 15:11:16.435565 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.67.131:54046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXdOcL08BTTQixEnoxTAAAAAA"]
[Thu Sep 17 15:11:16.531655 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/.env"] [unique_id "aqxXdOcL08BTTQixEnoxTgAAADk"]
[Thu Sep 17 15:11:16.550317 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/directionality/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXdOcL08BTTQixEnoxTwAAABw"]
[Thu Sep 17 15:11:16.651561 2026] [security2:error] [pid 971102:tid 971245] [client 45.169.98.18:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXdOcL08BTTQixEnoxUAAAAAs"]
[Thu Sep 17 15:11:16.653601 2026] [security2:error] [pid 971102:tid 971245] [client 45.169.98.18:55068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXdOcL08BTTQixEnoxUAAAAAs"]
[Thu Sep 17 15:11:16.805288 2026] [security2:error] [pid 971102:tid 971254] [client 200.26.224.146:47044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXdOcL08BTTQixEnoxVAAAFB4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821112553&hidebots=0&hideliu=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:11:16.907407 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdOcL08BTTQixEnoxUgAAABY"]
[Thu Sep 17 15:11:16.907430 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdOcL08BTTQixEnoxUgAAABY"]
[Thu Sep 17 15:11:17.023929 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/web/.env"] [unique_id "aqxXdecL08BTTQixEnoxXwAAAEA"]
[Thu Sep 17 15:11:17.123823 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/"] [unique_id "aqxXdecL08BTTQixEnoxYQAAAEs"]
[Thu Sep 17 15:11:17.248995 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/site/.env"] [unique_id "aqxXdecL08BTTQixEnoxZAAAAE8"]
[Thu Sep 17 15:11:17.284194 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/"] [unique_id "aqxXdecL08BTTQixEnoxZQAAAFA"]
[Thu Sep 17 15:11:17.336775 2026] [security2:error] [pid 971102:tid 971259] [client 104.234.32.52:28651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "clarkcountyclothing.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxIwAAABk"]
[Thu Sep 17 15:11:17.480356 2026] [security2:error] [pid 971102:tid 971318] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXdecL08BTTQixEnoxawAAAFQ"]
[Thu Sep 17 15:11:17.562846 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/public/.env"] [unique_id "aqxXdecL08BTTQixEnoxbwAAABE"]
[Thu Sep 17 15:11:17.845737 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdecL08BTTQixEnoxcQAAAF0"]
[Thu Sep 17 15:11:17.845761 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdecL08BTTQixEnoxcQAAAF0"]
[Thu Sep 17 15:11:17.987000 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/hr/"] [unique_id "aqxXdecL08BTTQixEnoxewAAABU"]
[Thu Sep 17 15:11:18.150452 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/hr/"] [unique_id "aqxXducL08BTTQixEnoxfQAAAHA"]
[Thu Sep 17 15:11:18.176919 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXdecL08BTTQixEnoxcwAAADY"]
[Thu Sep 17 15:11:18.302037 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/hr/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXducL08BTTQixEnoxgAAAAFs"]
[Thu Sep 17 15:11:18.609340 2026] [security2:error] [pid 971102:tid 971140] [remote 162.241.226.11:0] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1441"] [id "9009999"] [msg "8 char spam"] [hostname "playify.work"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aqxXducL08BTTQixEnoxiAAAISQ"]
[Thu Sep 17 15:11:18.630919 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXducL08BTTQixEnoxhQAAAE0"]
[Thu Sep 17 15:11:18.630939 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXducL08BTTQixEnoxhQAAAE0"]
[Thu Sep 17 15:11:18.777712 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/image/"] [unique_id "aqxXducL08BTTQixEnoxjwAAAAM"]
[Thu Sep 17 15:11:18.889234 2026] [security2:error] [pid 971102:tid 971289] [client 185.55.149.49:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXducL08BTTQixEnoxkAAAADc"]
[Thu Sep 17 15:11:18.889323 2026] [security2:error] [pid 971102:tid 971289] [client 185.55.149.49:52494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXducL08BTTQixEnoxkAAAADc"]
[Thu Sep 17 15:11:18.931072 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/image/"] [unique_id "aqxXducL08BTTQixEnoxlAAAACc"]
[Thu Sep 17 15:11:19.018566 2026] [security2:error] [pid 971102:tid 971274] [client 192.178.6.5:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxXd-cL08BTTQixEnoxlwAAACg"]
[Thu Sep 17 15:11:19.074364 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/image/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXd-cL08BTTQixEnoxmgAAAHc"]
[Thu Sep 17 15:11:19.139854 2026] [security2:error] [pid 971102:tid 971344] [client 156.192.234.52:62361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxmwAAAG4"]
[Thu Sep 17 15:11:19.139972 2026] [security2:error] [pid 971102:tid 971344] [client 156.192.234.52:62361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxmwAAAG4"]
[Thu Sep 17 15:11:19.163474 2026] [security2:error] [pid 971102:tid 971349] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/backend/.env"] [unique_id "aqxXd-cL08BTTQixEnoxnAAAAHM"]
[Thu Sep 17 15:11:19.402505 2026] [security2:error] [pid 971102:tid 971350] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/server/.env"] [unique_id "aqxXd-cL08BTTQixEnoxpQAAAHQ"]
[Thu Sep 17 15:11:19.408500 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxnwAAAAs"]
[Thu Sep 17 15:11:19.408519 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxnwAAAAs"]
[Thu Sep 17 15:11:19.552043 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/link/"] [unique_id "aqxXd-cL08BTTQixEnoxrwAAAEk"]
[Thu Sep 17 15:11:19.553826 2026] [authz_core:error] [pid 971102:tid 971294] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:11:19.593963 2026] [security2:error] [pid 971102:tid 971339] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/frontend/.env"] [unique_id "aqxXd-cL08BTTQixEnoxsQAAAGk"]
[Thu Sep 17 15:11:19.708364 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/link/"] [unique_id "aqxXd-cL08BTTQixEnoxtAAAADU"]
[Thu Sep 17 15:11:19.850432 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/link/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXd-cL08BTTQixEnoxtwAAAFA"]
[Thu Sep 17 15:11:19.872702 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxuAAAAB4"]
[Thu Sep 17 15:11:19.872783 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxuAAAAB4"]
[Thu Sep 17 15:11:20.028471 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/src/.env"] [unique_id "aqxXeOcL08BTTQixEnoxvgAAAH0"]
[Thu Sep 17 15:11:20.194042 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxvQAAACo"]
[Thu Sep 17 15:11:20.194067 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxvQAAACo"]
[Thu Sep 17 15:11:20.234210 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/core/.env"] [unique_id "aqxXeOcL08BTTQixEnoxxAAAACU"]
[Thu Sep 17 15:11:20.338517 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/lists/"] [unique_id "aqxXeOcL08BTTQixEnoxxwAAAAk"]
[Thu Sep 17 15:11:20.403928 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/core/app/.env"] [unique_id "aqxXeOcL08BTTQixEnoxygAAAEc"]
[Thu Sep 17 15:11:20.493896 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/lists/"] [unique_id "aqxXeOcL08BTTQixEnoxzgAAAGQ"]
[Thu Sep 17 15:11:20.625161 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/config/.env"] [unique_id "aqxXeOcL08BTTQixEnox0AAAADs"]
[Thu Sep 17 15:11:20.637994 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/lists/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXeOcL08BTTQixEnox0QAAAFE"]
[Thu Sep 17 15:11:20.850883 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/private/.env"] [unique_id "aqxXeOcL08BTTQixEnox2QAAAFg"]
[Thu Sep 17 15:11:20.995385 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeOcL08BTTQixEnox1AAAAGg"]
[Thu Sep 17 15:11:20.995418 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeOcL08BTTQixEnox1AAAAGg"]
[Thu Sep 17 15:11:21.107598 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/application/.env"] [unique_id "aqxXeecL08BTTQixEnox3wAAAEY"]
[Thu Sep 17 15:11:21.137493 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/media/"] [unique_id "aqxXeecL08BTTQixEnox4QAAAHw"]
[Thu Sep 17 15:11:21.312912 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/media/"] [unique_id "aqxXeecL08BTTQixEnox5QAAAEI"]
[Thu Sep 17 15:11:21.354998 2026] [security2:error] [pid 971102:tid 971299] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/bootstrap/.env"] [unique_id "aqxXeecL08BTTQixEnox5wAAAEE"]
[Thu Sep 17 15:11:21.456193 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/media/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXeecL08BTTQixEnox7QAAABs"]
[Thu Sep 17 15:11:21.571387 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/database/.env"] [unique_id "aqxXeecL08BTTQixEnox7wAAAHc"]
[Thu Sep 17 15:11:21.753404 2026] [security2:error] [pid 971102:tid 971250] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/storage/.env"] [unique_id "aqxXeecL08BTTQixEnox9AAAABA"]
[Thu Sep 17 15:11:21.819434 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeecL08BTTQixEnox8QAAAG4"]
[Thu Sep 17 15:11:21.819461 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeecL08BTTQixEnox8QAAAG4"]
[Thu Sep 17 15:11:21.939926 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/var/www/.env"] [unique_id "aqxXeecL08BTTQixEnox9wAAAA0"]
[Thu Sep 17 15:11:21.961632 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/paste/"] [unique_id "aqxXeecL08BTTQixEnox-QAAAHQ"]
[Thu Sep 17 15:11:22.088722 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXeucL08BTTQixEnox_QAAAH8"]
[Thu Sep 17 15:11:22.088822 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:50941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXeucL08BTTQixEnox_QAAAH8"]
[Thu Sep 17 15:11:22.122175 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/paste/"] [unique_id "aqxXeucL08BTTQixEnox_gAAACM"]
[Thu Sep 17 15:11:22.141127 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/var/www/html/.env"] [unique_id "aqxXeucL08BTTQixEnox_wAAAEk"]
[Thu Sep 17 15:11:22.266017 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/paste/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXeucL08BTTQixEnoyAgAAAGk"]
[Thu Sep 17 15:11:22.511069 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/current/.env"] [unique_id "aqxXeucL08BTTQixEnoyCQAAAFA"]
[Thu Sep 17 15:11:22.542606 2026] [security2:error] [pid 971102:tid 971259] [client 138.68.188.115:59236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfdub.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXeucL08BTTQixEnoyCwAAABk"]
[Thu Sep 17 15:11:22.602044 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeucL08BTTQixEnoyBQAAAAI"]
[Thu Sep 17 15:11:22.602064 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeucL08BTTQixEnoyBQAAAAI"]
[Thu Sep 17 15:11:22.711893 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/release/.env"] [unique_id "aqxXeucL08BTTQixEnoyEAAAAAg"]
[Thu Sep 17 15:11:22.743393 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/tabfocus/"] [unique_id "aqxXeucL08BTTQixEnoyEgAAABE"]
[Thu Sep 17 15:11:22.846992 2026] [security2:error] [pid 971102:tid 971329] [client 138.68.188.115:59239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfdub.com"] [uri "/"] [unique_id "aqxXeucL08BTTQixEnoyEwAAAF8"]
[Thu Sep 17 15:11:22.898178 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/tabfocus/"] [unique_id "aqxXeucL08BTTQixEnoyFQAAAGI"]
[Thu Sep 17 15:11:23.042712 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/tabfocus/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXe-cL08BTTQixEnoyGQAAAEc"]
[Thu Sep 17 15:11:23.138588 2026] [security2:error] [pid 971102:tid 971335] [client 138.68.188.115:59242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfdub.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXe-cL08BTTQixEnoyGwAAAGU"]
[Thu Sep 17 15:11:23.161886 2026] [security2:error] [pid 971102:tid 971312] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/releases/.env"] [unique_id "aqxXe-cL08BTTQixEnoyHAAAAE4"]
[Thu Sep 17 15:11:23.378804 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyHQAAAGQ"]
[Thu Sep 17 15:11:23.378828 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyHQAAAGQ"]
[Thu Sep 17 15:11:23.484007 2026] [security2:error] [pid 971102:tid 971243] [client 195.2.84.198:56372] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.84.198" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kopecdental.com"] [uri "/wp-comments-post.php"] [unique_id "aqxXe-cL08BTTQixEnoyJQAAAAk"], referer: https://kopecdental.com/2015/04/11/april-is-national-oral-health-month/
[Thu Sep 17 15:11:23.484169 2026] [security2:error] [pid 971102:tid 971243] [client 195.2.84.198:56372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kopecdental.com"] [uri "/wp-comments-post.php"] [unique_id "aqxXe-cL08BTTQixEnoyJQAAAAk"], referer: https://kopecdental.com/2015/04/11/april-is-national-oral-health-month/
[Thu Sep 17 15:11:23.524122 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/textcolor/"] [unique_id "aqxXe-cL08BTTQixEnoyJgAAABg"]
[Thu Sep 17 15:11:23.530926 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/shared/.env"] [unique_id "aqxXe-cL08BTTQixEnoyJwAAAG8"]
[Thu Sep 17 15:11:23.587354 2026] [security2:error] [pid 971102:tid 971341] [client 5.189.145.112:60978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxXe-cL08BTTQixEnoyKAAAAGs"], referer: binance.com
[Thu Sep 17 15:11:23.671416 2026] [security2:error] [pid 971102:tid 971304] [client 4.240.114.86:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxXe-cL08BTTQixEnoyKwAAAEY"], referer: binance.com
[Thu Sep 17 15:11:23.682537 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/textcolor/"] [unique_id "aqxXe-cL08BTTQixEnoyKgAAAGg"]
[Thu Sep 17 15:11:23.756394 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/deploy/.env"] [unique_id "aqxXe-cL08BTTQixEnoyLgAAAHE"]
[Thu Sep 17 15:11:23.823596 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/textcolor/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXe-cL08BTTQixEnoyMAAAAA8"]
[Thu Sep 17 15:11:23.937511 2026] [security2:error] [pid 971102:tid 971324] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/build/.env"] [unique_id "aqxXe-cL08BTTQixEnoyNAAAAFo"]
[Thu Sep 17 15:11:24.143291 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/dist/.env"] [unique_id "aqxXfOcL08BTTQixEnoyOwAAAEg"]
[Thu Sep 17 15:11:24.151451 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyNQAAAAM"]
[Thu Sep 17 15:11:24.151479 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyNQAAAAM"]
[Thu Sep 17 15:11:24.321487 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wordpress/"] [unique_id "aqxXfOcL08BTTQixEnoyPwAAAHs"]
[Thu Sep 17 15:11:24.361343 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/public_html/.env"] [unique_id "aqxXfOcL08BTTQixEnoyQgAAAAw"]
[Thu Sep 17 15:11:24.488226 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wordpress/"] [unique_id "aqxXfOcL08BTTQixEnoyRwAAADI"]
[Thu Sep 17 15:11:24.602250 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/htdocs/.env"] [unique_id "aqxXfOcL08BTTQixEnoySwAAAEk"]
[Thu Sep 17 15:11:24.630284 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wordpress/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXfOcL08BTTQixEnoyTwAAABM"]
[Thu Sep 17 15:11:24.935751 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/www/.env"] [unique_id "aqxXfOcL08BTTQixEnoyVwAAABo"]
[Thu Sep 17 15:11:24.988323 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfOcL08BTTQixEnoyUwAAADE"]
[Thu Sep 17 15:11:24.988350 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfOcL08BTTQixEnoyUwAAADE"]
[Thu Sep 17 15:11:25.129227 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpautoresize/"] [unique_id "aqxXfecL08BTTQixEnoyXAAAAEs"]
[Thu Sep 17 15:11:25.154774 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/html/.env"] [unique_id "aqxXfecL08BTTQixEnoyXQAAABE"]
[Thu Sep 17 15:11:25.166312 2026] [security2:error] [pid 971102:tid 971275] [client 154.190.208.131:41459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXfecL08BTTQixEnoyXgAAACk"]
[Thu Sep 17 15:11:25.166385 2026] [security2:error] [pid 971102:tid 971275] [client 154.190.208.131:41459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXfecL08BTTQixEnoyXgAAACk"]
[Thu Sep 17 15:11:25.289569 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpautoresize/"] [unique_id "aqxXfecL08BTTQixEnoyYAAAAF8"]
[Thu Sep 17 15:11:25.432603 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpautoresize/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXfecL08BTTQixEnoyZQAAAEc"]
[Thu Sep 17 15:11:25.441907 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/live/.env"] [unique_id "aqxXfecL08BTTQixEnoyZgAAADM"]
[Thu Sep 17 15:11:25.619468 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/prod/.env"] [unique_id "aqxXfecL08BTTQixEnoyagAAACA"]
[Thu Sep 17 15:11:25.765862 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfecL08BTTQixEnoyZwAAAE4"]
[Thu Sep 17 15:11:25.765886 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfecL08BTTQixEnoyZwAAAE4"]
[Thu Sep 17 15:11:25.806637 2026] [security2:error] [pid 971102:tid 971258] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/dev/.env"] [unique_id "aqxXfecL08BTTQixEnoybAAAABg"]
[Thu Sep 17 15:11:25.926615 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpdialogs/"] [unique_id "aqxXfecL08BTTQixEnoycAAAAFg"]
[Thu Sep 17 15:11:26.088116 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpdialogs/"] [unique_id "aqxXfucL08BTTQixEnoycgAAADs"]
[Thu Sep 17 15:11:26.201916 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/staging/.env"] [unique_id "aqxXfucL08BTTQixEnoydQAAAFs"]
[Thu Sep 17 15:11:26.229087 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpdialogs/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXfucL08BTTQixEnoydgAAAFc"]
[Thu Sep 17 15:11:26.495857 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/opt/.env"] [unique_id "aqxXfucL08BTTQixEnoyfQAAAHk"]
[Thu Sep 17 15:11:26.564143 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfucL08BTTQixEnoyeQAAAHw"]
[Thu Sep 17 15:11:26.564163 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfucL08BTTQixEnoyeQAAAHw"]
[Thu Sep 17 15:11:26.658815 2026] [security2:error] [pid 971102:tid 971299] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/laravel/.env"] [unique_id "aqxXfucL08BTTQixEnoygAAAAEE"]
[Thu Sep 17 15:11:26.726160 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/"] [unique_id "aqxXfucL08BTTQixEnoygQAAACc"]
[Thu Sep 17 15:11:26.848240 2026] [security2:error] [pid 971102:tid 971315] [client 49.51.196.42:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.196.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mycarydentist.com"] [uri "/index.php"] [unique_id "aqxXfucL08BTTQixEnoygwAAAFE"]
[Thu Sep 17 15:11:26.882233 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/"] [unique_id "aqxXfucL08BTTQixEnoyhAAAABc"]
[Thu Sep 17 15:11:27.025894 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXf-cL08BTTQixEnoyigAAAAw"]
[Thu Sep 17 15:11:27.117304 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/symfony/.env"] [unique_id "aqxXf-cL08BTTQixEnoyjQAAAH0"]
[Thu Sep 17 15:11:27.148461 2026] [security2:error] [pid 971102:tid 971357] [client 45.169.98.18:55627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXf-cL08BTTQixEnoyjgAAAHs"]
[Thu Sep 17 15:11:27.148575 2026] [security2:error] [pid 971102:tid 971357] [client 45.169.98.18:55627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXf-cL08BTTQixEnoyjgAAAHs"]
[Thu Sep 17 15:11:27.359626 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoyjwAAABw"]
[Thu Sep 17 15:11:27.359655 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoyjwAAABw"]
[Thu Sep 17 15:11:27.375395 2026] [fcgid:warn] [pid 971102:tid 971344] (70014)End of file found: [client 106.63.26.7:16959] mod_fcgid: can't get data from http client
[Thu Sep 17 15:11:27.411815 2026] [security2:error] [pid 971102:tid 971238] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/wordpress/.env"] [unique_id "aqxXf-cL08BTTQixEnoylQAAAAQ"]
[Thu Sep 17 15:11:27.508211 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpemoji/"] [unique_id "aqxXf-cL08BTTQixEnoymQAAACM"]
[Thu Sep 17 15:11:27.576236 2026] [security2:error] [pid 971102:tid 971279] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/wp/.env"] [unique_id "aqxXf-cL08BTTQixEnoymgAAAC0"]
[Thu Sep 17 15:11:27.663161 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpemoji/"] [unique_id "aqxXf-cL08BTTQixEnoynAAAADw"]
[Thu Sep 17 15:11:27.799413 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cms/.env"] [unique_id "aqxXf-cL08BTTQixEnoyngAAAAs"]
[Thu Sep 17 15:11:27.807682 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpemoji/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXf-cL08BTTQixEnoynwAAACQ"]
[Thu Sep 17 15:11:27.936981 2026] [security2:error] [pid 971102:tid 971308] [client 4.240.114.86:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxXf-cL08BTTQixEnoypQAAAEo"], referer: binance.com
[Thu Sep 17 15:11:28.092867 2026] [security2:error] [pid 971102:tid 971339] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/drupal/.env"] [unique_id "aqxXgOcL08BTTQixEnoyrQAAAGk"]
[Thu Sep 17 15:11:28.160257 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoypwAAAE8"]
[Thu Sep 17 15:11:28.160284 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoypwAAAE8"]
[Thu Sep 17 15:11:28.304009 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpgallery/"] [unique_id "aqxXgOcL08BTTQixEnoysQAAADU"]
[Thu Sep 17 15:11:28.305779 2026] [security2:error] [pid 971102:tid 971287] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/joomla/.env"] [unique_id "aqxXgOcL08BTTQixEnoysgAAADU"]
[Thu Sep 17 15:11:28.322888 2026] [security2:error] [pid 971102:tid 971314] [client 52.167.144.170:27320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxXgOcL08BTTQixEnoyqQAAUEA"]
[Thu Sep 17 15:11:28.465196 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpgallery/"] [unique_id "aqxXgOcL08BTTQixEnoyuAAAAEc"]
[Thu Sep 17 15:11:28.532185 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/magento/.env"] [unique_id "aqxXgOcL08BTTQixEnoyuQAAADM"]
[Thu Sep 17 15:11:28.627401 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpgallery/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgOcL08BTTQixEnoyuwAAACw"]
[Thu Sep 17 15:11:28.747762 2026] [security2:error] [pid 971102:tid 971337] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/shopify/.env"] [unique_id "aqxXgOcL08BTTQixEnoyvgAAAGc"]
[Thu Sep 17 15:11:28.810249 2026] [security2:error] [pid 971102:tid 971334] [client 198.211.117.118:52610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgOcL08BTTQixEnoywQAAAGQ"]
[Thu Sep 17 15:11:28.950894 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgOcL08BTTQixEnoyvwAAAA4"]
[Thu Sep 17 15:11:28.950917 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgOcL08BTTQixEnoyvwAAAA4"]
[Thu Sep 17 15:11:29.009610 2026] [security2:error] [pid 971102:tid 971320] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/prestashop/.env"] [unique_id "aqxXgecL08BTTQixEnoyygAAAFY"]
[Thu Sep 17 15:11:29.031319 2026] [security2:error] [pid 971102:tid 971322] [client 198.211.117.118:52624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoyzAAAAFg"]
[Thu Sep 17 15:11:29.092221 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wplink/"] [unique_id "aqxXgecL08BTTQixEnoyzgAAAEY"]
[Thu Sep 17 15:11:29.253508 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wplink/"] [unique_id "aqxXgecL08BTTQixEnoy0AAAAHA"]
[Thu Sep 17 15:11:29.260061 2026] [security2:error] [pid 971102:tid 971340] [client 198.211.117.118:52640] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy0QAAAGo"]
[Thu Sep 17 15:11:29.260312 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/codeigniter/.env"] [unique_id "aqxXgecL08BTTQixEnoy0gAAAHE"]
[Thu Sep 17 15:11:29.407629 2026] [security2:error] [pid 971102:tid 971261] [client 185.117.225.169:33542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "www.idautovic.com"] [uri "/robots.txt"] [unique_id "aqxXgecL08BTTQixEnoy1AAAABs"]
[Thu Sep 17 15:11:29.426006 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wplink/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgecL08BTTQixEnoy1wAAAEg"]
[Thu Sep 17 15:11:29.481396 2026] [security2:error] [pid 971102:tid 971295] [client 198.211.117.118:52644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy2wAAAD0"]
[Thu Sep 17 15:11:29.555995 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cakephp/.env"] [unique_id "aqxXgecL08BTTQixEnoy3AAAAAA"]
[Thu Sep 17 15:11:29.594413 2026] [security2:error] [pid 971102:tid 971311] [client 185.55.149.49:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy3wAAAE0"]
[Thu Sep 17 15:11:29.594516 2026] [security2:error] [pid 971102:tid 971311] [client 185.55.149.49:59605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy3wAAAE0"]
[Thu Sep 17 15:11:29.644700 2026] [security2:error] [pid 971102:tid 971355] [client 156.192.234.52:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy4AAAAHk"]
[Thu Sep 17 15:11:29.646154 2026] [security2:error] [pid 971102:tid 971355] [client 156.192.234.52:62961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy4AAAAHk"]
[Thu Sep 17 15:11:29.690673 2026] [security2:error] [pid 971102:tid 971357] [client 198.211.117.118:52648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy4QAAAHs"]
[Thu Sep 17 15:11:29.744972 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgecL08BTTQixEnoy3QAAADk"]
[Thu Sep 17 15:11:29.744991 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgecL08BTTQixEnoy3QAAADk"]
[Thu Sep 17 15:11:29.783780 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/zend/.env"] [unique_id "aqxXgecL08BTTQixEnoy4gAAAHc"]
[Thu Sep 17 15:11:29.886949 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/"] [unique_id "aqxXgecL08BTTQixEnoy5wAAAC0"]
[Thu Sep 17 15:11:29.916739 2026] [security2:error] [pid 971102:tid 971344] [client 198.211.117.118:52658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy6gAAAG4"]
[Thu Sep 17 15:11:29.996738 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/yii/.env"] [unique_id "aqxXgecL08BTTQixEnoy7gAAAAo"]
[Thu Sep 17 15:11:30.045719 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/"] [unique_id "aqxXgucL08BTTQixEnoy8AAAAAs"]
[Thu Sep 17 15:11:30.188618 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgucL08BTTQixEnoy8wAAAH4"]
[Thu Sep 17 15:11:30.212178 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/laravel5/.env"] [unique_id "aqxXgucL08BTTQixEnoy9AAAABI"]
[Thu Sep 17 15:11:30.391054 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/v1/.env"] [unique_id "aqxXgucL08BTTQixEnoy_gAAAA0"]
[Thu Sep 17 15:11:30.465132 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgucL08BTTQixEnozAAAAAB4"]
[Thu Sep 17 15:11:30.465258 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgucL08BTTQixEnozAAAAAB4"]
[Thu Sep 17 15:11:30.528387 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgucL08BTTQixEnoy-gAAADg"]
[Thu Sep 17 15:11:30.528408 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgucL08BTTQixEnoy-gAAADg"]
[Thu Sep 17 15:11:30.567633 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/v2/.env"] [unique_id "aqxXgucL08BTTQixEnozAgAAAFI"]
[Thu Sep 17 15:11:30.675805 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/"] [unique_id "aqxXgucL08BTTQixEnozBQAAABM"]
[Thu Sep 17 15:11:30.809231 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/v3/.env"] [unique_id "aqxXgucL08BTTQixEnozCAAAAFA"]
[Thu Sep 17 15:11:30.843916 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/"] [unique_id "aqxXgucL08BTTQixEnozCQAAAEc"]
[Thu Sep 17 15:11:30.986822 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgucL08BTTQixEnozEwAAACw"]
[Thu Sep 17 15:11:31.010210 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/v1/.env"] [unique_id "aqxXg-cL08BTTQixEnozFAAAAGY"]
[Thu Sep 17 15:11:31.187837 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/v2/.env"] [unique_id "aqxXg-cL08BTTQixEnozGQAAAA4"]
[Thu Sep 17 15:11:31.318897 2026] [security2:error] [pid 971102:tid 971342] [client 5.189.145.112:62156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxXg-cL08BTTQixEnozHAAAAGw"], referer: binance.com
[Thu Sep 17 15:11:31.335128 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozFwAAAGQ"]
[Thu Sep 17 15:11:31.335149 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozFwAAAGQ"]
[Thu Sep 17 15:11:31.350254 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/rest/.env"] [unique_id "aqxXg-cL08BTTQixEnozHgAAAFs"]
[Thu Sep 17 15:11:31.358901 2026] [security2:error] [pid 971102:tid 971254] [client 157.55.39.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXgucL08BTTQixEnozEAAAABQ"]
[Thu Sep 17 15:11:31.477676 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/"] [unique_id "aqxXg-cL08BTTQixEnozJgAAAEE"]
[Thu Sep 17 15:11:31.653064 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/graphql/.env"] [unique_id "aqxXg-cL08BTTQixEnozKAAAAEg"]
[Thu Sep 17 15:11:31.681506 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/"] [unique_id "aqxXg-cL08BTTQixEnozKQAAAAM"]
[Thu Sep 17 15:11:31.805272 2026] [security2:error] [pid 971102:tid 971257] [client 138.199.7.239:1344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXg-cL08BTTQixEnozKgAAF0w"]
[Thu Sep 17 15:11:31.826944 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wp-includes/js/tinymce/"] [unique_id "aqxXg-cL08BTTQixEnozLQAAAAw"]
[Thu Sep 17 15:11:31.945841 2026] [security2:error] [pid 971102:tid 971356] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/gateway/.env"] [unique_id "aqxXg-cL08BTTQixEnozNQAAAHo"]
[Thu Sep 17 15:11:32.152845 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozNgAAACc"]
[Thu Sep 17 15:11:32.152862 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozNgAAACc"]
[Thu Sep 17 15:11:32.199157 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/microservice/.env"] [unique_id "aqxXhOcL08BTTQixEnozOgAAAHc"]
[Thu Sep 17 15:11:32.322790 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhOcL08BTTQixEnozPAAAAG8"]
[Thu Sep 17 15:11:32.471092 2026] [security2:error] [pid 971102:tid 971279] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/service/.env"] [unique_id "aqxXhOcL08BTTQixEnozQgAAAC0"]
[Thu Sep 17 15:11:32.483767 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhOcL08BTTQixEnozQQAAADs"]
[Thu Sep 17 15:11:32.627222 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/wp-includes/js/tinymce/skins/"] [unique_id "aqxXhOcL08BTTQixEnozRAAAADI"]
[Thu Sep 17 15:11:32.744473 2026] [security2:error] [pid 971102:tid 971296] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/v3/.env"] [unique_id "aqxXhOcL08BTTQixEnozSgAAAD4"]
[Thu Sep 17 15:11:32.890949 2026] [security2:error] [pid 971102:tid 971269] [client 186.105.232.15:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXhOcL08BTTQixEnozUgAAACM"]
[Thu Sep 17 15:11:32.891061 2026] [security2:error] [pid 971102:tid 971269] [client 186.105.232.15:51548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXhOcL08BTTQixEnozUgAAACM"]
[Thu Sep 17 15:11:32.928075 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/dev/.env"] [unique_id "aqxXhOcL08BTTQixEnozVAAAAGM"]
[Thu Sep 17 15:11:32.956136 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhOcL08BTTQixEnozSwAAAH8"]
[Thu Sep 17 15:11:32.956156 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhOcL08BTTQixEnozSwAAAH8"]
[Thu Sep 17 15:11:33.091977 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/staging/.env"] [unique_id "aqxXhecL08BTTQixEnozWgAAAEA"]
[Thu Sep 17 15:11:33.111077 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/fonts/"] [unique_id "aqxXhecL08BTTQixEnozWwAAAAg"]
[Thu Sep 17 15:11:33.278445 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/fonts/"] [unique_id "aqxXhecL08BTTQixEnozXgAAAGI"]
[Thu Sep 17 15:11:33.424615 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/fonts/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhecL08BTTQixEnozYgAAAGY"]
[Thu Sep 17 15:11:33.470516 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/vendor/.env"] [unique_id "aqxXhecL08BTTQixEnozZQAAAFU"]
[Thu Sep 17 15:11:33.688832 2026] [security2:error] [pid 971102:tid 971342] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/lib/.env"] [unique_id "aqxXhecL08BTTQixEnozagAAAGw"]
[Thu Sep 17 15:11:33.767845 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhecL08BTTQixEnozZwAAAE4"]
[Thu Sep 17 15:11:33.767868 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhecL08BTTQixEnozZwAAAE4"]
[Thu Sep 17 15:11:33.792873 2026] [security2:error] [pid 971102:tid 971325] [client 223.109.252.148:36606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "talent-in-borders.com"] [uri "/tag/beacon/"] [unique_id "aqxXhecL08BTTQixEnozbAAAAFs"]
[Thu Sep 17 15:11:33.792981 2026] [security2:error] [pid 971102:tid 971325] [client 223.109.252.148:36606] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "talent-in-borders.com"] [uri "/tag/beacon/"] [unique_id "aqxXhecL08BTTQixEnozbAAAAFs"]
[Thu Sep 17 15:11:33.904973 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/resources/.env"] [unique_id "aqxXhecL08BTTQixEnozcwAAACY"]
[Thu Sep 17 15:11:33.922275 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "aqxXhecL08BTTQixEnozdAAAAFY"]
[Thu Sep 17 15:11:34.081992 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "aqxXhucL08BTTQixEnozewAAABc"]
[Thu Sep 17 15:11:34.226948 2026] [security2:error] [pid 971102:tid 971267] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhucL08BTTQixEnozggAAACE"]
[Thu Sep 17 15:11:34.262773 2026] [security2:error] [pid 971102:tid 971277] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxXhucL08BTTQixEnozhQAAACs"]
[Thu Sep 17 15:11:34.305749 2026] [security2:error] [pid 971102:tid 971295] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxXhucL08BTTQixEnozeQAAPVg"]
[Thu Sep 17 15:11:34.409583 2026] [security2:error] [pid 971102:tid 971245] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozlgAAAAs"], referer: https://cpcalendars.sav.yiu.mybluehost.me/robots.txt
[Thu Sep 17 15:11:34.417602 2026] [security2:error] [pid 971102:tid 971262] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozjAAAHF4"], referer: https://cpcalendars.sav.yiu.mybluehost.me/robots.txt
[Thu Sep 17 15:11:34.480087 2026] [security2:error] [pid 971102:tid 971250] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/assets/.env"] [unique_id "aqxXhucL08BTTQixEnozmwAAABA"]
[Thu Sep 17 15:11:34.524827 2026] [security2:error] [pid 971102:tid 971318] [client 4.240.114.86:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxXhucL08BTTQixEnozngAAAFQ"], referer: binance.com
[Thu Sep 17 15:11:34.549166 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhucL08BTTQixEnozjgAAAC0"]
[Thu Sep 17 15:11:34.549187 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhucL08BTTQixEnozjgAAAC0"]
[Thu Sep 17 15:11:34.557974 2026] [security2:error] [pid 971102:tid 971316] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnoznwAAAFI"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.604975 2026] [security2:error] [pid 971102:tid 971269] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozmAAAI2I"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.634570 2026] [security2:error] [pid 971102:tid 971283] [client 74.7.230.40:53718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.freemarkjordan.com"] [uri "/robots.txt"] [unique_id "aqxXhucL08BTTQixEnozoQAAADE"]
[Thu Sep 17 15:11:34.672531 2026] [security2:error] [pid 971102:tid 971240] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/uploads/.env"] [unique_id "aqxXhucL08BTTQixEnozpgAAAAY"]
[Thu Sep 17 15:11:34.675595 2026] [security2:error] [pid 971102:tid 971242] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozpwAAAAg"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.678747 2026] [security2:error] [pid 971102:tid 971354] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozpAAAeGU"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.719526 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/"] [unique_id "aqxXhucL08BTTQixEnozqgAAADg"]
[Thu Sep 17 15:11:34.839971 2026] [security2:error] [pid 971102:tid 971275] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozrwAAACk"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.905250 2026] [security2:error] [pid 971102:tid 971264] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozqwAAHmY"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.996962 2026] [security2:error] [pid 971102:tid 971351] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozuQAAAHU"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:35.011540 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/internal/.env"] [unique_id "aqxXh-cL08BTTQixEnozugAAAAE"]
[Thu Sep 17 15:11:35.035241 2026] [security2:error] [pid 971102:tid 971304] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnoztQAARmk"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:35.039617 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/"] [unique_id "aqxXh-cL08BTTQixEnozuwAAAF4"]
[Thu Sep 17 15:11:35.181734 2026] [security2:error] [pid 971102:tid 971261] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/tools/.env"] [unique_id "aqxXh-cL08BTTQixEnozwwAAABs"]
[Thu Sep 17 15:11:35.193956 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/wp-includes/js/tinymce/skins/"] [unique_id "aqxXh-cL08BTTQixEnozxQAAADw"]
[Thu Sep 17 15:11:35.203813 2026] [autoindex:error] [pid 971102:tid 971268] [client 106.63.26.14:63368] AH01276: Cannot serve directory /home1/vxmhuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://vxm.hui.mybluehost.me/
[Thu Sep 17 15:11:35.519242 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXh-cL08BTTQixEnozyQAAAFk"]
[Thu Sep 17 15:11:35.519265 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXh-cL08BTTQixEnozyQAAAFk"]
[Thu Sep 17 15:11:35.547317 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/scripts/.env"] [unique_id "aqxXh-cL08BTTQixEnoz1QAAAAs"]
[Thu Sep 17 15:11:35.658525 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/"] [unique_id "aqxXh-cL08BTTQixEnoz2QAAADI"]
[Thu Sep 17 15:11:35.701957 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXh-cL08BTTQixEnoz3AAAABc"]
[Thu Sep 17 15:11:35.704954 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXh-cL08BTTQixEnoz3AAAABc"]
[Thu Sep 17 15:11:35.839045 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/"] [unique_id "aqxXh-cL08BTTQixEnoz4QAAACg"]
[Thu Sep 17 15:11:35.976491 2026] [security2:error] [pid 971102:tid 971269] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/bin/.env"] [unique_id "aqxXh-cL08BTTQixEnoz5wAAACM"]
[Thu Sep 17 15:11:35.981353 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/wp-includes/js/tinymce/skins/wordpress/"] [unique_id "aqxXh-cL08BTTQixEnoz6AAAADE"]
[Thu Sep 17 15:11:36.169963 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sbin/.env"] [unique_id "aqxXiOcL08BTTQixEnoz7QAAAB0"]
[Thu Sep 17 15:11:36.320248 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiOcL08BTTQixEnoz6wAAAEA"]
[Thu Sep 17 15:11:36.320273 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiOcL08BTTQixEnoz6wAAAEA"]
[Thu Sep 17 15:11:36.394711 2026] [security2:error] [pid 971102:tid 971360] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/local/.env"] [unique_id "aqxXiOcL08BTTQixEno0BgAAAH4"]
[Thu Sep 17 15:11:36.466488 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiOcL08BTTQixEno0BwAAAEM"]
[Thu Sep 17 15:11:36.582861 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/portal/.env"] [unique_id "aqxXiOcL08BTTQixEno0DAAAAEg"]
[Thu Sep 17 15:11:36.713214 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiOcL08BTTQixEno0DQAAACk"]
[Thu Sep 17 15:11:36.786085 2026] [security2:error] [pid 971102:tid 971327] [client 167.235.143.113:46336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxXiOcL08BTTQixEno0EgAAAF0"], referer: https://faewave.com
[Thu Sep 17 15:11:36.812089 2026] [log_config:warn] [pid 955873:tid 956130] (32)Broken pipe: [client 198.71.60.165:54714] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:11:36.812106 2026] [log_config:warn] [pid 955873:tid 956130] (32)Broken pipe: [client 198.71.60.165:54714] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:11:36.868757 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/wp-includes/js/tinymce/"] [unique_id "aqxXiOcL08BTTQixEno0FgAAAAw"]
[Thu Sep 17 15:11:37.010305 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/dashboard/.env"] [unique_id "aqxXiecL08BTTQixEno0IAAAAGg"]
[Thu Sep 17 15:11:37.176235 2026] [security2:error] [pid 971102:tid 971335] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/panel/.env"] [unique_id "aqxXiecL08BTTQixEno0LgAAAGU"]
[Thu Sep 17 15:11:37.211766 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0IQAAACY"]
[Thu Sep 17 15:11:37.211786 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0IQAAACY"]
[Thu Sep 17 15:11:37.357948 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "aqxXiecL08BTTQixEno0PwAAAHk"]
[Thu Sep 17 15:11:37.524458 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "aqxXiecL08BTTQixEno0SAAAAHE"]
[Thu Sep 17 15:11:37.547474 2026] [security2:error] [pid 971102:tid 971310] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/crm/.env"] [unique_id "aqxXiecL08BTTQixEno0SgAAAEw"]
[Thu Sep 17 15:11:37.642895 2026] [security2:error] [pid 971102:tid 971258] [client 45.169.98.18:56193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXiecL08BTTQixEno0UgAAABg"]
[Thu Sep 17 15:11:37.642977 2026] [security2:error] [pid 971102:tid 971258] [client 45.169.98.18:56193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXiecL08BTTQixEno0UgAAABg"]
[Thu Sep 17 15:11:37.677641 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/inlite/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiecL08BTTQixEno0VgAAAG4"]
[Thu Sep 17 15:11:37.816508 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/erp/.env"] [unique_id "aqxXiecL08BTTQixEno0WAAAAAo"]
[Thu Sep 17 15:11:37.985773 2026] [security2:error] [pid 971102:tid 971240] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/shop/.env"] [unique_id "aqxXiecL08BTTQixEno0YAAAAAY"]
[Thu Sep 17 15:11:38.023831 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0WQAAABM"]
[Thu Sep 17 15:11:38.023854 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0WQAAABM"]
[Thu Sep 17 15:11:38.166858 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/modern/"] [unique_id "aqxXiucL08BTTQixEno0YwAAAAI"]
[Thu Sep 17 15:11:38.240270 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/store/.env"] [unique_id "aqxXiucL08BTTQixEno0ZAAAAHg"]
[Thu Sep 17 15:11:38.336324 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/modern/"] [unique_id "aqxXiucL08BTTQixEno0aQAAAEk"]
[Thu Sep 17 15:11:38.472566 2026] [security2:error] [pid 971102:tid 971265] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/saas/.env"] [unique_id "aqxXiucL08BTTQixEno0dQAAAB8"]
[Thu Sep 17 15:11:38.489890 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/modern/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiucL08BTTQixEno0dgAAACw"]
[Thu Sep 17 15:11:38.538046 2026] [security2:error] [pid 971102:tid 971275] [client 5.189.145.112:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxXiucL08BTTQixEno0dwAAACk"], referer: binance.com
[Thu Sep 17 15:11:38.677749 2026] [security2:error] [pid 971102:tid 971322] [client 4.240.114.86:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXiucL08BTTQixEno0fwAAAFg"], referer: binance.com
[Thu Sep 17 15:11:38.715879 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/client/.env"] [unique_id "aqxXiucL08BTTQixEno0ggAAAAw"]
[Thu Sep 17 15:11:38.830531 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiucL08BTTQixEno0egAAAGw"]
[Thu Sep 17 15:11:38.830559 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiucL08BTTQixEno0egAAAGw"]
[Thu Sep 17 15:11:38.911623 2026] [security2:error] [pid 971102:tid 971300] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/project/.env"] [unique_id "aqxXiucL08BTTQixEno0iQAAAEI"]
[Thu Sep 17 15:11:38.970204 2026] [security2:error] [pid 971102:tid 971152] [remote 216.73.217.142:51408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxXiucL08BTTQixEno0iwAAPDA"]
[Thu Sep 17 15:11:38.972087 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "aqxXiucL08BTTQixEno0jAAAADw"]
[Thu Sep 17 15:11:39.065586 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/admin-panel/.env"] [unique_id "aqxXi-cL08BTTQixEno0kAAAACY"]
[Thu Sep 17 15:11:39.123751 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "aqxXi-cL08BTTQixEno0kwAAAEU"]
[Thu Sep 17 15:11:39.240532 2026] [security2:error] [pid 971102:tid 971351] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/control-panel/.env"] [unique_id "aqxXi-cL08BTTQixEno0lgAAAHU"]
[Thu Sep 17 15:11:39.270548 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/utils/wp-includes/js/tinymce/"] [unique_id "aqxXi-cL08BTTQixEno0mQAAAHM"]
[Thu Sep 17 15:11:39.280905 2026] [security2:error] [pid 971102:tid 971243] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0kgAAAAk"]
[Thu Sep 17 15:11:39.460138 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/user-panel/.env"] [unique_id "aqxXi-cL08BTTQixEno0ogAAAAA"]
[Thu Sep 17 15:11:39.629465 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0oAAAAG8"]
[Thu Sep 17 15:11:39.629489 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0oAAAAG8"]
[Thu Sep 17 15:11:39.810319 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/node/.env"] [unique_id "aqxXi-cL08BTTQixEno0qAAAAFI"]
[Thu Sep 17 15:11:39.840897 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env"] [unique_id "aqxXi-cL08BTTQixEno0qQAAADQ"]
[Thu Sep 17 15:11:39.910843 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:37244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "aqxXi-cL08BTTQixEno0rQAAAEo"]
[Thu Sep 17 15:11:39.910937 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:37244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "aqxXi-cL08BTTQixEno0rQAAAEo"]
[Thu Sep 17 15:11:40.021306 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/express/.env"] [unique_id "aqxXjOcL08BTTQixEno0sAAAAE8"]
[Thu Sep 17 15:11:40.186037 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:37254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxXjOcL08BTTQixEno0twAAADE"]
[Thu Sep 17 15:11:40.187033 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0rgAAAA0"]
[Thu Sep 17 15:11:40.193056 2026] [security2:error] [pid 971102:tid 971277] [client 156.192.234.52:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0uAAAACs"]
[Thu Sep 17 15:11:40.194500 2026] [security2:error] [pid 971102:tid 971277] [client 156.192.234.52:63566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0uAAAACs"]
[Thu Sep 17 15:11:40.253958 2026] [security2:error] [pid 971102:tid 971354] [client 74.7.241.182:53512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.commcapusa.gcpmanagement.com"] [uri "/robots.txt"] [unique_id "aqxXjOcL08BTTQixEno0uQAAeDQ"]
[Thu Sep 17 15:11:40.267241 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/next/.env"] [unique_id "aqxXjOcL08BTTQixEno0ugAAAEc"]
[Thu Sep 17 15:11:40.342160 2026] [security2:error] [pid 971102:tid 971274] [client 185.55.149.49:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0vQAAACg"]
[Thu Sep 17 15:11:40.342310 2026] [security2:error] [pid 971102:tid 971274] [client 185.55.149.49:60236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0vQAAACg"]
[Thu Sep 17 15:11:40.420296 2026] [security2:error] [pid 971102:tid 971278] [client 34.94.67.131:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php"] [unique_id "aqxXjOcL08BTTQixEno0wwAAACw"]
[Thu Sep 17 15:11:40.490485 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/nuxt/.env"] [unique_id "aqxXjOcL08BTTQixEno0xAAAADg"]
[Thu Sep 17 15:11:40.564703 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjOcL08BTTQixEno0vgAAAE0"]
[Thu Sep 17 15:11:40.632408 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxXjOcL08BTTQixEno0xgAAACk"]
[Thu Sep 17 15:11:40.743256 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/nest/.env"] [unique_id "aqxXjOcL08BTTQixEno0yAAAAB4"]
[Thu Sep 17 15:11:40.770052 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxXjOcL08BTTQixEno0yQAAAE4"]
[Thu Sep 17 15:11:40.770169 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:37254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxXjOcL08BTTQixEno0yQAAAE4"]
[Thu Sep 17 15:11:40.925563 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjOcL08BTTQixEno0xwAAAF0"]
[Thu Sep 17 15:11:40.933893 2026] [security2:error] [pid 971102:tid 971259] [client 34.94.67.131:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/info.php"] [unique_id "aqxXjOcL08BTTQixEno0zAAAABk"]
[Thu Sep 17 15:11:40.960840 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/react/.env"] [unique_id "aqxXjOcL08BTTQixEno00AAAAAU"]
[Thu Sep 17 15:11:40.990501 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:51537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno00gAAAGY"]
[Thu Sep 17 15:11:40.990608 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:51537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno00gAAAGY"]
[Thu Sep 17 15:11:40.998852 2026] [security2:error] [pid 971102:tid 971357] [client 204.14.250.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0mwAAAHs"], referer: https://instagram.com/
[Thu Sep 17 15:11:41.070116 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:37258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxXjecL08BTTQixEno01gAAAGU"]
[Thu Sep 17 15:11:41.166257 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/vue/.env"] [unique_id "aqxXjecL08BTTQixEno02QAAACY"]
[Thu Sep 17 15:11:41.230699 2026] [authz_core:error] [pid 971102:tid 971359] [client 143.244.57.120:59052] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/PHPMailer/error_log
[Thu Sep 17 15:11:41.234435 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxXjecL08BTTQixEno02wAAAH0"]
[Thu Sep 17 15:11:41.258104 2026] [security2:error] [pid 971102:tid 971249] [client 34.94.67.131:47596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/php.php"] [unique_id "aqxXjecL08BTTQixEno03AAAAA8"]
[Thu Sep 17 15:11:41.293616 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjecL08BTTQixEno01wAAAGo"]
[Thu Sep 17 15:11:41.376999 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/angular/.env"] [unique_id "aqxXjecL08BTTQixEno03QAAAHk"]
[Thu Sep 17 15:11:41.380336 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxXjecL08BTTQixEno03gAAADk"]
[Thu Sep 17 15:11:41.380468 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxXjecL08BTTQixEno03gAAADk"]
[Thu Sep 17 15:11:41.530797 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/svelte/.env"] [unique_id "aqxXjecL08BTTQixEno05QAAADA"]
[Thu Sep 17 15:11:41.630074 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.67.131:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/i.php"] [unique_id "aqxXjecL08BTTQixEno05wAAAGk"]
[Thu Sep 17 15:11:41.650527 2026] [core:error] [pid 971102:tid 971163] [remote 74.7.175.151:52860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:11:41.650549 2026] [core:error] [pid 971102:tid 971163] [remote 74.7.175.151:52860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:11:41.650807 2026] [security2:error] [pid 971102:tid 971324] [client 74.7.175.151:52860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-529af5fc.qat.qby.mybluehost.me"] [uri "/website_529af5fc/index.php"] [unique_id "aqxXjecL08BTTQixEno06AAAWjs"]
[Thu Sep 17 15:11:41.652096 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjecL08BTTQixEno04gAAAHE"]
[Thu Sep 17 15:11:41.663157 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxXjecL08BTTQixEno06QAAAHw"]
[Thu Sep 17 15:11:41.663242 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxXjecL08BTTQixEno06QAAAHw"]
[Thu Sep 17 15:11:41.741221 2026] [security2:error] [pid 971102:tid 971279] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/vite/.env"] [unique_id "aqxXjecL08BTTQixEno06gAAAC0"]
[Thu Sep 17 15:11:41.954818 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxXjecL08BTTQixEno08QAAAD0"]
[Thu Sep 17 15:11:41.954915 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:37278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxXjecL08BTTQixEno08QAAAD0"]
[Thu Sep 17 15:11:42.007714 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjecL08BTTQixEno07AAAADQ"]
[Thu Sep 17 15:11:42.028643 2026] [security2:error] [pid 971102:tid 971240] [client 34.94.67.131:47614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/pi.php"] [unique_id "aqxXjucL08BTTQixEno09QAAAAY"]
[Thu Sep 17 15:11:42.080554 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/backup/.env"] [unique_id "aqxXjucL08BTTQixEno09gAAACs"]
[Thu Sep 17 15:11:42.165565 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.bak"] [unique_id "aqxXjucL08BTTQixEno09wAAABY"]
[Thu Sep 17 15:11:42.184614 2026] [security2:error] [pid 971102:tid 971309] [client 220.181.108.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxXjOcL08BTTQixEno0tAAAAEs"]
[Thu Sep 17 15:11:42.243632 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXjucL08BTTQixEno0-AAAACU"]
[Thu Sep 17 15:11:42.243743 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:37280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXjucL08BTTQixEno0-AAAACU"]
[Thu Sep 17 15:11:42.310162 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/backups/.env"] [unique_id "aqxXjucL08BTTQixEno0-QAAAAc"]
[Thu Sep 17 15:11:42.323906 2026] [security2:error] [pid 971102:tid 971348] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.backup"] [unique_id "aqxXjucL08BTTQixEno0-gAAAHI"]
[Thu Sep 17 15:11:42.479758 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/old/.env"] [unique_id "aqxXjucL08BTTQixEno1AAAAACk"]
[Thu Sep 17 15:11:42.527598 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxXjucL08BTTQixEno1AQAAAA4"]
[Thu Sep 17 15:11:42.544217 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.67.131:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/pinfo.php"] [unique_id "aqxXjucL08BTTQixEno1AgAAAEg"]
[Thu Sep 17 15:11:42.645049 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/tmp/.env"] [unique_id "aqxXjucL08BTTQixEno1BAAAAAw"]
[Thu Sep 17 15:11:42.685282 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxXjucL08BTTQixEno1BQAAAE4"]
[Thu Sep 17 15:11:42.730638 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjucL08BTTQixEno0_wAAAFw"]
[Thu Sep 17 15:11:42.828290 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/random_compat/"] [unique_id "aqxXjucL08BTTQixEno1BwAAAGY"]
[Thu Sep 17 15:11:42.880160 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.old"] [unique_id "aqxXjucL08BTTQixEno1DAAAAHc"]
[Thu Sep 17 15:11:42.913723 2026] [security2:error] [pid 971102:tid 971319] [client 34.94.67.131:47626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/test.php"] [unique_id "aqxXjucL08BTTQixEno1DgAAAFU"]
[Thu Sep 17 15:11:43.140863 2026] [security2:error] [pid 971102:tid 971249] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/temp/.env"] [unique_id "aqxXj-cL08BTTQixEno1GAAAAA8"]
[Thu Sep 17 15:11:43.199402 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjucL08BTTQixEno1EQAAADM"]
[Thu Sep 17 15:11:43.199440 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjucL08BTTQixEno1EQAAADM"]
[Thu Sep 17 15:11:43.228336 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXj-cL08BTTQixEno1EgAAAFE"]
[Thu Sep 17 15:11:43.485556 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxXj-cL08BTTQixEno1IwAAADc"]
[Thu Sep 17 15:11:43.506303 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/lab/.env"] [unique_id "aqxXj-cL08BTTQixEno1JgAAADA"]
[Thu Sep 17 15:11:43.535279 2026] [security2:error] [pid 971102:tid 971324] [client 34.94.67.131:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/p.php"] [unique_id "aqxXj-cL08BTTQixEno1JwAAAFo"]
[Thu Sep 17 15:11:43.581589 2026] [security2:error] [pid 971102:tid 971352] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXj-cL08BTTQixEno1HQAAAHY"]
[Thu Sep 17 15:11:43.647471 2026] [authz_core:error] [pid 971102:tid 971351] [client 143.244.57.120:59052] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/error_log
[Thu Sep 17 15:11:43.658296 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxXj-cL08BTTQixEno1KQAAAHU"]
[Thu Sep 17 15:11:43.667781 2026] [security2:error] [pid 971102:tid 971252] [client 51.8.102.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.arhitecturabuzau.ro"] [uri "/index.php"] [unique_id "aqxXiucL08BTTQixEno0bwAAABI"]
[Thu Sep 17 15:11:43.843259 2026] [security2:error] [pid 971102:tid 971318] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxXj-cL08BTTQixEno1LgAAAFQ"]
[Thu Sep 17 15:11:43.856624 2026] [security2:error] [pid 971102:tid 971321] [client 34.94.67.131:47646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/debug.php"] [unique_id "aqxXj-cL08BTTQixEno1LwAAAFc"]
[Thu Sep 17 15:11:43.886799 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cronlab/.env"] [unique_id "aqxXj-cL08BTTQixEno1MQAAAFA"]
[Thu Sep 17 15:11:43.929968 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXj-cL08BTTQixEno1KwAAAEo"]
[Thu Sep 17 15:11:44.055797 2026] [security2:error] [pid 971102:tid 971262] [client 186.105.232.15:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkOcL08BTTQixEno1OgAAABw"]
[Thu Sep 17 15:11:44.055899 2026] [security2:error] [pid 971102:tid 971262] [client 186.105.232.15:52165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkOcL08BTTQixEno1OgAAABw"]
[Thu Sep 17 15:11:44.147624 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cron/.env"] [unique_id "aqxXkOcL08BTTQixEno1PQAAAGM"]
[Thu Sep 17 15:11:44.238514 2026] [authz_core:error] [pid 971102:tid 971305] [client 143.244.57.120:59052] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/endpoints/error_log
[Thu Sep 17 15:11:44.248398 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxXkOcL08BTTQixEno1PgAAAEc"]
[Thu Sep 17 15:11:44.274202 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1OwAAAF8"]
[Thu Sep 17 15:11:44.311346 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.67.131:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXkOcL08BTTQixEno1QAAAAEk"]
[Thu Sep 17 15:11:44.352006 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/en/.env"] [unique_id "aqxXkOcL08BTTQixEno1QgAAADg"]
[Thu Sep 17 15:11:44.421332 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/wp-includes/rest-api/"] [unique_id "aqxXkOcL08BTTQixEno1RgAAAB8"]
[Thu Sep 17 15:11:44.630884 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1RwAAAE0"]
[Thu Sep 17 15:11:44.710353 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/administrator/.env"] [unique_id "aqxXkOcL08BTTQixEno1TAAAAB4"]
[Thu Sep 17 15:11:44.764226 2026] [security2:error] [pid 971102:tid 971259] [client 34.94.67.131:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXkOcL08BTTQixEno1TwAAABk"]
[Thu Sep 17 15:11:44.783553 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1SwAAADU"]
[Thu Sep 17 15:11:44.783580 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1SwAAADU"]
[Thu Sep 17 15:11:44.928593 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxXkOcL08BTTQixEno1VgAAAC4"]
[Thu Sep 17 15:11:44.928753 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxXkOcL08BTTQixEno1VgAAAC4"]
[Thu Sep 17 15:11:44.997592 2026] [security2:error] [pid 971102:tid 971292] [client 34.94.67.131:47686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXkOcL08BTTQixEno1WgAAADo"]
[Thu Sep 17 15:11:45.087301 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1UwAAAAU"]
[Thu Sep 17 15:11:45.197550 2026] [security2:error] [pid 971102:tid 971267] [client 34.94.67.131:47694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXkecL08BTTQixEno1XQAAACE"]
[Thu Sep 17 15:11:45.204685 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:37308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxXkecL08BTTQixEno1XgAAADc"]
[Thu Sep 17 15:11:45.204797 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:37308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxXkecL08BTTQixEno1XgAAADc"]
[Thu Sep 17 15:11:45.438048 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkecL08BTTQixEno1XwAAAFk"]
[Thu Sep 17 15:11:45.493607 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:37318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxXkecL08BTTQixEno1ZQAAAHY"]
[Thu Sep 17 15:11:45.493747 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:37318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxXkecL08BTTQixEno1ZQAAAHY"]
[Thu Sep 17 15:11:45.581747 2026] [security2:error] [pid 971102:tid 971302] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/psnlink/.env"] [unique_id "aqxXkecL08BTTQixEno1agAAAEQ"]
[Thu Sep 17 15:11:45.717494 2026] [security2:error] [pid 971102:tid 971279] [client 34.94.67.131:47702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXkecL08BTTQixEno1bQAAAC0"]
[Thu Sep 17 15:11:45.754129 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/exapi/.env"] [unique_id "aqxXkecL08BTTQixEno1bgAAACQ"]
[Thu Sep 17 15:11:45.776764 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxXkecL08BTTQixEno1bwAAADI"]
[Thu Sep 17 15:11:45.776854 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:37330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxXkecL08BTTQixEno1bwAAADI"]
[Thu Sep 17 15:11:45.795211 2026] [security2:error] [pid 971102:tid 971296] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkecL08BTTQixEno1awAAAD4"]
[Thu Sep 17 15:11:45.950593 2026] [security2:error] [pid 971102:tid 971318] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sitemaps/.env"] [unique_id "aqxXkecL08BTTQixEno1cgAAAFQ"]
[Thu Sep 17 15:11:46.065957 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxXkucL08BTTQixEno1dQAAADE"]
[Thu Sep 17 15:11:46.066078 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxXkucL08BTTQixEno1dQAAADE"]
[Thu Sep 17 15:11:46.143691 2026] [security2:error] [pid 971102:tid 971321] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkecL08BTTQixEno1cwAAAFc"]
[Thu Sep 17 15:11:46.241991 2026] [security2:error] [pid 971102:tid 971301] [client 154.190.208.131:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkucL08BTTQixEno1dwAAAEM"]
[Thu Sep 17 15:11:46.244801 2026] [security2:error] [pid 971102:tid 971301] [client 154.190.208.131:42440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkucL08BTTQixEno1dwAAAEM"]
[Thu Sep 17 15:11:46.287496 2026] [security2:error] [pid 971102:tid 971308] [client 34.94.67.131:47718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXkucL08BTTQixEno1eAAAAEo"]
[Thu Sep 17 15:11:46.391254 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:37350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxXkucL08BTTQixEno1fgAAAAY"]
[Thu Sep 17 15:11:46.391405 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:37350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxXkucL08BTTQixEno1fgAAAAY"]
[Thu Sep 17 15:11:46.489914 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkucL08BTTQixEno1ewAAAGM"]
[Thu Sep 17 15:11:46.671397 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:55132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXkucL08BTTQixEno1dgAAAA0"]
[Thu Sep 17 15:11:46.686159 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxXkucL08BTTQixEno1hQAAACo"]
[Thu Sep 17 15:11:46.686257 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxXkucL08BTTQixEno1hQAAACo"]
[Thu Sep 17 15:11:46.715342 2026] [security2:error] [pid 971102:tid 971322] [client 34.94.67.131:47728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/php-info.php"] [unique_id "aqxXkucL08BTTQixEno1hgAAAFg"]
[Thu Sep 17 15:11:46.825996 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkucL08BTTQixEno1ggAAADg"]
[Thu Sep 17 15:11:46.984100 2026] [security2:error] [pid 971102:tid 971330] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.swp"] [unique_id "aqxXkucL08BTTQixEno1iQAAAGA"]
[Thu Sep 17 15:11:46.998264 2026] [security2:error] [pid 971102:tid 971327] [client 34.94.67.131:47738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpversion.php"] [unique_id "aqxXkucL08BTTQixEno1iwAAAF0"]
[Thu Sep 17 15:11:47.024968 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jAAAABk"]
[Thu Sep 17 15:11:47.025090 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jAAAABk"]
[Thu Sep 17 15:11:47.138990 2026] [security2:error] [pid 971102:tid 971287] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env~"] [unique_id "aqxXk-cL08BTTQixEno1jQAAADU"]
[Thu Sep 17 15:11:47.315227 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jwAAACA"]
[Thu Sep 17 15:11:47.315331 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:37376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jwAAACA"]
[Thu Sep 17 15:11:47.325838 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.67.131:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/_phpinfo.php"] [unique_id "aqxXk-cL08BTTQixEno1kAAAAC4"]
[Thu Sep 17 15:11:47.486833 2026] [security2:error] [pid 971102:tid 971300] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1jgAAAEI"]
[Thu Sep 17 15:11:47.646279 2026] [security2:error] [pid 971102:tid 971249] [client 34.94.67.131:47756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXk-cL08BTTQixEno1lwAAAA8"]
[Thu Sep 17 15:11:47.659420 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1mwAAADk"]
[Thu Sep 17 15:11:47.659524 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1mwAAADk"]
[Thu Sep 17 15:11:47.837492 2026] [security2:error] [pid 971102:tid 971299] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1lgAAAEE"]
[Thu Sep 17 15:11:47.972937 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1uwAAAAM"]
[Thu Sep 17 15:11:47.973050 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:37392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1uwAAAAM"]
[Thu Sep 17 15:11:48.050044 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.67.131:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/server-info.php"] [unique_id "aqxXlOcL08BTTQixEno1wQAAAHE"]
[Thu Sep 17 15:11:48.130562 2026] [security2:error] [pid 971102:tid 971351] [client 45.169.98.18:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlOcL08BTTQixEno1xQAAAHU"]
[Thu Sep 17 15:11:48.130657 2026] [security2:error] [pid 971102:tid 971351] [client 45.169.98.18:56855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlOcL08BTTQixEno1xQAAAHU"]
[Thu Sep 17 15:11:48.186949 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:55132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1nQAAAHk"]
[Thu Sep 17 15:11:48.192125 2026] [security2:error] [pid 971102:tid 971302] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1vAAAAEQ"]
[Thu Sep 17 15:11:48.289554 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:37398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxXlOcL08BTTQixEno1yAAAAFA"]
[Thu Sep 17 15:11:48.289650 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:37398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxXlOcL08BTTQixEno1yAAAAFA"]
[Thu Sep 17 15:11:48.488015 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.67.131:47768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/server-status.php"] [unique_id "aqxXlOcL08BTTQixEno10QAAAEM"]
[Thu Sep 17 15:11:48.543636 2026] [security2:error] [pid 971102:tid 971321] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlOcL08BTTQixEno1yQAAAFc"]
[Thu Sep 17 15:11:48.590502 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:37408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxXlOcL08BTTQixEno11gAAAEA"]
[Thu Sep 17 15:11:48.590588 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:37408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxXlOcL08BTTQixEno11gAAAEA"]
[Thu Sep 17 15:11:48.878151 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:37416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxXlOcL08BTTQixEno14gAAAHc"]
[Thu Sep 17 15:11:48.878295 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:37416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxXlOcL08BTTQixEno14gAAAHc"]
[Thu Sep 17 15:11:48.883102 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlOcL08BTTQixEno13AAAADY"]
[Thu Sep 17 15:11:48.944947 2026] [security2:error] [pid 971102:tid 971335] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/logs/.env"] [unique_id "aqxXlOcL08BTTQixEno15wAAAGU"]
[Thu Sep 17 15:11:49.120477 2026] [security2:error] [pid 971102:tid 971320] [client 34.94.67.131:47782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXlecL08BTTQixEno19wAAAFY"]
[Thu Sep 17 15:11:49.168391 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxXlecL08BTTQixEno1-gAAADk"]
[Thu Sep 17 15:11:49.168486 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxXlecL08BTTQixEno1-gAAADk"]
[Thu Sep 17 15:11:49.226843 2026] [security2:error] [pid 971102:tid 971334] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlecL08BTTQixEno18AAAAGQ"]
[Thu Sep 17 15:11:49.256039 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cache/.env"] [unique_id "aqxXlecL08BTTQixEno1_QAAAHs"]
[Thu Sep 17 15:11:49.450416 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailer/.env"] [unique_id "aqxXlecL08BTTQixEno2BAAAAHA"]
[Thu Sep 17 15:11:49.453830 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxXlecL08BTTQixEno2BQAAABc"]
[Thu Sep 17 15:11:49.453910 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:37434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxXlecL08BTTQixEno2BQAAABc"]
[Thu Sep 17 15:11:49.473675 2026] [security2:error] [pid 971102:tid 971343] [client 5.189.145.112:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxXlecL08BTTQixEno2BgAAAG0"], referer: binance.com
[Thu Sep 17 15:11:49.576164 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlecL08BTTQixEno1_wAAAAs"]
[Thu Sep 17 15:11:49.636755 2026] [security2:error] [pid 971102:tid 971325] [client 34.94.67.131:47788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXlecL08BTTQixEno2DgAAAFs"]
[Thu Sep 17 15:11:49.719191 2026] [security2:error] [pid 971102:tid 971295] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mail/.env"] [unique_id "aqxXlecL08BTTQixEno2DwAAAD0"]
[Thu Sep 17 15:11:49.731285 2026] [security2:error] [pid 971102:tid 971258] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/app/.env"] [unique_id "aqxXlecL08BTTQixEno2EAAAABg"]
[Thu Sep 17 15:11:49.755112 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxXlecL08BTTQixEno2EQAAAD4"]
[Thu Sep 17 15:11:49.755191 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxXlecL08BTTQixEno2EQAAAD4"]
[Thu Sep 17 15:11:49.827577 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxXlecL08BTTQixEno2FAAAAEU"]
[Thu Sep 17 15:11:49.868593 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/email/.env"] [unique_id "aqxXlecL08BTTQixEno2GAAAAFA"]
[Thu Sep 17 15:11:49.887573 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/apps/.env"] [unique_id "aqxXlecL08BTTQixEno2GQAAABw"]
[Thu Sep 17 15:11:50.035532 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxXlucL08BTTQixEno2HwAAAHI"]
[Thu Sep 17 15:11:50.035636 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:47018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxXlucL08BTTQixEno2HwAAAHI"]
[Thu Sep 17 15:11:50.036413 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env"] [unique_id "aqxXlucL08BTTQixEno2IAAAYgg"]
[Thu Sep 17 15:11:50.037783 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2IwAAYgo"]
[Thu Sep 17 15:11:50.037847 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2IgAAYgk"]
[Thu Sep 17 15:11:50.037982 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2IQAAYgc"]
[Thu Sep 17 15:11:50.038029 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2JQAAYhE"]
[Thu Sep 17 15:11:50.038139 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2JAAAYgs"]
[Thu Sep 17 15:11:50.038223 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2JgAAYgg"]
[Thu Sep 17 15:11:50.038567 2026] [security2:error] [pid 971102:tid 971113] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.backup"] [unique_id "aqxXlucL08BTTQixEno2JwAAYgk"]
[Thu Sep 17 15:11:50.038885 2026] [security2:error] [pid 971102:tid 971121] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.old"] [unique_id "aqxXlucL08BTTQixEno2KQAAYhE"]
[Thu Sep 17 15:11:50.038913 2026] [security2:error] [pid 971102:tid 971111] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.bak"] [unique_id "aqxXlucL08BTTQixEno2KgAAYgc"]
[Thu Sep 17 15:11:50.039504 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2KAAAYgo"]
[Thu Sep 17 15:11:50.040009 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LgAAYhc"]
[Thu Sep 17 15:11:50.040088 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LwAAYhk"]
[Thu Sep 17 15:11:50.040141 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2KwAAYgs"]
[Thu Sep 17 15:11:50.040447 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LQAAYhg"]
[Thu Sep 17 15:11:50.040480 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LAAAYgg"]
[Thu Sep 17 15:11:50.045282 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/.env"] [unique_id "aqxXlucL08BTTQixEno2MAAAAEA"]
[Thu Sep 17 15:11:50.157641 2026] [security2:error] [pid 971102:tid 971241] [client 34.94.67.131:43776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXlucL08BTTQixEno2NQAAAAc"]
[Thu Sep 17 15:11:50.200862 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/web/.env"] [unique_id "aqxXlucL08BTTQixEno2NwAAAFg"]
[Thu Sep 17 15:11:50.275684 2026] [security2:error] [pid 971102:tid 971133] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/.env.php"] [unique_id "aqxXlucL08BTTQixEno2PAAACB0"]
[Thu Sep 17 15:11:50.277170 2026] [security2:error] [pid 971102:tid 971137] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env~"] [unique_id "aqxXlucL08BTTQixEno2PgAACCE"]
[Thu Sep 17 15:11:50.277173 2026] [security2:error] [pid 971102:tid 971136] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.swp"] [unique_id "aqxXlucL08BTTQixEno2OwAACCA"]
[Thu Sep 17 15:11:50.278292 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2OgAACBs"]
[Thu Sep 17 15:11:50.278711 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2PwAACCI"]
[Thu Sep 17 15:11:50.278759 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2QQAACCQ"]
[Thu Sep 17 15:11:50.278828 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2PQAACBw"]
[Thu Sep 17 15:11:50.278866 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2OQAACB4"]
[Thu Sep 17 15:11:50.278897 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2QAAACB8"]
[Thu Sep 17 15:11:50.318083 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxXlucL08BTTQixEno2QgAAABo"]
[Thu Sep 17 15:11:50.318181 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:47020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxXlucL08BTTQixEno2QgAAABo"]
[Thu Sep 17 15:11:50.356759 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/site/.env"] [unique_id "aqxXlucL08BTTQixEno2QwAAAH8"]
[Thu Sep 17 15:11:50.391905 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/smtp/.env"] [unique_id "aqxXlucL08BTTQixEno2RAAAAB4"]
[Thu Sep 17 15:11:50.393371 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.67.131:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXlucL08BTTQixEno2RgAAAEg"]
[Thu Sep 17 15:11:50.488604 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/api/.env"] [unique_id "aqxXlucL08BTTQixEno2TwAAICY"]
[Thu Sep 17 15:11:50.488647 2026] [security2:error] [pid 971102:tid 971148] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/server/.env"] [unique_id "aqxXlucL08BTTQixEno2VAAAICw"]
[Thu Sep 17 15:11:50.488685 2026] [security2:error] [pid 971102:tid 971145] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/app/.env"] [unique_id "aqxXlucL08BTTQixEno2TAAAICk"]
[Thu Sep 17 15:11:50.488714 2026] [security2:error] [pid 971102:tid 971156] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/public/.env"] [unique_id "aqxXlucL08BTTQixEno2WgAAIDQ"]
[Thu Sep 17 15:11:50.488747 2026] [security2:error] [pid 971102:tid 971149] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/backend/.env"] [unique_id "aqxXlucL08BTTQixEno2UgAAIC0"]
[Thu Sep 17 15:11:50.488786 2026] [security2:error] [pid 971102:tid 971150] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/config/.env"] [unique_id "aqxXlucL08BTTQixEno2VQAAIC4"]
[Thu Sep 17 15:11:50.488813 2026] [security2:error] [pid 971102:tid 971157] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/frontend/.env"] [unique_id "aqxXlucL08BTTQixEno2WQAAIDU"]
[Thu Sep 17 15:11:50.488838 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/web/.env"] [unique_id "aqxXlucL08BTTQixEno2VwAAIDI"]
[Thu Sep 17 15:11:50.488855 2026] [security2:error] [pid 971102:tid 971153] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/src/.env"] [unique_id "aqxXlucL08BTTQixEno2VgAAIDE"]
[Thu Sep 17 15:11:50.488915 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/var/www/.env"] [unique_id "aqxXlucL08BTTQixEno2WwAAIDY"]
[Thu Sep 17 15:11:50.488980 2026] [security2:error] [pid 971102:tid 971155] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/client/.env"] [unique_id "aqxXlucL08BTTQixEno2WAAAIDM"]
[Thu Sep 17 15:11:50.490053 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2TQAAIBU"]
[Thu Sep 17 15:11:50.490524 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2UAAAICg"]
[Thu Sep 17 15:11:50.490566 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2UQAAICo"]
[Thu Sep 17 15:11:50.490615 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2TgAAICs"]
[Thu Sep 17 15:11:50.491110 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2UwAAIDA"]
[Thu Sep 17 15:11:50.513362 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/public/.env"] [unique_id "aqxXlucL08BTTQixEno2XAAAAH0"]
[Thu Sep 17 15:11:50.601906 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxXlucL08BTTQixEno2XwAAAFE"]
[Thu Sep 17 15:11:50.601982 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:47032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxXlucL08BTTQixEno2XwAAAFE"]
[Thu Sep 17 15:11:50.676140 2026] [security2:error] [pid 971102:tid 971141] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/var/www/html/.env"] [unique_id "aqxXlucL08BTTQixEno2YwAAViU"]
[Thu Sep 17 15:11:50.682870 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/backup/.env"] [unique_id "aqxXlucL08BTTQixEno2ZgAAETk"]
[Thu Sep 17 15:11:50.682902 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/laravel/.env"] [unique_id "aqxXlucL08BTTQixEno2ZQAAETc"]
[Thu Sep 17 15:11:50.682925 2026] [security2:error] [pid 971102:tid 971166] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/application/.env"] [unique_id "aqxXlucL08BTTQixEno2aAAAET4"]
[Thu Sep 17 15:11:50.682945 2026] [security2:error] [pid 971102:tid 971163] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/back/.env"] [unique_id "aqxXlucL08BTTQixEno2agAAETs"]
[Thu Sep 17 15:11:50.682948 2026] [security2:error] [pid 971102:tid 971164] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/apps/.env"] [unique_id "aqxXlucL08BTTQixEno2ZwAAETw"]
[Thu Sep 17 15:11:50.683043 2026] [security2:error] [pid 971102:tid 971162] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/prod/.env"] [unique_id "aqxXlucL08BTTQixEno2awAAETo"]
[Thu Sep 17 15:11:50.683048 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/production/.env"] [unique_id "aqxXlucL08BTTQixEno2bAAAEUE"]
[Thu Sep 17 15:11:50.683356 2026] [security2:error] [pid 971102:tid 971165] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/cms/.env"] [unique_id "aqxXlucL08BTTQixEno2aQAAET0"]
[Thu Sep 17 15:11:50.683481 2026] [security2:error] [pid 971102:tid 971167] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/dev/.env"] [unique_id "aqxXlucL08BTTQixEno2bQAAET8"]
[Thu Sep 17 15:11:50.683557 2026] [security2:error] [pid 971102:tid 971151] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/staging/.env"] [unique_id "aqxXlucL08BTTQixEno2bgAAES8"]
[Thu Sep 17 15:11:50.683586 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/test/.env"] [unique_id "aqxXlucL08BTTQixEno2bwAAEUI"]
[Thu Sep 17 15:11:50.683602 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/new/.env"] [unique_id "aqxXlucL08BTTQixEno2cQAAETc"]
[Thu Sep 17 15:11:50.683629 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/old/.env"] [unique_id "aqxXlucL08BTTQixEno2cAAAETk"]
[Thu Sep 17 15:11:50.683703 2026] [security2:error] [pid 971102:tid 971166] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/node-api/.env"] [unique_id "aqxXlucL08BTTQixEno2cwAAET4"]
[Thu Sep 17 15:11:50.683727 2026] [security2:error] [pid 971102:tid 971164] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/api-backend/.env"] [unique_id "aqxXlucL08BTTQixEno2dAAAETw"]
[Thu Sep 17 15:11:50.683917 2026] [security2:error] [pid 971102:tid 971297] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailing/.env"] [unique_id "aqxXlucL08BTTQixEno2cgAAAD8"]
[Thu Sep 17 15:11:50.763830 2026] [security2:error] [pid 971102:tid 971291] [client 34.94.67.131:43796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXlucL08BTTQixEno2dwAAADk"]
[Thu Sep 17 15:11:50.816356 2026] [security2:error] [pid 971102:tid 971273] [client 156.192.234.52:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlucL08BTTQixEno2eAAAACc"]
[Thu Sep 17 15:11:50.817574 2026] [security2:error] [pid 971102:tid 971273] [client 156.192.234.52:64206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlucL08BTTQixEno2eAAAACc"]
[Thu Sep 17 15:11:50.858636 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlucL08BTTQixEno2YQAAAA4"]
[Thu Sep 17 15:11:50.863328 2026] [security2:error] [pid 971102:tid 971178] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/admin-app/.env"] [unique_id "aqxXlucL08BTTQixEno2ewAAPEo"]
[Thu Sep 17 15:11:50.868797 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxXlucL08BTTQixEno2ggAAXks"]
[Thu Sep 17 15:11:50.868845 2026] [security2:error] [pid 971102:tid 971182] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/server/backend/.env"] [unique_id "aqxXlucL08BTTQixEno2gAAAXk4"]
[Thu Sep 17 15:11:50.868845 2026] [security2:error] [pid 971102:tid 971177] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/server/api/.env"] [unique_id "aqxXlucL08BTTQixEno2fwAAXkk"]
[Thu Sep 17 15:11:50.868871 2026] [security2:error] [pid 971102:tid 971184] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.aws/.env"] [unique_id "aqxXlucL08BTTQixEno2hAAAXlA"]
[Thu Sep 17 15:11:50.868889 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/public_html/.env"] [unique_id "aqxXlucL08BTTQixEno2fQAAXkg"]
[Thu Sep 17 15:11:50.868897 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/aws/.env"] [unique_id "aqxXlucL08BTTQixEno2gwAAXlM"]
[Thu Sep 17 15:11:50.868937 2026] [security2:error] [pid 971102:tid 971180] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/current/.env"] [unique_id "aqxXlucL08BTTQixEno2fgAAXkw"]
[Thu Sep 17 15:11:50.868936 2026] [security2:error] [pid 971102:tid 971181] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.docker/.env"] [unique_id "aqxXlucL08BTTQixEno2gQAAXk0"]
[Thu Sep 17 15:11:50.868995 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/stripe/.env"] [unique_id "aqxXlucL08BTTQixEno2hQAAXlE"]
[Thu Sep 17 15:11:50.869686 2026] [security2:error] [pid 971102:tid 971182] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/v2/.env"] [unique_id "aqxXlucL08BTTQixEno2iQAAXk4"]
[Thu Sep 17 15:11:50.869702 2026] [security2:error] [pid 971102:tid 971177] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/v1/.env"] [unique_id "aqxXlucL08BTTQixEno2iAAAXkk"]
[Thu Sep 17 15:11:50.869746 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/v3/.env"] [unique_id "aqxXlucL08BTTQixEno2igAAXlE"]
[Thu Sep 17 15:11:50.871018 2026] [security2:error] [pid 971102:tid 971328] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2hgAAXlI"]
[Thu Sep 17 15:11:50.871070 2026] [security2:error] [pid 971102:tid 971328] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2hwAAXlQ"]
[Thu Sep 17 15:11:50.896195 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxXlucL08BTTQixEno2iwAAAHs"]
[Thu Sep 17 15:11:50.896270 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:47044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxXlucL08BTTQixEno2iwAAAHs"]
[Thu Sep 17 15:11:50.938201 2026] [security2:error] [pid 971102:tid 971143] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/administrator/.env"] [unique_id "aqxXlucL08BTTQixEno2fAAAXic"]
[Thu Sep 17 15:11:50.939239 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/notifications/.env"] [unique_id "aqxXlucL08BTTQixEno2jwAAAHA"]
[Thu Sep 17 15:11:51.014492 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/backend/.env"] [unique_id "aqxXl-cL08BTTQixEno2kQAAAAE"]
[Thu Sep 17 15:11:51.051744 2026] [security2:error] [pid 971102:tid 971183] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/media/.env"] [unique_id "aqxXl-cL08BTTQixEno2kgAAWk8"]
[Thu Sep 17 15:11:51.056072 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2kwAAeVg"]
[Thu Sep 17 15:11:51.057701 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.git/config.bak"] [unique_id "aqxXl-cL08BTTQixEno2nwAAeWw"]
[Thu Sep 17 15:11:51.058783 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2nAAAeWA"]
[Thu Sep 17 15:11:51.058921 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lAAAeVo"]
[Thu Sep 17 15:11:51.058956 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lwAAeVg"]
[Thu Sep 17 15:11:51.059041 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lQAAeVY"]
[Thu Sep 17 15:11:51.059076 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lgAAeVw"]
[Thu Sep 17 15:11:51.059110 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mAAAeWU"]
[Thu Sep 17 15:11:51.059144 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mQAAeWE"]
[Thu Sep 17 15:11:51.059181 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mgAAeVk"]
[Thu Sep 17 15:11:51.059276 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2nQAAeVs"]
[Thu Sep 17 15:11:51.059310 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2oAAAeW4"]
[Thu Sep 17 15:11:51.059376 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mwAAeWY"]
[Thu Sep 17 15:11:51.059412 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2ngAAeWo"]
[Thu Sep 17 15:11:51.083305 2026] [security2:error] [pid 971102:tid 971344] [client 185.55.149.49:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno2ogAAAG4"]
[Thu Sep 17 15:11:51.083408 2026] [security2:error] [pid 971102:tid 971344] [client 185.55.149.49:50551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno2ogAAAG4"]
[Thu Sep 17 15:11:51.125082 2026] [security2:error] [pid 971102:tid 971302] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2pAAARGQ"]
[Thu Sep 17 15:11:51.147911 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/notify/.env"] [unique_id "aqxXl-cL08BTTQixEno2pQAAAHw"]
[Thu Sep 17 15:11:51.167893 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/server/.env"] [unique_id "aqxXl-cL08BTTQixEno2pgAAAFk"]
[Thu Sep 17 15:11:51.181418 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:47048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2qAAAABg"]
[Thu Sep 17 15:11:51.181483 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:47048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2qAAAABg"]
[Thu Sep 17 15:11:51.236861 2026] [security2:error] [pid 971102:tid 971303] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2qwAARV8"]
[Thu Sep 17 15:11:51.240119 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rAAAUGc"]
[Thu Sep 17 15:11:51.241566 2026] [security2:error] [pid 971102:tid 971219] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxXl-cL08BTTQixEno2tQAAUHI"]
[Thu Sep 17 15:11:51.241630 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxXl-cL08BTTQixEno2sQAAUGs"]
[Thu Sep 17 15:11:51.241744 2026] [security2:error] [pid 971102:tid 971218] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/id_rsa"] [unique_id "aqxXl-cL08BTTQixEno2tgAAUHE"]
[Thu Sep 17 15:11:51.242186 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rQAAUF0"]
[Thu Sep 17 15:11:51.242645 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rgAAUGk"]
[Thu Sep 17 15:11:51.242761 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2sAAAUGg"]
[Thu Sep 17 15:11:51.242910 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2tAAAUHA"]
[Thu Sep 17 15:11:51.242957 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2sgAAUFc"]
[Thu Sep 17 15:11:51.243094 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2uAAAUG0"]
[Thu Sep 17 15:11:51.243175 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2uQAAUAA"]
[Thu Sep 17 15:11:51.243204 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rwAAUGI"]
[Thu Sep 17 15:11:51.243248 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2swAAUG8"]
[Thu Sep 17 15:11:51.243274 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2twAAUHo"]
[Thu Sep 17 15:11:51.243306 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.67.131:43810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXl-cL08BTTQixEno2ugAAAD4"]
[Thu Sep 17 15:11:51.311131 2026] [security2:error] [pid 971102:tid 971310] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2vAAATDg"]
[Thu Sep 17 15:11:51.321126 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/frontend/.env"] [unique_id "aqxXl-cL08BTTQixEno2vQAAAEc"]
[Thu Sep 17 15:11:51.412226 2026] [security2:error] [pid 971102:tid 971348] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sender/.env"] [unique_id "aqxXl-cL08BTTQixEno2vwAAAHI"]
[Thu Sep 17 15:11:51.423488 2026] [security2:error] [pid 971102:tid 971298] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wAAAQHQ"]
[Thu Sep 17 15:11:51.425705 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wQAAKH4"]
[Thu Sep 17 15:11:51.427520 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xQAAKHk"]
[Thu Sep 17 15:11:51.427620 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xAAAKHc"]
[Thu Sep 17 15:11:51.427671 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wgAAKAQ"]
[Thu Sep 17 15:11:51.427718 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wwAAKAM"]
[Thu Sep 17 15:11:51.428104 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2yAAAKHY"]
[Thu Sep 17 15:11:51.428193 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xgAAKAU"]
[Thu Sep 17 15:11:51.428230 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2zgAAKAE"]
[Thu Sep 17 15:11:51.428269 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xwAAKHU"]
[Thu Sep 17 15:11:51.428312 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2zAAAKAY"]
[Thu Sep 17 15:11:51.428391 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2ywAAKHM"]
[Thu Sep 17 15:11:51.428426 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2yQAAKAI"]
[Thu Sep 17 15:11:51.428510 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2zQAAKHg"]
[Thu Sep 17 15:11:51.428537 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2ygAAKH0"]
[Thu Sep 17 15:11:51.430980 2026] [security2:error] [pid 971102:tid 971261] [client 162.241.226.11:32768] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXl-cL08BTTQixEno2vgAAABs"]
[Thu Sep 17 15:11:51.469541 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2zwAAABY"]
[Thu Sep 17 15:11:51.469656 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2zwAAABY"]
[Thu Sep 17 15:11:51.483873 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/src/.env"] [unique_id "aqxXl-cL08BTTQixEno20AAAAAo"]
[Thu Sep 17 15:11:51.505224 2026] [security2:error] [pid 971102:tid 971349] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno20QAAcww"]
[Thu Sep 17 15:11:51.582134 2026] [security2:error] [pid 971102:tid 971263] [client 115.244.164.14:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno21gAAAB0"]
[Thu Sep 17 15:11:51.582222 2026] [security2:error] [pid 971102:tid 971263] [client 115.244.164.14:52169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno21gAAAB0"]
[Thu Sep 17 15:11:51.601869 2026] [security2:error] [pid 971102:tid 971283] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/campaign/.env"] [unique_id "aqxXl-cL08BTTQixEno21wAAADE"]
[Thu Sep 17 15:11:51.613060 2026] [security2:error] [pid 971102:tid 971269] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22AAAIw4"]
[Thu Sep 17 15:11:51.616871 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22QAAJBA"]
[Thu Sep 17 15:11:51.618156 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22wAAJBM"]
[Thu Sep 17 15:11:51.618208 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22gAAJBY"]
[Thu Sep 17 15:11:51.618280 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23QAAJBI"]
[Thu Sep 17 15:11:51.618500 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23AAAJA8"]
[Thu Sep 17 15:11:51.618681 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23gAAJA0"]
[Thu Sep 17 15:11:51.623090 2026] [security2:error] [pid 971102:tid 971111] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config.php"] [unique_id "aqxXl-cL08BTTQixEno24QAAFQc"]
[Thu Sep 17 15:11:51.625033 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno25QAAFQs"]
[Thu Sep 17 15:11:51.625150 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno25gAAFRg"]
[Thu Sep 17 15:11:51.625218 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23wAAFQk"]
[Thu Sep 17 15:11:51.625253 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno24gAAFQo"]
[Thu Sep 17 15:11:51.625288 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno24wAAFRc"]
[Thu Sep 17 15:11:51.625716 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno24AAAFRE"]
[Thu Sep 17 15:11:51.625754 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno25AAAFRk"]
[Thu Sep 17 15:11:51.638199 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/core/.env"] [unique_id "aqxXl-cL08BTTQixEno25wAAAFg"]
[Thu Sep 17 15:11:51.691876 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno26gAATgg"]
[Thu Sep 17 15:11:51.726173 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.67.131:43820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXl-cL08BTTQixEno27QAAAEM"]
[Thu Sep 17 15:11:51.777681 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxXl-cL08BTTQixEno27gAAAEg"]
[Thu Sep 17 15:11:51.777839 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxXl-cL08BTTQixEno27gAAAEg"]
[Thu Sep 17 15:11:51.793950 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/core/app/.env"] [unique_id "aqxXl-cL08BTTQixEno27wAAAFw"]
[Thu Sep 17 15:11:51.799146 2026] [security2:error] [pid 971102:tid 971319] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28AAAVX8"]
[Thu Sep 17 15:11:51.802905 2026] [security2:error] [pid 971102:tid 971259] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28QAAGRQ"]
[Thu Sep 17 15:11:51.803734 2026] [security2:error] [pid 971102:tid 971138] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/aws.php"] [unique_id "aqxXl-cL08BTTQixEno29gAAKyI"]
[Thu Sep 17 15:11:51.805170 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28wAAKyA"]
[Thu Sep 17 15:11:51.805216 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno29AAAKyE"]
[Thu Sep 17 15:11:51.805474 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28gAAKx0"]
[Thu Sep 17 15:11:51.805519 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno29QAAKxs"]
[Thu Sep 17 15:11:51.807961 2026] [security2:error] [pid 971102:tid 971327] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno29wAAXSQ"]
[Thu Sep 17 15:11:51.809217 2026] [security2:error] [pid 971102:tid 971130] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/config.inc.php"] [unique_id "aqxXl-cL08BTTQixEno2-wAAZRo"]
[Thu Sep 17 15:11:51.809236 2026] [security2:error] [pid 971102:tid 971148] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/nexmo.php"] [unique_id "aqxXl-cL08BTTQixEno2_QAAZSw"]
[Thu Sep 17 15:11:51.809271 2026] [security2:error] [pid 971102:tid 971134] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/stripe.php"] [unique_id "aqxXl-cL08BTTQixEno2-AAAZR4"]
[Thu Sep 17 15:11:51.809296 2026] [security2:error] [pid 971102:tid 971135] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/mail.php"] [unique_id "aqxXl-cL08BTTQixEno2-gAAZR8"]
[Thu Sep 17 15:11:51.810582 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2_gAAZSk"]
[Thu Sep 17 15:11:51.810757 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2_AAAZSY"]
[Thu Sep 17 15:11:51.810808 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2-QAAZRw"]
[Thu Sep 17 15:11:51.848638 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/newsletter/.env"] [unique_id "aqxXl-cL08BTTQixEno2_wAAAFI"]
[Thu Sep 17 15:11:51.878335 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3AAAAOjQ"]
[Thu Sep 17 15:11:51.948371 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/config/.env"] [unique_id "aqxXl-cL08BTTQixEno3AQAAADg"]
[Thu Sep 17 15:11:51.982343 2026] [security2:error] [pid 971102:tid 971149] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "perimetry.com"] [uri "/wp-config.php.old"] [unique_id "aqxXl-cL08BTTQixEno3BQAABC0"]
[Thu Sep 17 15:11:51.982343 2026] [security2:error] [pid 971102:tid 971153] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "perimetry.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXl-cL08BTTQixEno3BgAABDE"]
[Thu Sep 17 15:11:51.982390 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/wp-config.php"] [unique_id "aqxXl-cL08BTTQixEno3BAAABDI"]
[Thu Sep 17 15:11:51.983281 2026] [security2:error] [pid 971102:tid 971157] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "perimetry.com"] [uri "/wp-config.php.new"] [unique_id "aqxXl-cL08BTTQixEno3BwAAVjU"]
[Thu Sep 17 15:11:51.983610 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxXl-cL08BTTQixEno3CAAAVjY"]
[Thu Sep 17 15:11:51.986934 2026] [security2:error] [pid 971102:tid 971251] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3CgAAERU"]
[Thu Sep 17 15:11:51.987001 2026] [security2:error] [pid 971102:tid 971251] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3CQAAETM"]
[Thu Sep 17 15:11:51.988538 2026] [security2:error] [pid 971102:tid 971146] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxXl-cL08BTTQixEno3CwAAPyo"]
[Thu Sep 17 15:11:51.990438 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxXl-cL08BTTQixEno3EgAAP0E"]
[Thu Sep 17 15:11:51.991104 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DQAAPyg"]
[Thu Sep 17 15:11:51.991276 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3EAAAP0Y"]
[Thu Sep 17 15:11:51.991407 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DgAAPyU"]
[Thu Sep 17 15:11:51.991490 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DwAAPzA"]
[Thu Sep 17 15:11:51.991536 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DAAAPys"]
[Thu Sep 17 15:11:51.991677 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3EQAAP0U"]
[Thu Sep 17 15:11:52.053854 2026] [security2:error] [pid 971102:tid 971273] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/ses/.env"] [unique_id "aqxXmOcL08BTTQixEno3FQAAACc"]
[Thu Sep 17 15:11:52.069016 2026] [security2:error] [pid 971102:tid 971334] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3FwAAZEA"]
[Thu Sep 17 15:11:52.071745 2026] [security2:error] [pid 971102:tid 971282] [client 34.94.67.131:43826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXmOcL08BTTQixEno3GAAAADA"]
[Thu Sep 17 15:11:52.094691 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3GQAAACI"]
[Thu Sep 17 15:11:52.094768 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3GQAAACI"]
[Thu Sep 17 15:11:52.101786 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/private/.env"] [unique_id "aqxXmOcL08BTTQixEno3GwAAADw"]
[Thu Sep 17 15:11:52.199100 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JQAASTw"]
[Thu Sep 17 15:11:52.199219 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IgAASS8"]
[Thu Sep 17 15:11:52.199332 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HgAAST0"]
[Thu Sep 17 15:11:52.199362 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HwAASUM"]
[Thu Sep 17 15:11:52.199390 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HQAAST8"]
[Thu Sep 17 15:11:52.199428 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IAAASTc"]
[Thu Sep 17 15:11:52.199452 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IwAASTk"]
[Thu Sep 17 15:11:52.199528 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IQAASTs"]
[Thu Sep 17 15:11:52.199552 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HAAASUI"]
[Thu Sep 17 15:11:52.199579 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JAAAST4"]
[Thu Sep 17 15:11:52.199603 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JgAASUo"]
[Thu Sep 17 15:11:52.199626 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JwAASUs"]
[Thu Sep 17 15:11:52.199649 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3KQAASVU"]
[Thu Sep 17 15:11:52.199685 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3KAAASUc"]
[Thu Sep 17 15:11:52.199718 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3KgAASVA"]
[Thu Sep 17 15:11:52.227166 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxXmOcL08BTTQixEno3KwAAABA"]
[Thu Sep 17 15:11:52.252741 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/application/.env"] [unique_id "aqxXmOcL08BTTQixEno3LQAAAHA"]
[Thu Sep 17 15:11:52.252806 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3LAAAZkg"]
[Thu Sep 17 15:11:52.284333 2026] [security2:error] [pid 971102:tid 971328] [client 34.94.67.131:43828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php~"] [unique_id "aqxXmOcL08BTTQixEno3LgAAAF4"]
[Thu Sep 17 15:11:52.305969 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sendgrid/.env"] [unique_id "aqxXmOcL08BTTQixEno3LwAAABc"]
[Thu Sep 17 15:11:52.372487 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3MAAAAG8"]
[Thu Sep 17 15:11:52.372555 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3MAAAAG8"]
[Thu Sep 17 15:11:52.386445 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3MwAAfkw"]
[Thu Sep 17 15:11:52.386511 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NAAAfkQ"]
[Thu Sep 17 15:11:52.386547 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NwAAflE"]
[Thu Sep 17 15:11:52.386630 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3MQAAflM"]
[Thu Sep 17 15:11:52.386684 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3MgAAfk0"]
[Thu Sep 17 15:11:52.386730 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NQAAfkk"]
[Thu Sep 17 15:11:52.386765 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PAAAfk8"]
[Thu Sep 17 15:11:52.386830 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NgAAfk4"]
[Thu Sep 17 15:11:52.386905 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OAAAflQ"]
[Thu Sep 17 15:11:52.386937 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OgAAfic"]
[Thu Sep 17 15:11:52.386973 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PQAAfl4"]
[Thu Sep 17 15:11:52.387004 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PgAAfmw"]
[Thu Sep 17 15:11:52.387038 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PwAAfmA"]
[Thu Sep 17 15:11:52.387111 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OQAAflI"]
[Thu Sep 17 15:11:52.387145 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OwAAfiM"]
[Thu Sep 17 15:11:52.405107 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/bootstrap/.env"] [unique_id "aqxXmOcL08BTTQixEno3QAAAAGo"]
[Thu Sep 17 15:11:52.436563 2026] [security2:error] [pid 971102:tid 971351] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3QQAAdVg"]
[Thu Sep 17 15:11:52.455034 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxXmOcL08BTTQixEno3QgAAAHc"]
[Thu Sep 17 15:11:52.546196 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sparkpost/.env"] [unique_id "aqxXmOcL08BTTQixEno3SAAAABI"]
[Thu Sep 17 15:11:52.548177 2026] [security2:error] [pid 971102:tid 971350] [client 40.88.21.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXlecL08BTTQixEno2DQAAAHQ"], referer: http://frenchtutoringfun.com/favicon.ico
[Thu Sep 17 15:11:52.559899 2026] [security2:error] [pid 971102:tid 971289] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/database/.env"] [unique_id "aqxXmOcL08BTTQixEno3SQAAADc"]
[Thu Sep 17 15:11:52.671411 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3TQAAADs"]
[Thu Sep 17 15:11:52.671516 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:47088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3TQAAADs"]
[Thu Sep 17 15:11:52.716487 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/storage/.env"] [unique_id "aqxXmOcL08BTTQixEno3UAAAAGM"]
[Thu Sep 17 15:11:52.779769 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.67.131:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/info.php.bak"] [unique_id "aqxXmOcL08BTTQixEno3VQAAAFA"]
[Thu Sep 17 15:11:52.783841 2026] [security2:error] [pid 971102:tid 971237] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/postmark/.env"] [unique_id "aqxXmOcL08BTTQixEno3VgAAAAM"]
[Thu Sep 17 15:11:52.868856 2026] [security2:error] [pid 971102:tid 971309] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/var/www/.env"] [unique_id "aqxXmOcL08BTTQixEno3VwAAAEs"]
[Thu Sep 17 15:11:52.958505 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3WAAAACU"]
[Thu Sep 17 15:11:52.958588 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3WAAAACU"]
[Thu Sep 17 15:11:52.975697 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxXmOcL08BTTQixEno3WQAAABY"]
[Thu Sep 17 15:11:52.993330 2026] [security2:error] [pid 971102:tid 971236] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailgun/.env"] [unique_id "aqxXmOcL08BTTQixEno3WgAAAAI"]
[Thu Sep 17 15:11:53.006073 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3agAACmk"]
[Thu Sep 17 15:11:53.007479 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3WwAAClk"]
[Thu Sep 17 15:11:53.007642 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YgAACmo"]
[Thu Sep 17 15:11:53.007840 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XwAACls"]
[Thu Sep 17 15:11:53.007880 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XAAAClY"]
[Thu Sep 17 15:11:53.007921 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XQAAClw"]
[Thu Sep 17 15:11:53.007959 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XgAACmE"]
[Thu Sep 17 15:11:53.007991 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YAAACm4"]
[Thu Sep 17 15:11:53.008023 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YQAACmY"]
[Thu Sep 17 15:11:53.008054 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YwAACmQ"]
[Thu Sep 17 15:11:53.008087 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZQAACl8"]
[Thu Sep 17 15:11:53.008121 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZAAACmc"]
[Thu Sep 17 15:11:53.008162 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZgAACnI"]
[Thu Sep 17 15:11:53.008192 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZwAACms"]
[Thu Sep 17 15:11:53.008226 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3aQAACl0"]
[Thu Sep 17 15:11:53.008704 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3aAAACnE"]
[Thu Sep 17 15:11:53.027767 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/var/www/html/.env"] [unique_id "aqxXmecL08BTTQixEno3bQAAAB0"]
[Thu Sep 17 15:11:53.120834 2026] [security2:error] [pid 971102:tid 971300] [client 34.94.67.131:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXmecL08BTTQixEno3cAAAAEI"]
[Thu Sep 17 15:11:53.183887 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/current/.env"] [unique_id "aqxXmecL08BTTQixEno3cwAAAAc"]
[Thu Sep 17 15:11:53.189838 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/info.php"] [unique_id "aqxXmecL08BTTQixEno3dQAADW0"]
[Thu Sep 17 15:11:53.191377 2026] [security2:error] [pid 971102:tid 971247] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3dAAADXA"]
[Thu Sep 17 15:11:53.192083 2026] [security2:error] [pid 971102:tid 971192] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/infos.php"] [unique_id "aqxXmecL08BTTQixEno3dgAATlc"]
[Thu Sep 17 15:11:53.192139 2026] [security2:error] [pid 971102:tid 971104] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/php_info.php"] [unique_id "aqxXmecL08BTTQixEno3dwAATgA"]
[Thu Sep 17 15:11:53.192174 2026] [security2:error] [pid 971102:tid 971227] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/php-info.php"] [unique_id "aqxXmecL08BTTQixEno3eQAATno"]
[Thu Sep 17 15:11:53.192219 2026] [security2:error] [pid 971102:tid 971216] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/php.php"] [unique_id "aqxXmecL08BTTQixEno3eAAATm8"]
[Thu Sep 17 15:11:53.192227 2026] [security2:error] [pid 971102:tid 971203] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/infophp.php"] [unique_id "aqxXmecL08BTTQixEno3egAATmI"]
[Thu Sep 17 15:11:53.192276 2026] [security2:error] [pid 971102:tid 971160] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3ewAATjg"]
[Thu Sep 17 15:11:53.192338 2026] [security2:error] [pid 971102:tid 971204] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/api/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3fgAATmM"]
[Thu Sep 17 15:11:53.192373 2026] [security2:error] [pid 971102:tid 971231] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3fQAATn4"]
[Thu Sep 17 15:11:53.192393 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3fwAATnk"]
[Thu Sep 17 15:11:53.192401 2026] [security2:error] [pid 971102:tid 971107] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3gQAATgM"]
[Thu Sep 17 15:11:53.193711 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3fAAATnQ"]
[Thu Sep 17 15:11:53.193752 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3gAAATgQ"]
[Thu Sep 17 15:11:53.193805 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3gwAATnY"]
[Thu Sep 17 15:11:53.251058 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mandrill/.env"] [unique_id "aqxXmecL08BTTQixEno3igAAABM"]
[Thu Sep 17 15:11:53.281263 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxXmecL08BTTQixEno3jAAAACs"]
[Thu Sep 17 15:11:53.281355 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:47094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxXmecL08BTTQixEno3jAAAACs"]
[Thu Sep 17 15:11:53.338147 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/release/.env"] [unique_id "aqxXmecL08BTTQixEno3jQAAADM"]
[Thu Sep 17 15:11:53.353172 2026] [security2:error] [pid 971102:tid 971330] [client 34.94.67.131:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3jgAAAGA"]
[Thu Sep 17 15:11:53.374362 2026] [security2:error] [pid 971102:tid 971230] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/database.sql"] [unique_id "aqxXmecL08BTTQixEno3lQAAKn0"]
[Thu Sep 17 15:11:53.374994 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kAAAKgU"]
[Thu Sep 17 15:11:53.375172 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3jwAAKnU"]
[Thu Sep 17 15:11:53.377261 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kQAAKgY"]
[Thu Sep 17 15:11:53.377310 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kgAAKgI"]
[Thu Sep 17 15:11:53.377339 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kwAAKnM"]
[Thu Sep 17 15:11:53.377364 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3lAAAKng"]
[Thu Sep 17 15:11:53.377394 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3lgAAKgw"]
[Thu Sep 17 15:11:53.377419 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mAAAKg4"]
[Thu Sep 17 15:11:53.377443 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3lwAAKns"]
[Thu Sep 17 15:11:53.377467 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mQAAKhA"]
[Thu Sep 17 15:11:53.377491 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mgAAKhY"]
[Thu Sep 17 15:11:53.377514 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mwAAKhM"]
[Thu Sep 17 15:11:53.377541 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3nQAAKgU"]
[Thu Sep 17 15:11:53.377584 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3nAAAKhI"]
[Thu Sep 17 15:11:53.379551 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ngAAKg0"]
[Thu Sep 17 15:11:53.425622 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:22785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXmecL08BTTQixEno3owAAADQ"]
[Thu Sep 17 15:11:53.425781 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:22785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXmecL08BTTQixEno3owAAADQ"]
[Thu Sep 17 15:11:53.426087 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailjet/.env"] [unique_id "aqxXmecL08BTTQixEno3ogAAADg"]
[Thu Sep 17 15:11:53.497321 2026] [security2:error] [pid 971102:tid 971297] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/releases/.env"] [unique_id "aqxXmecL08BTTQixEno3pgAAAD8"]
[Thu Sep 17 15:11:53.558227 2026] [security2:error] [pid 971102:tid 971115] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/wp-config.backup.php"] [unique_id "aqxXmecL08BTTQixEno3qAAADws"]
[Thu Sep 17 15:11:53.561033 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3pwAADwc"]
[Thu Sep 17 15:11:53.561125 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3qQAADxg"]
[Thu Sep 17 15:11:53.561720 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rgAADwg"]
[Thu Sep 17 15:11:53.561963 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3qgAADwk"]
[Thu Sep 17 15:11:53.562155 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rAAADxE"]
[Thu Sep 17 15:11:53.562245 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3qwAADxc"]
[Thu Sep 17 15:11:53.562295 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rQAADxk"]
[Thu Sep 17 15:11:53.562331 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3sAAAD38"]
[Thu Sep 17 15:11:53.562368 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3sgAADyI"]
[Thu Sep 17 15:11:53.562520 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rwAADxQ"]
[Thu Sep 17 15:11:53.562566 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3swAADyA"]
[Thu Sep 17 15:11:53.562633 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3sQAADyE"]
[Thu Sep 17 15:11:53.562685 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3tAAADx0"]
[Thu Sep 17 15:11:53.562737 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3tQAADxs"]
[Thu Sep 17 15:11:53.563532 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3tgAADyQ"]
[Thu Sep 17 15:11:53.575512 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxXmecL08BTTQixEno3uQAAAGQ"]
[Thu Sep 17 15:11:53.575593 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:47104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxXmecL08BTTQixEno3uQAAAGQ"]
[Thu Sep 17 15:11:53.584826 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/brevo/.env"] [unique_id "aqxXmecL08BTTQixEno3ugAAADA"]
[Thu Sep 17 15:11:53.626579 2026] [security2:error] [pid 971102:tid 971273] [client 34.94.67.131:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3uwAAACc"]
[Thu Sep 17 15:11:53.654174 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/shared/.env"] [unique_id "aqxXmecL08BTTQixEno3vQAAAGg"]
[Thu Sep 17 15:11:53.744779 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3vwAAZiw"]
[Thu Sep 17 15:11:53.745571 2026] [security2:error] [pid 971102:tid 971135] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/vendor/.env"] [unique_id "aqxXmecL08BTTQixEno3wQAAZh8"]
[Thu Sep 17 15:11:53.746066 2026] [security2:error] [pid 971102:tid 971150] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/sites/default/settings.local.php"] [unique_id "aqxXmecL08BTTQixEno3yAAAZi4"]
[Thu Sep 17 15:11:53.746103 2026] [authz_core:error] [pid 971102:tid 971145] [remote 45.138.12.28:54158] AH01630: client denied by server configuration: /home1/perimev0/public_html/.htpasswd
[Thu Sep 17 15:11:53.746436 2026] [security2:error] [pid 971102:tid 971149] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/panel/.env"] [unique_id "aqxXmecL08BTTQixEno3yQAAZi0"]
[Thu Sep 17 15:11:53.747400 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.local.swp"] [unique_id "aqxXmecL08BTTQixEno3ygAAZjI"]
[Thu Sep 17 15:11:53.747701 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3wAAAZh4"]
[Thu Sep 17 15:11:53.747873 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xwAAZh8"]
[Thu Sep 17 15:11:53.747936 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3wwAAZiY"]
[Thu Sep 17 15:11:53.748018 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xAAAZhw"]
[Thu Sep 17 15:11:53.748084 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xgAAZnw"]
[Thu Sep 17 15:11:53.748144 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xQAAZjQ"]
[Thu Sep 17 15:11:53.748472 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ywAAZjU"]
[Thu Sep 17 15:11:53.810471 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/deploy/.env"] [unique_id "aqxXmecL08BTTQixEno3zAAAABc"]
[Thu Sep 17 15:11:53.834155 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/transactional/.env"] [unique_id "aqxXmecL08BTTQixEno3zgAAADk"]
[Thu Sep 17 15:11:53.866451 2026] [security2:error] [pid 971102:tid 971328] [client 34.94.67.131:43882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3zwAAAF4"]
[Thu Sep 17 15:11:53.871002 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxXmecL08BTTQixEno30AAAAG8"]
[Thu Sep 17 15:11:53.871076 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxXmecL08BTTQixEno30AAAAG8"]
[Thu Sep 17 15:11:53.965564 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/build/.env"] [unique_id "aqxXmecL08BTTQixEno31gAAAAE"]
[Thu Sep 17 15:11:54.079938 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/bulk/.env"] [unique_id "aqxXmucL08BTTQixEno33AAAADs"]
[Thu Sep 17 15:11:54.122353 2026] [security2:error] [pid 971102:tid 971243] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/dist/.env"] [unique_id "aqxXmucL08BTTQixEno33QAAAAk"]
[Thu Sep 17 15:11:54.152162 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxXmucL08BTTQixEno33gAAAGs"]
[Thu Sep 17 15:11:54.152260 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxXmucL08BTTQixEno33gAAAGs"]
[Thu Sep 17 15:11:54.291747 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/public_html/.env"] [unique_id "aqxXmucL08BTTQixEno35wAAAEA"]
[Thu Sep 17 15:11:54.318197 2026] [security2:error] [pid 971102:tid 971314] [client 50.67.73.198:58658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxXmucL08BTTQixEno34wAAUCg"]
[Thu Sep 17 15:11:54.319543 2026] [security2:error] [pid 971102:tid 971314] [client 50.67.73.198:58658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxXmucL08BTTQixEno34gAAUEE"]
[Thu Sep 17 15:11:54.400627 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/aws/.env"] [unique_id "aqxXmucL08BTTQixEno38AAAABY"]
[Thu Sep 17 15:11:54.447713 2026] [security2:error] [pid 971102:tid 971267] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/htdocs/.env"] [unique_id "aqxXmucL08BTTQixEno38QAAACE"]
[Thu Sep 17 15:11:54.462293 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxXmucL08BTTQixEno38wAAAB8"]
[Thu Sep 17 15:11:54.462402 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxXmucL08BTTQixEno38wAAAB8"]
[Thu Sep 17 15:11:54.545525 2026] [security2:error] [pid 971102:tid 971236] [client 34.94.67.131:43898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXmucL08BTTQixEno39gAAAAI"]
[Thu Sep 17 15:11:54.603601 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/www/.env"] [unique_id "aqxXmucL08BTTQixEno3-gAAABo"]
[Thu Sep 17 15:11:54.750779 2026] [security2:error] [pid 971102:tid 971335] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/azure/.env"] [unique_id "aqxXmucL08BTTQixEno4AQAAAGU"]
[Thu Sep 17 15:11:54.767533 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/html/.env"] [unique_id "aqxXmucL08BTTQixEno4AgAAAFI"]
[Thu Sep 17 15:11:54.831571 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:47150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxXmucL08BTTQixEno4BQAAADE"]
[Thu Sep 17 15:11:54.831655 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:47150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxXmucL08BTTQixEno4BQAAADE"]
[Thu Sep 17 15:11:54.925441 2026] [security2:error] [pid 971102:tid 971268] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/live/.env"] [unique_id "aqxXmucL08BTTQixEno4CAAAACI"]
[Thu Sep 17 15:11:55.014578 2026] [security2:error] [pid 971102:tid 971264] [client 186.105.232.15:52766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXm-cL08BTTQixEno4DAAAAB4"]
[Thu Sep 17 15:11:55.014703 2026] [security2:error] [pid 971102:tid 971264] [client 186.105.232.15:52766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXm-cL08BTTQixEno4DAAAAB4"]
[Thu Sep 17 15:11:55.052483 2026] [security2:error] [pid 971102:tid 971346] [client 5.189.145.112:64709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxXm-cL08BTTQixEno4DQAAAHA"], referer: binance.com
[Thu Sep 17 15:11:55.070828 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/gcp/.env"] [unique_id "aqxXm-cL08BTTQixEno4DgAAAGY"]
[Thu Sep 17 15:11:55.080166 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/prod/.env"] [unique_id "aqxXm-cL08BTTQixEno4DwAAABc"]
[Thu Sep 17 15:11:55.103740 2026] [security2:error] [pid 971102:tid 971248] [client 34.94.67.131:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXm-cL08BTTQixEno4EAAAAA4"]
[Thu Sep 17 15:11:55.123085 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:47156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4FAAAAH4"]
[Thu Sep 17 15:11:55.123161 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:47156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4FAAAAH4"]
[Thu Sep 17 15:11:55.129045 2026] [autoindex:error] [pid 971102:tid 971357] [client 157.66.54.188:55162] AH01276: Cannot serve directory /home4/jthomps4/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:11:55.241138 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/dev/.env"] [unique_id "aqxXm-cL08BTTQixEno4GgAAAHw"]
[Thu Sep 17 15:11:55.285038 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cloud/.env"] [unique_id "aqxXm-cL08BTTQixEno4GwAAADY"]
[Thu Sep 17 15:11:55.367717 2026] [security2:error] [pid 971102:tid 971279] [client 34.94.67.131:43918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXm-cL08BTTQixEno4HAAAAC0"]
[Thu Sep 17 15:11:55.395053 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/staging/.env"] [unique_id "aqxXm-cL08BTTQixEno4HQAAADs"]
[Thu Sep 17 15:11:55.399511 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:47168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4HgAAAAk"]
[Thu Sep 17 15:11:55.399571 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:47168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4HgAAAAk"]
[Thu Sep 17 15:11:55.478824 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/infrastructure/.env"] [unique_id "aqxXm-cL08BTTQixEno4IwAAAEc"]
[Thu Sep 17 15:11:55.550689 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/opt/.env"] [unique_id "aqxXm-cL08BTTQixEno4JQAAAAw"]
[Thu Sep 17 15:11:55.679196 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:47184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4KwAAAEI"]
[Thu Sep 17 15:11:55.679298 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:47184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4KwAAAEI"]
[Thu Sep 17 15:11:55.710288 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/laravel/.env"] [unique_id "aqxXm-cL08BTTQixEno4LgAAAHE"]
[Thu Sep 17 15:11:55.713345 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/docker/.env"] [unique_id "aqxXm-cL08BTTQixEno4LwAAACU"]
[Thu Sep 17 15:11:55.777678 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.67.131:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXm-cL08BTTQixEno4MQAAAC4"]
[Thu Sep 17 15:11:55.867322 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/symfony/.env"] [unique_id "aqxXm-cL08BTTQixEno4NAAAAFw"]
[Thu Sep 17 15:11:55.969293 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:47192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4NQAAAFU"]
[Thu Sep 17 15:11:55.969378 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:47192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4NQAAAFU"]
[Thu Sep 17 15:11:56.149148 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/k8s/.env"] [unique_id "aqxXnOcL08BTTQixEno4OwAAAH8"]
[Thu Sep 17 15:11:56.151632 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.67.131:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4PAAAACA"]
[Thu Sep 17 15:11:56.214586 2026] [autoindex:error] [pid 971102:tid 971359] [client 157.66.54.188:55162] AH01276: Cannot serve directory /home4/jthomps4/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:11:56.247541 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:47202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4PgAAAHo"]
[Thu Sep 17 15:11:56.247632 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:47202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4PgAAAHo"]
[Thu Sep 17 15:11:56.322874 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/wordpress/.env"] [unique_id "aqxXnOcL08BTTQixEno4QgAAAFI"]
[Thu Sep 17 15:11:56.394201 2026] [security2:error] [pid 971102:tid 971297] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/kubernetes/.env"] [unique_id "aqxXnOcL08BTTQixEno4RgAAAD8"]
[Thu Sep 17 15:11:56.473751 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/wp/.env"] [unique_id "aqxXnOcL08BTTQixEno4RwAAABM"]
[Thu Sep 17 15:11:56.512269 2026] [security2:error] [pid 971102:tid 971285] [client 210.222.43.21:64921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXnOcL08BTTQixEno4RQAAADM"], referer: http://talent-in-borders.com/WWW
[Thu Sep 17 15:11:56.518420 2026] [security2:error] [pid 971102:tid 971286] [client 34.94.67.131:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4SQAAADQ"]
[Thu Sep 17 15:11:56.560043 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4TAAAAGI"]
[Thu Sep 17 15:11:56.560136 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:47212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4TAAAAGI"]
[Thu Sep 17 15:11:56.622641 2026] [security2:error] [pid 971102:tid 971320] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cms/.env"] [unique_id "aqxXnOcL08BTTQixEno4UQAAAFY"]
[Thu Sep 17 15:11:56.710234 2026] [security2:error] [pid 971102:tid 971277] [client 154.190.208.131:41708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnOcL08BTTQixEno4UwAAACs"]
[Thu Sep 17 15:11:56.714352 2026] [security2:error] [pid 971102:tid 971277] [client 154.190.208.131:41708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnOcL08BTTQixEno4UwAAACs"]
[Thu Sep 17 15:11:56.751913 2026] [security2:error] [pid 971102:tid 971328] [client 34.94.67.131:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4VQAAAF4"]
[Thu Sep 17 15:11:56.773512 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/drupal/.env"] [unique_id "aqxXnOcL08BTTQixEno4VgAAAGo"]
[Thu Sep 17 15:11:56.853513 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:47214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4VwAAAFk"]
[Thu Sep 17 15:11:56.853598 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:47214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4VwAAAFk"]
[Thu Sep 17 15:11:56.856113 2026] [security2:error] [pid 971102:tid 971235] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxXnOcL08BTTQixEno4WAAAAAE"]
[Thu Sep 17 15:11:56.924712 2026] [security2:error] [pid 971102:tid 971252] [client 34.94.67.131:43948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4XAAAABI"]
[Thu Sep 17 15:11:56.926645 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/joomla/.env"] [unique_id "aqxXnOcL08BTTQixEno4XQAAADY"]
[Thu Sep 17 15:11:57.075878 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/magento/.env"] [unique_id "aqxXnecL08BTTQixEno4YQAAAHg"]
[Thu Sep 17 15:11:57.084886 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxXnecL08BTTQixEno4YwAAAG8"]
[Thu Sep 17 15:11:57.169414 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxXnecL08BTTQixEno4ZAAAADk"]
[Thu Sep 17 15:11:57.169499 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxXnecL08BTTQixEno4ZAAAADk"]
[Thu Sep 17 15:11:57.174839 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/terraform/.env"] [unique_id "aqxXnecL08BTTQixEno4ZQAAAFE"]
[Thu Sep 17 15:11:57.223979 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/shopify/.env"] [unique_id "aqxXnecL08BTTQixEno4ZwAAAEA"]
[Thu Sep 17 15:11:57.261213 2026] [security2:error] [pid 971102:tid 971341] [client 34.94.67.131:43962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXnecL08BTTQixEno4aAAAAGs"]
[Thu Sep 17 15:11:57.372760 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/prestashop/.env"] [unique_id "aqxXnecL08BTTQixEno4bQAAAEo"]
[Thu Sep 17 15:11:57.473897 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxXnecL08BTTQixEno4cAAAAB8"]
[Thu Sep 17 15:11:57.474032 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxXnecL08BTTQixEno4cAAAAB8"]
[Thu Sep 17 15:11:57.512070 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.67.131:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/core/phpinfo.php"] [unique_id "aqxXnecL08BTTQixEno4cQAAAHM"]
[Thu Sep 17 15:11:57.521909 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/codeigniter/.env"] [unique_id "aqxXnecL08BTTQixEno4cgAAAE8"]
[Thu Sep 17 15:11:57.575241 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/ansible/.env"] [unique_id "aqxXnecL08BTTQixEno4cwAAAAc"]
[Thu Sep 17 15:11:57.675776 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cakephp/.env"] [unique_id "aqxXnecL08BTTQixEno4eAAAAFw"]
[Thu Sep 17 15:11:57.737023 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.67.131:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxXnecL08BTTQixEno4egAAAAA"]
[Thu Sep 17 15:11:57.744986 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.git/.env"] [unique_id "aqxXnecL08BTTQixEno4ewAAACQ"]
[Thu Sep 17 15:11:57.754542 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxXnecL08BTTQixEno4fQAAAD0"]
[Thu Sep 17 15:11:57.754621 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:47232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxXnecL08BTTQixEno4fQAAAD0"]
[Thu Sep 17 15:11:57.825688 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/zend/.env"] [unique_id "aqxXnecL08BTTQixEno4gAAAAH0"]
[Thu Sep 17 15:11:57.932320 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/ci/.env"] [unique_id "aqxXnecL08BTTQixEno4gQAAAG0"]
[Thu Sep 17 15:11:57.951511 2026] [security2:error] [pid 971102:tid 971361] [client 114.119.132.183:64547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtbclubdecampo.com"] [uri "/Rutas/Alto_Tajo/alto_tajo.plt"] [unique_id "aqxXnecL08BTTQixEno4ggAAAH8"], referer: https://mtbclubdecampo.com/Rutas/Alto_Tajo/alto_tajo.plt
[Thu Sep 17 15:11:57.975366 2026] [security2:error] [pid 971102:tid 971330] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/yii/.env"] [unique_id "aqxXnecL08BTTQixEno4gwAAAGA"]
[Thu Sep 17 15:11:58.072974 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:47234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxXnucL08BTTQixEno4hwAAAEs"]
[Thu Sep 17 15:11:58.073075 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:47234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxXnucL08BTTQixEno4hwAAAEs"]
[Thu Sep 17 15:11:58.129995 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/laravel5/.env"] [unique_id "aqxXnucL08BTTQixEno4iwAAABM"]
[Thu Sep 17 15:11:58.181721 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cd/.env"] [unique_id "aqxXnucL08BTTQixEno4jAAAAGI"]
[Thu Sep 17 15:11:58.284916 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/v1/.env"] [unique_id "aqxXnucL08BTTQixEno4jwAAAEk"]
[Thu Sep 17 15:11:58.362045 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxXnucL08BTTQixEno4kQAAACI"]
[Thu Sep 17 15:11:58.362156 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxXnucL08BTTQixEno4kQAAACI"]
[Thu Sep 17 15:11:58.390340 2026] [security2:error] [pid 971102:tid 971269] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/jenkins/.env"] [unique_id "aqxXnucL08BTTQixEno4kwAAACM"]
[Thu Sep 17 15:11:58.443431 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/v2/.env"] [unique_id "aqxXnucL08BTTQixEno4mQAAAHs"]
[Thu Sep 17 15:11:58.602170 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/v3/.env"] [unique_id "aqxXnucL08BTTQixEno4rQAAAHk"]
[Thu Sep 17 15:11:58.647591 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxXnucL08BTTQixEno4sgAAAHU"]
[Thu Sep 17 15:11:58.647687 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:47260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxXnucL08BTTQixEno4sgAAAHU"]
[Thu Sep 17 15:11:58.647901 2026] [security2:error] [pid 971102:tid 971250] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/gitlab/.env"] [unique_id "aqxXnucL08BTTQixEno4sQAAABA"]
[Thu Sep 17 15:11:58.754104 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/v1/.env"] [unique_id "aqxXnucL08BTTQixEno4ugAAABw"]
[Thu Sep 17 15:11:58.809640 2026] [security2:error] [pid 971102:tid 971259] [client 45.169.98.18:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnucL08BTTQixEno4vQAAABk"]
[Thu Sep 17 15:11:58.809779 2026] [security2:error] [pid 971102:tid 971259] [client 45.169.98.18:57415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnucL08BTTQixEno4vQAAABk"]
[Thu Sep 17 15:11:58.816720 2026] [security2:error] [pid 971102:tid 971344] [client 157.66.54.188:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.54.66.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qja.nnk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "aqxXnucL08BTTQixEno4uAAAAG4"]
[Thu Sep 17 15:11:58.818955 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/github/.env"] [unique_id "aqxXnucL08BTTQixEno4xgAAAFA"]
[Thu Sep 17 15:11:58.906976 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/v2/.env"] [unique_id "aqxXnucL08BTTQixEno4yAAAAAw"]
[Thu Sep 17 15:11:58.932011 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:47266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxXnucL08BTTQixEno4ywAAAEc"]
[Thu Sep 17 15:11:59.059199 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/rest/.env"] [unique_id "aqxXn-cL08BTTQixEno41QAAAFg"]
[Thu Sep 17 15:11:59.106859 2026] [security2:error] [pid 971102:tid 971274] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/actions/.env"] [unique_id "aqxXn-cL08BTTQixEno42AAAACg"]
[Thu Sep 17 15:11:59.219745 2026] [security2:error] [pid 971102:tid 971350] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/graphql/.env"] [unique_id "aqxXn-cL08BTTQixEno44AAAAHQ"]
[Thu Sep 17 15:11:59.263943 2026] [security2:error] [pid 971102:tid 971242] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno43QAAAAg"]
[Thu Sep 17 15:11:59.277204 2026] [security2:error] [pid 971102:tid 971283] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/circleci/.env"] [unique_id "aqxXn-cL08BTTQixEno44gAAADE"]
[Thu Sep 17 15:11:59.368447 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/gateway/.env"] [unique_id "aqxXn-cL08BTTQixEno45QAAAG0"]
[Thu Sep 17 15:11:59.387547 2026] [authz_core:error] [pid 971102:tid 971263] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/fields/error_log
[Thu Sep 17 15:11:59.389426 2026] [security2:error] [pid 971102:tid 971263] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxXn-cL08BTTQixEno45AAAAB0"]
[Thu Sep 17 15:11:59.499904 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/travis/.env"] [unique_id "aqxXn-cL08BTTQixEno47AAAAE0"]
[Thu Sep 17 15:11:59.518275 2026] [security2:error] [pid 971102:tid 971238] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/microservice/.env"] [unique_id "aqxXn-cL08BTTQixEno47QAAAAQ"]
[Thu Sep 17 15:11:59.533983 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:47266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/wp-includes/rest-api/"] [unique_id "aqxXn-cL08BTTQixEno47gAAAF8"]
[Thu Sep 17 15:11:59.615196 2026] [security2:error] [pid 971102:tid 971335] [client 162.241.226.11:40806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxXnucL08BTTQixEno4rAAAAGo"]
[Thu Sep 17 15:11:59.675309 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/buildkite/.env"] [unique_id "aqxXn-cL08BTTQixEno49AAAACY"]
[Thu Sep 17 15:11:59.683630 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/service/.env"] [unique_id "aqxXn-cL08BTTQixEno49QAAAEk"]
[Thu Sep 17 15:11:59.747958 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxXn-cL08BTTQixEno4-QAAACM"]
[Thu Sep 17 15:11:59.822837 2026] [security2:error] [pid 971102:tid 971294] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno49wAAADw"]
[Thu Sep 17 15:11:59.837196 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/v3/.env"] [unique_id "aqxXn-cL08BTTQixEno4-wAAAHs"]
[Thu Sep 17 15:11:59.912427 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno48wAAAGg"]
[Thu Sep 17 15:11:59.912451 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno48wAAAGg"]
[Thu Sep 17 15:11:59.923997 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mysql/.env"] [unique_id "aqxXn-cL08BTTQixEno4_QAAACs"]
[Thu Sep 17 15:11:59.984559 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxXn-cL08BTTQixEno4_gAAABc"]
[Thu Sep 17 15:11:59.995336 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/dev/.env"] [unique_id "aqxXn-cL08BTTQixEno4_wAAABE"]
[Thu Sep 17 15:12:00.147936 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/staging/.env"] [unique_id "aqxXoOcL08BTTQixEno5AgAAABU"]
[Thu Sep 17 15:12:00.201494 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:47266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5FAAAABw"]
[Thu Sep 17 15:12:00.201586 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:47266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5FAAAABw"]
[Thu Sep 17 15:12:00.218311 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxXoOcL08BTTQixEno5FQAAADs"]
[Thu Sep 17 15:12:00.272280 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/postgres/.env"] [unique_id "aqxXoOcL08BTTQixEno5FwAAABI"]
[Thu Sep 17 15:12:00.298135 2026] [security2:error] [pid 971102:tid 971288] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoOcL08BTTQixEno5FgAAADY"]
[Thu Sep 17 15:12:00.299411 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/vendor/.env"] [unique_id "aqxXoOcL08BTTQixEno5GAAAAG8"]
[Thu Sep 17 15:12:00.447703 2026] [security2:error] [pid 971102:tid 971314] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxXoOcL08BTTQixEno5HQAAAFA"]
[Thu Sep 17 15:12:00.452769 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/lib/.env"] [unique_id "aqxXoOcL08BTTQixEno5HgAAAEA"]
[Thu Sep 17 15:12:00.488096 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5HwAAAGs"]
[Thu Sep 17 15:12:00.488207 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5HwAAAGs"]
[Thu Sep 17 15:12:00.615546 2026] [security2:error] [pid 971102:tid 971310] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/resources/.env"] [unique_id "aqxXoOcL08BTTQixEno5IQAAAEw"]
[Thu Sep 17 15:12:00.659867 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mongodb/.env"] [unique_id "aqxXoOcL08BTTQixEno5IgAAAAw"]
[Thu Sep 17 15:12:00.675027 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/site/.env"] [unique_id "aqxXoOcL08BTTQixEno5JQAAADU"]
[Thu Sep 17 15:12:00.765363 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5JwAAABs"]
[Thu Sep 17 15:12:00.765476 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:47652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5JwAAABs"]
[Thu Sep 17 15:12:00.769507 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/assets/.env"] [unique_id "aqxXoOcL08BTTQixEno5KAAAAEc"]
[Thu Sep 17 15:12:00.825626 2026] [security2:error] [pid 971102:tid 971268] [client 162.241.226.11:40812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno4-AAAACI"]
[Thu Sep 17 15:12:00.870712 2026] [security2:error] [pid 971102:tid 971323] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoOcL08BTTQixEno5NAAAAFk"]
[Thu Sep 17 15:12:00.903582 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxXoOcL08BTTQixEno5NwAAAAc"]
[Thu Sep 17 15:12:00.921734 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/uploads/.env"] [unique_id "aqxXoOcL08BTTQixEno5OAAAADI"]
[Thu Sep 17 15:12:00.972980 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/redis/.env"] [unique_id "aqxXoOcL08BTTQixEno5OQAAAFw"]
[Thu Sep 17 15:12:01.066389 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5OgAAABY"]
[Thu Sep 17 15:12:01.066545 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5OgAAABY"]
[Thu Sep 17 15:12:01.073931 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/internal/.env"] [unique_id "aqxXoecL08BTTQixEno5OwAAAFg"]
[Thu Sep 17 15:12:01.224841 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/tools/.env"] [unique_id "aqxXoecL08BTTQixEno5RgAAAAg"]
[Thu Sep 17 15:12:01.225790 2026] [security2:error] [pid 971102:tid 971358] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoecL08BTTQixEno5PQAAAHw"]
[Thu Sep 17 15:12:01.271616 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/elasticsearch/.env"] [unique_id "aqxXoecL08BTTQixEno5SAAAABo"]
[Thu Sep 17 15:12:01.337034 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:64822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5SQAAAFc"]
[Thu Sep 17 15:12:01.337965 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:64822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5SQAAAFc"]
[Thu Sep 17 15:12:01.353249 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5SgAAAA0"]
[Thu Sep 17 15:12:01.353357 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:47670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5SgAAAA0"]
[Thu Sep 17 15:12:01.376430 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/scripts/.env"] [unique_id "aqxXoecL08BTTQixEno5SwAAACQ"]
[Thu Sep 17 15:12:01.407767 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxXoecL08BTTQixEno5TAAAACw"]
[Thu Sep 17 15:12:01.527203 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/bin/.env"] [unique_id "aqxXoecL08BTTQixEno5TwAAAG0"]
[Thu Sep 17 15:12:01.636022 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxXoecL08BTTQixEno5UgAAAE0"]
[Thu Sep 17 15:12:01.636574 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:47674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxXoecL08BTTQixEno5UwAAAFI"]
[Thu Sep 17 15:12:01.675636 2026] [security2:error] [pid 971102:tid 971312] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sbin/.env"] [unique_id "aqxXoecL08BTTQixEno5VAAAAE4"]
[Thu Sep 17 15:12:01.693169 2026] [security2:error] [pid 971102:tid 971239] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoecL08BTTQixEno5UQAAAAU"]
[Thu Sep 17 15:12:01.745452 2026] [security2:error] [pid 971102:tid 971263] [client 185.55.149.49:64646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5VwAAAB0"]
[Thu Sep 17 15:12:01.746461 2026] [security2:error] [pid 971102:tid 971263] [client 185.55.149.49:64646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5VwAAAB0"]
[Thu Sep 17 15:12:01.798199 2026] [authz_core:error] [pid 971102:tid 971286] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/search/error_log
[Thu Sep 17 15:12:01.799419 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxXoecL08BTTQixEno5WQAAADQ"]
[Thu Sep 17 15:12:01.826825 2026] [security2:error] [pid 971102:tid 971273] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/local/.env"] [unique_id "aqxXoecL08BTTQixEno5WgAAACc"]
[Thu Sep 17 15:12:01.842931 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/rabbitmq/.env"] [unique_id "aqxXoecL08BTTQixEno5WwAAACY"]
[Thu Sep 17 15:12:01.864331 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxXoecL08BTTQixEno5XAAAACM"]
[Thu Sep 17 15:12:01.941307 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:47674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/wp-includes/rest-api/"] [unique_id "aqxXoecL08BTTQixEno5XwAAAGI"]
[Thu Sep 17 15:12:01.981871 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/portal/.env"] [unique_id "aqxXoecL08BTTQixEno5YAAAAGg"]
[Thu Sep 17 15:12:02.096621 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxXoucL08BTTQixEno5ZAAAADg"]
[Thu Sep 17 15:12:02.116626 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/kafka/.env"] [unique_id "aqxXoucL08BTTQixEno5ZQAAABM"]
[Thu Sep 17 15:12:02.131621 2026] [security2:error] [pid 971102:tid 971307] [client 115.244.164.14:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoucL08BTTQixEno5ZgAAAEk"]
[Thu Sep 17 15:12:02.131764 2026] [security2:error] [pid 971102:tid 971307] [client 115.244.164.14:52805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoucL08BTTQixEno5ZgAAAEk"]
[Thu Sep 17 15:12:02.133336 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/dashboard/.env"] [unique_id "aqxXoucL08BTTQixEno5ZwAAABE"]
[Thu Sep 17 15:12:02.285246 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/panel/.env"] [unique_id "aqxXoucL08BTTQixEno5awAAACk"]
[Thu Sep 17 15:12:02.308944 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5YgAAADM"]
[Thu Sep 17 15:12:02.308977 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5YgAAADM"]
[Thu Sep 17 15:12:02.314009 2026] [security2:error] [pid 971102:tid 971355] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5agAAAHk"]
[Thu Sep 17 15:12:02.324844 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/core/.env"] [unique_id "aqxXoucL08BTTQixEno5bAAAAFY"]
[Thu Sep 17 15:12:02.399701 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/queue/.env"] [unique_id "aqxXoucL08BTTQixEno5bQAAABw"]
[Thu Sep 17 15:12:02.435988 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/crm/.env"] [unique_id "aqxXoucL08BTTQixEno5bwAAADY"]
[Thu Sep 17 15:12:02.454196 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5cAAAAG8"]
[Thu Sep 17 15:12:02.454275 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5cAAAAG8"]
[Thu Sep 17 15:12:02.558301 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/core/app/.env"] [unique_id "aqxXoucL08BTTQixEno5dwAAADU"]
[Thu Sep 17 15:12:02.586315 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/erp/.env"] [unique_id "aqxXoucL08BTTQixEno5eAAAAA4"]
[Thu Sep 17 15:12:02.613281 2026] [security2:error] [pid 971102:tid 971310] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5dgAAAEw"]
[Thu Sep 17 15:12:02.621082 2026] [security2:error] [pid 971102:tid 971268] [client 5.189.145.112:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxXoucL08BTTQixEno5eQAAACI"], referer: binance.com
[Thu Sep 17 15:12:02.731552 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5egAAACU"]
[Thu Sep 17 15:12:02.731653 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5egAAACU"]
[Thu Sep 17 15:12:02.737790 2026] [security2:error] [pid 971102:tid 971280] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/shop/.env"] [unique_id "aqxXoucL08BTTQixEno5ewAAAC4"]
[Thu Sep 17 15:12:02.791842 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxXoucL08BTTQixEno5fgAAAAM"]
[Thu Sep 17 15:12:02.887200 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/store/.env"] [unique_id "aqxXoucL08BTTQixEno5gAAAAEo"]
[Thu Sep 17 15:12:03.020670 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/private/.env"] [unique_id "aqxXo-cL08BTTQixEno5hQAAAAI"]
[Thu Sep 17 15:12:03.027562 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/worker/.env"] [unique_id "aqxXo-cL08BTTQixEno5hgAAAAA"]
[Thu Sep 17 15:12:03.027754 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:47682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5hwAAAE8"]
[Thu Sep 17 15:12:03.027823 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:47682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5hwAAAE8"]
[Thu Sep 17 15:12:03.039798 2026] [security2:error] [pid 971102:tid 971303] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/saas/.env"] [unique_id "aqxXo-cL08BTTQixEno5iAAAAEU"]
[Thu Sep 17 15:12:03.058361 2026] [security2:error] [pid 971102:tid 971256] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5hAAAABY"]
[Thu Sep 17 15:12:03.192158 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/client/.env"] [unique_id "aqxXo-cL08BTTQixEno5jAAAABo"]
[Thu Sep 17 15:12:03.240474 2026] [security2:error] [pid 971102:tid 971359] [client 84.233.195.159:63819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXo-cL08BTTQixEno5kQAAAH0"]
[Thu Sep 17 15:12:03.249105 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxXo-cL08BTTQixEno5kgAAAFc"]
[Thu Sep 17 15:12:03.279755 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/job/.env"] [unique_id "aqxXo-cL08BTTQixEno5kwAAAA0"]
[Thu Sep 17 15:12:03.316705 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:47684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5lQAAAFs"]
[Thu Sep 17 15:12:03.316780 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:47684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5lQAAAFs"]
[Thu Sep 17 15:12:03.340904 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/project/.env"] [unique_id "aqxXo-cL08BTTQixEno5lwAAAEY"]
[Thu Sep 17 15:12:03.394356 2026] [security2:error] [pid 971102:tid 971343] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXo-cL08BTTQixEno5lgAAAG0"]
[Thu Sep 17 15:12:03.478975 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/bootstrap/.env"] [unique_id "aqxXo-cL08BTTQixEno5mwAAAHM"]
[Thu Sep 17 15:12:03.497114 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/admin-panel/.env"] [unique_id "aqxXo-cL08BTTQixEno5nAAAAAU"]
[Thu Sep 17 15:12:03.497114 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/test/.env"] [unique_id "aqxXo-cL08BTTQixEno5nQAAAGo"]
[Thu Sep 17 15:12:03.613716 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxXo-cL08BTTQixEno5nwAAADQ"]
[Thu Sep 17 15:12:03.651149 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/control-panel/.env"] [unique_id "aqxXo-cL08BTTQixEno5oAAAACY"]
[Thu Sep 17 15:12:03.682090 2026] [security2:error] [pid 971102:tid 971273] [client 162.241.226.11:16956] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXo-cL08BTTQixEno5oQAAACc"]
[Thu Sep 17 15:12:03.707214 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/database/.env"] [unique_id "aqxXo-cL08BTTQixEno5pAAAAEg"]
[Thu Sep 17 15:12:03.737669 2026] [security2:error] [pid 971102:tid 971263] [client 84.233.195.149:52335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXo-cL08BTTQixEno5pQAAAB0"]
[Thu Sep 17 15:12:03.765976 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/qa/.env"] [unique_id "aqxXo-cL08BTTQixEno5qAAAAF8"]
[Thu Sep 17 15:12:03.773294 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxXo-cL08BTTQixEno5pgAAAH8"]
[Thu Sep 17 15:12:03.813621 2026] [security2:error] [pid 971102:tid 971296] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/user-panel/.env"] [unique_id "aqxXo-cL08BTTQixEno5qgAAAD4"]
[Thu Sep 17 15:12:03.911571 2026] [security2:error] [pid 971102:tid 971327] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXo-cL08BTTQixEno5qwAAAF0"]
[Thu Sep 17 15:12:03.917180 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxXo-cL08BTTQixEno5rAAAABU"]
[Thu Sep 17 15:12:03.934543 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/storage/.env"] [unique_id "aqxXo-cL08BTTQixEno5rQAAAHU"]
[Thu Sep 17 15:12:03.969898 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/node/.env"] [unique_id "aqxXo-cL08BTTQixEno5rgAAAHs"]
[Thu Sep 17 15:12:04.073480 2026] [authz_core:error] [pid 971102:tid 971318] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sitemaps/providers/error_log
[Thu Sep 17 15:12:04.074289 2026] [security2:error] [pid 971102:tid 971318] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxXpOcL08BTTQixEno5sgAAAFQ"]
[Thu Sep 17 15:12:04.078418 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/preview/.env"] [unique_id "aqxXpOcL08BTTQixEno5swAAABw"]
[Thu Sep 17 15:12:04.121137 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/express/.env"] [unique_id "aqxXpOcL08BTTQixEno5twAAAG8"]
[Thu Sep 17 15:12:04.158133 2026] [core:error] [pid 971102:tid 971314] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:04.158150 2026] [core:error] [pid 971102:tid 971314] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:04.164624 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxXpOcL08BTTQixEno5uwAAAEA"]
[Thu Sep 17 15:12:04.224322 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/wp-includes/sitemaps/"] [unique_id "aqxXpOcL08BTTQixEno5vgAAABg"]
[Thu Sep 17 15:12:04.245225 2026] [security2:error] [pid 971102:tid 971293] [client 84.233.195.157:54932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpOcL08BTTQixEno5wAAAADs"]
[Thu Sep 17 15:12:04.275601 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/next/.env"] [unique_id "aqxXpOcL08BTTQixEno5wQAAAHg"]
[Thu Sep 17 15:12:04.350291 2026] [security2:error] [pid 971102:tid 971287] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno5wgAAADU"]
[Thu Sep 17 15:12:04.396713 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxXpOcL08BTTQixEno5xAAAABs"]
[Thu Sep 17 15:12:04.428616 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/nuxt/.env"] [unique_id "aqxXpOcL08BTTQixEno5xQAAAB4"]
[Thu Sep 17 15:12:04.469497 2026] [security2:error] [pid 971102:tid 971328] [client 57.141.14.108:65094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXo-cL08BTTQixEno5qQAAXhM"]
[Thu Sep 17 15:12:04.469724 2026] [security2:error] [pid 971102:tid 971243] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/beta/.env"] [unique_id "aqxXpOcL08BTTQixEno5yQAAAAk"]
[Thu Sep 17 15:12:04.554409 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno5wwAAABI"]
[Thu Sep 17 15:12:04.554432 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno5wwAAABI"]
[Thu Sep 17 15:12:04.587710 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/nest/.env"] [unique_id "aqxXpOcL08BTTQixEno5ygAAADI"]
[Thu Sep 17 15:12:04.630482 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxXpOcL08BTTQixEno5zwAAADE"]
[Thu Sep 17 15:12:04.697415 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxXpOcL08BTTQixEno50QAAACg"]
[Thu Sep 17 15:12:04.697547 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxXpOcL08BTTQixEno50QAAACg"]
[Thu Sep 17 15:12:04.743459 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/react/.env"] [unique_id "aqxXpOcL08BTTQixEno51gAAAE8"]
[Thu Sep 17 15:12:04.759834 2026] [security2:error] [pid 971102:tid 971322] [client 84.233.195.153:57872] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpOcL08BTTQixEno52AAAAFg"]
[Thu Sep 17 15:12:04.782654 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/uat/.env"] [unique_id "aqxXpOcL08BTTQixEno52QAAABY"]
[Thu Sep 17 15:12:04.815766 2026] [security2:error] [pid 971102:tid 971234] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno51QAAAAA"]
[Thu Sep 17 15:12:04.865529 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/release/.env"] [unique_id "aqxXpOcL08BTTQixEno52gAAABo"]
[Thu Sep 17 15:12:04.876488 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.130.148:44820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXpOcL08BTTQixEno52wAAAGk"]
[Thu Sep 17 15:12:04.892611 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/vue/.env"] [unique_id "aqxXpOcL08BTTQixEno53AAAAH0"]
[Thu Sep 17 15:12:04.963354 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/stage/.env"] [unique_id "aqxXpOcL08BTTQixEno53gAAAFU"]
[Thu Sep 17 15:12:04.978975 2026] [security2:error] [pid 971102:tid 971240] [client 104.28.198.244:22856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpOcL08BTTQixEno53QAAAAY"]
[Thu Sep 17 15:12:04.979090 2026] [security2:error] [pid 971102:tid 971240] [client 104.28.198.244:22856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpOcL08BTTQixEno53QAAAAY"]
[Thu Sep 17 15:12:04.982070 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxXpOcL08BTTQixEno53wAAACw"]
[Thu Sep 17 15:12:04.982167 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:47708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxXpOcL08BTTQixEno53wAAACw"]
[Thu Sep 17 15:12:05.048201 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/angular/.env"] [unique_id "aqxXpecL08BTTQixEno54AAAAG0"]
[Thu Sep 17 15:12:05.093811 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/releases/.env"] [unique_id "aqxXpecL08BTTQixEno54wAAAEM"]
[Thu Sep 17 15:12:05.178651 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/development/.env"] [unique_id "aqxXpecL08BTTQixEno55AAAAGo"]
[Thu Sep 17 15:12:05.207507 2026] [security2:error] [pid 971102:tid 971330] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/svelte/.env"] [unique_id "aqxXpecL08BTTQixEno55wAAAGA"]
[Thu Sep 17 15:12:05.249800 2026] [security2:error] [pid 971102:tid 971244] [client 84.233.195.152:53379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpecL08BTTQixEno56wAAAAo"]
[Thu Sep 17 15:12:05.264387 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxXpecL08BTTQixEno57QAAAEg"]
[Thu Sep 17 15:12:05.264466 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxXpecL08BTTQixEno57QAAAEg"]
[Thu Sep 17 15:12:05.326185 2026] [security2:error] [pid 971102:tid 971277] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/shared/.env"] [unique_id "aqxXpecL08BTTQixEno59AAAACs"]
[Thu Sep 17 15:12:05.362299 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/vite/.env"] [unique_id "aqxXpecL08BTTQixEno59QAAAF8"]
[Thu Sep 17 15:12:05.474828 2026] [security2:error] [pid 971102:tid 971336] [client 169.58.197.253:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxXpecL08BTTQixEno5-QAAAGY"], referer: binance.com
[Thu Sep 17 15:12:05.508405 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/production/.env"] [unique_id "aqxXpecL08BTTQixEno5-gAAABU"]
[Thu Sep 17 15:12:05.524832 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/backup/.env"] [unique_id "aqxXpecL08BTTQixEno5-wAAADw"]
[Thu Sep 17 15:12:05.561905 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/deploy/.env"] [unique_id "aqxXpecL08BTTQixEno6AAAAAFQ"]
[Thu Sep 17 15:12:05.563958 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.130.148:44826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXpecL08BTTQixEno6AQAAAAc"]
[Thu Sep 17 15:12:05.571987 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:47720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxXpecL08BTTQixEno6AgAAABw"]
[Thu Sep 17 15:12:05.678409 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/backups/.env"] [unique_id "aqxXpecL08BTTQixEno6BgAAADg"]
[Thu Sep 17 15:12:05.733190 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/config/app/.env"] [unique_id "aqxXpecL08BTTQixEno6CQAAADs"]
[Thu Sep 17 15:12:05.733306 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxXpecL08BTTQixEno6CAAAAFo"]
[Thu Sep 17 15:12:05.736933 2026] [security2:error] [pid 971102:tid 971345] [client 84.233.195.155:52438] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpecL08BTTQixEno6CwAAAG8"]
[Thu Sep 17 15:12:05.790133 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/build/.env"] [unique_id "aqxXpecL08BTTQixEno6DgAAADU"]
[Thu Sep 17 15:12:05.833059 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/old/.env"] [unique_id "aqxXpecL08BTTQixEno6EAAAAEc"]
[Thu Sep 17 15:12:05.877058 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:47720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxXpecL08BTTQixEno6EgAAAEo"]
[Thu Sep 17 15:12:05.914367 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpecL08BTTQixEno6EwAAAFY"]
[Thu Sep 17 15:12:05.914450 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:53362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpecL08BTTQixEno6EwAAAFY"]
[Thu Sep 17 15:12:05.987140 2026] [security2:error] [pid 971102:tid 971280] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/tmp/.env"] [unique_id "aqxXpecL08BTTQixEno6FgAAAC4"]
[Thu Sep 17 15:12:06.022286 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/dist/.env"] [unique_id "aqxXpucL08BTTQixEno6GAAAADI"]
[Thu Sep 17 15:12:06.025079 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxXpucL08BTTQixEno6GQAAACg"]
[Thu Sep 17 15:12:06.041409 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php"] [unique_id "aqxXpecL08BTTQixEno6FwAAABI"]
[Thu Sep 17 15:12:06.137066 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/temp/.env"] [unique_id "aqxXpucL08BTTQixEno6GgAAAGM"]
[Thu Sep 17 15:12:06.167839 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:47720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxXpucL08BTTQixEno6GwAAAHc"]
[Thu Sep 17 15:12:06.167908 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:47720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxXpucL08BTTQixEno6GwAAAHc"]
[Thu Sep 17 15:12:06.249205 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxXpucL08BTTQixEno6HwAAAD0"]
[Thu Sep 17 15:12:06.250276 2026] [core:error] [pid 971102:tid 971303] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:06.250288 2026] [core:error] [pid 971102:tid 971303] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:06.250375 2026] [security2:error] [pid 971102:tid 971303] [client 74.7.175.159:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sweetvictories.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxXpucL08BTTQixEno6HgAAAEU"]
[Thu Sep 17 15:12:06.252379 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.130.148:44830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXpucL08BTTQixEno6IAAAADE"]
[Thu Sep 17 15:12:06.255878 2026] [security2:error] [pid 971102:tid 971359] [client 74.7.175.159:33754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sweetvictories.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxXpucL08BTTQixEno6HAAAfSA"]
[Thu Sep 17 15:12:06.293433 2026] [security2:error] [pid 971102:tid 971309] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/lab/.env"] [unique_id "aqxXpucL08BTTQixEno6IwAAAEs"]
[Thu Sep 17 15:12:06.375990 2026] [security2:error] [pid 971102:tid 971348] [client 114.198.138.124:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpucL08BTTQixEno6MAAAAHI"]
[Thu Sep 17 15:12:06.376143 2026] [security2:error] [pid 971102:tid 971348] [client 114.198.138.124:59880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpucL08BTTQixEno6MAAAAHI"]
[Thu Sep 17 15:12:06.442558 2026] [security2:error] [pid 971102:tid 971237] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cronlab/.env"] [unique_id "aqxXpucL08BTTQixEno6PAAAAAM"]
[Thu Sep 17 15:12:06.455717 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxXpucL08BTTQixEno6PQAAAGU"]
[Thu Sep 17 15:12:06.477192 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/htdocs/.env"] [unique_id "aqxXpucL08BTTQixEno6QAAAAGA"]
[Thu Sep 17 15:12:06.604627 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cron/.env"] [unique_id "aqxXpucL08BTTQixEno6SAAAACY"]
[Thu Sep 17 15:12:06.606504 2026] [authz_core:error] [pid 971102:tid 971296] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/lib/error_log
[Thu Sep 17 15:12:06.608206 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxXpucL08BTTQixEno6RAAAAD4"]
[Thu Sep 17 15:12:06.705856 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/www/.env"] [unique_id "aqxXpucL08BTTQixEno6SwAAAHU"]
[Thu Sep 17 15:12:06.752127 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/wp-includes/sodium_compat/"] [unique_id "aqxXpucL08BTTQixEno6TAAAAEE"]
[Thu Sep 17 15:12:06.759611 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/en/.env"] [unique_id "aqxXpucL08BTTQixEno6TQAAAH8"]
[Thu Sep 17 15:12:06.764317 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:50458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/info.php"] [unique_id "aqxXpucL08BTTQixEno6TgAAACs"]
[Thu Sep 17 15:12:06.937688 2026] [security2:error] [pid 971102:tid 971315] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/html/.env"] [unique_id "aqxXpucL08BTTQixEno6WgAAAFE"]
[Thu Sep 17 15:12:06.975193 2026] [security2:error] [pid 971102:tid 971259] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/administrator/.env"] [unique_id "aqxXpucL08BTTQixEno6VgAAABk"]
[Thu Sep 17 15:12:07.084146 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpucL08BTTQixEno6UgAAAF0"]
[Thu Sep 17 15:12:07.084167 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpucL08BTTQixEno6UgAAAF0"]
[Thu Sep 17 15:12:07.132220 2026] [security2:error] [pid 971102:tid 971352] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/psnlink/.env"] [unique_id "aqxXp-cL08BTTQixEno6YQAAAHY"]
[Thu Sep 17 15:12:07.172235 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/live/.env"] [unique_id "aqxXp-cL08BTTQixEno6YgAAAGs"]
[Thu Sep 17 15:12:07.224972 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxXp-cL08BTTQixEno6YwAAABQ"]
[Thu Sep 17 15:12:07.225047 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxXp-cL08BTTQixEno6YwAAABQ"]
[Thu Sep 17 15:12:07.283320 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/exapi/.env"] [unique_id "aqxXp-cL08BTTQixEno6ZAAAAFk"]
[Thu Sep 17 15:12:07.338017 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:07.338030 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:07.347128 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXp-cL08BTTQixEno6ZQAAACo"]
[Thu Sep 17 15:12:07.347216 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:42300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXp-cL08BTTQixEno6ZQAAACo"]
[Thu Sep 17 15:12:07.402447 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxXp-cL08BTTQixEno6agAAAFY"]
[Thu Sep 17 15:12:07.434546 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sitemaps/.env"] [unique_id "aqxXp-cL08BTTQixEno6awAAADI"]
[Thu Sep 17 15:12:07.473552 2026] [security2:error] [pid 971102:tid 971281] [client 34.32.117.146:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/php.php"] [unique_id "aqxXp-cL08BTTQixEno6bAAAAC8"]
[Thu Sep 17 15:12:07.514907 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxXp-cL08BTTQixEno6bQAAACg"]
[Thu Sep 17 15:12:07.514973 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxXp-cL08BTTQixEno6bQAAACg"]
[Thu Sep 17 15:12:07.629677 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxXp-cL08BTTQixEno6dQAAAA0"]
[Thu Sep 17 15:12:07.718635 2026] [security2:error] [pid 971102:tid 971321] [client 198.20.67.197:41326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6dwAAAFc"]
[Thu Sep 17 15:12:07.718777 2026] [security2:error] [pid 971102:tid 971321] [client 198.20.67.197:41326] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6dwAAAFc"]
[Thu Sep 17 15:12:07.763363 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:37346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6cwAAABo"]
[Thu Sep 17 15:12:07.803491 2026] [security2:error] [pid 971102:tid 971151] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env"] [unique_id "aqxXp-cL08BTTQixEno6egAAOi8"]
[Thu Sep 17 15:12:07.806393 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxXp-cL08BTTQixEno6gAAAADk"]
[Thu Sep 17 15:12:07.806471 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxXp-cL08BTTQixEno6gAAAADk"]
[Thu Sep 17 15:12:07.858150 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxXp-cL08BTTQixEno6hwAAAG0"]
[Thu Sep 17 15:12:07.888475 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6eQAAOjw"]
[Thu Sep 17 15:12:07.890430 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fgAAOj0"]
[Thu Sep 17 15:12:07.890575 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fQAAOkc"]
[Thu Sep 17 15:12:07.890623 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6ewAAOks"]
[Thu Sep 17 15:12:07.890676 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fAAAOj8"]
[Thu Sep 17 15:12:07.891626 2026] [security2:error] [pid 971102:tid 971175] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.old"] [unique_id "aqxXp-cL08BTTQixEno6jQAAOkc"]
[Thu Sep 17 15:12:07.891626 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.bak"] [unique_id "aqxXp-cL08BTTQixEno6jAAAOks"]
[Thu Sep 17 15:12:07.892089 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fwAAOi8"]
[Thu Sep 17 15:12:07.892780 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.backup"] [unique_id "aqxXp-cL08BTTQixEno6kAAAOlM"]
[Thu Sep 17 15:12:07.972299 2026] [security2:error] [pid 971102:tid 971237] [client 198.20.67.197:41340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/faqs.php"] [unique_id "aqxXp-cL08BTTQixEno6lgAAAAM"]
[Thu Sep 17 15:12:07.972444 2026] [security2:error] [pid 971102:tid 971237] [client 198.20.67.197:41340] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/faqs.php"] [unique_id "aqxXp-cL08BTTQixEno6lgAAAAM"]
[Thu Sep 17 15:12:07.976052 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6jgAAOic"]
[Thu Sep 17 15:12:07.976209 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6iwAAOj0"]
[Thu Sep 17 15:12:07.976273 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6kgAAOkc"]
[Thu Sep 17 15:12:07.978796 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6igAAOjw"]
[Thu Sep 17 15:12:07.978872 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6jwAAOks"]
[Thu Sep 17 15:12:07.979227 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6kQAAOk4"]
[Thu Sep 17 15:12:08.039464 2026] [security2:error] [pid 971102:tid 971304] [client 198.20.67.197:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/windows.php"] [unique_id "aqxXqOcL08BTTQixEno6mAAAAEY"]
[Thu Sep 17 15:12:08.039575 2026] [security2:error] [pid 971102:tid 971304] [client 198.20.67.197:41352] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/windows.php"] [unique_id "aqxXqOcL08BTTQixEno6mAAAAEY"]
[Thu Sep 17 15:12:08.065294 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6lwAAZU8"]
[Thu Sep 17 15:12:08.068401 2026] [security2:error] [pid 971102:tid 971184] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/.env.php"] [unique_id "aqxXqOcL08BTTQixEno6mgAAW1A"]
[Thu Sep 17 15:12:08.070486 2026] [security2:error] [pid 971102:tid 971180] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env~"] [unique_id "aqxXqOcL08BTTQixEno6mwAAW0w"]
[Thu Sep 17 15:12:08.070495 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.swp"] [unique_id "aqxXqOcL08BTTQixEno6nAAAW0g"]
[Thu Sep 17 15:12:08.088561 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:47762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno6oAAAAEM"]
[Thu Sep 17 15:12:08.088722 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:47762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno6oAAAAEM"]
[Thu Sep 17 15:12:08.090197 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/opt/.env"] [unique_id "aqxXqOcL08BTTQixEno6oQAAACE"]
[Thu Sep 17 15:12:08.109671 2026] [security2:error] [pid 971102:tid 971263] [client 198.20.67.197:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/roofing.php"] [unique_id "aqxXqOcL08BTTQixEno6ogAAAB0"]
[Thu Sep 17 15:12:08.109850 2026] [security2:error] [pid 971102:tid 971263] [client 198.20.67.197:41354] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/roofing.php"] [unique_id "aqxXqOcL08BTTQixEno6ogAAAB0"]
[Thu Sep 17 15:12:08.124149 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.130.148:44844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXqOcL08BTTQixEno6owAAAHI"]
[Thu Sep 17 15:12:08.129404 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.0.94:37346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6lAAAACA"]
[Thu Sep 17 15:12:08.147869 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6nwAAWzo"]
[Thu Sep 17 15:12:08.147984 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6ngAAW2A"]
[Thu Sep 17 15:12:08.148021 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6mQAAW00"]
[Thu Sep 17 15:12:08.148187 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6nQAAW14"]
[Thu Sep 17 15:12:08.159724 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/api/.env"] [unique_id "aqxXqOcL08BTTQixEno6pAAATkI"]
[Thu Sep 17 15:12:08.159784 2026] [security2:error] [pid 971102:tid 971190] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/app/.env"] [unique_id "aqxXqOcL08BTTQixEno6pgAATlU"]
[Thu Sep 17 15:12:08.161632 2026] [security2:error] [pid 971102:tid 971205] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/backend/.env"] [unique_id "aqxXqOcL08BTTQixEno6qgAATmQ"]
[Thu Sep 17 15:12:08.169621 2026] [security2:error] [pid 971102:tid 971285] [client 198.20.67.197:41358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/testimonials.php"] [unique_id "aqxXqOcL08BTTQixEno6rAAAADM"]
[Thu Sep 17 15:12:08.169785 2026] [security2:error] [pid 971102:tid 971285] [client 198.20.67.197:41358] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/testimonials.php"] [unique_id "aqxXqOcL08BTTQixEno6rAAAADM"]
[Thu Sep 17 15:12:08.233126 2026] [security2:error] [pid 971102:tid 971355] [client 198.20.67.197:41364] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chiext.net"] [uri "/style.css"] [unique_id "aqxXqOcL08BTTQixEno6rQAAAHk"]
[Thu Sep 17 15:12:08.237645 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6qQAATlo"]
[Thu Sep 17 15:12:08.237751 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6pwAATlQ"]
[Thu Sep 17 15:12:08.237850 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6pQAATiM"]
[Thu Sep 17 15:12:08.238162 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6qwAATmU"]
[Thu Sep 17 15:12:08.239419 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6qAAATjs"]
[Thu Sep 17 15:12:08.248905 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/server/.env"] [unique_id "aqxXqOcL08BTTQixEno6rwAAJmk"]
[Thu Sep 17 15:12:08.250012 2026] [security2:error] [pid 971102:tid 971186] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/src/.env"] [unique_id "aqxXqOcL08BTTQixEno6sAAAJlI"]
[Thu Sep 17 15:12:08.250022 2026] [security2:error] [pid 971102:tid 971211] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/config/.env"] [unique_id "aqxXqOcL08BTTQixEno6sQAAJmo"]
[Thu Sep 17 15:12:08.280504 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/logs/.env"] [unique_id "aqxXqOcL08BTTQixEno6sgAAAHw"]
[Thu Sep 17 15:12:08.319484 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxXqOcL08BTTQixEno6swAAAGY"]
[Thu Sep 17 15:12:08.325989 2026] [security2:error] [pid 971102:tid 971272] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6rgAAJlg"]
[Thu Sep 17 15:12:08.327926 2026] [security2:error] [pid 971102:tid 971194] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/web/.env"] [unique_id "aqxXqOcL08BTTQixEno6tgAAdVk"]
[Thu Sep 17 15:12:08.327957 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/frontend/.env"] [unique_id "aqxXqOcL08BTTQixEno6tQAAdVw"]
[Thu Sep 17 15:12:08.327990 2026] [security2:error] [pid 971102:tid 971219] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/public/.env"] [unique_id "aqxXqOcL08BTTQixEno6twAAdXI"]
[Thu Sep 17 15:12:08.327990 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/client/.env"] [unique_id "aqxXqOcL08BTTQixEno6tAAAdWw"]
[Thu Sep 17 15:12:08.343129 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/var/www/.env"] [unique_id "aqxXqOcL08BTTQixEno6vAAASWs"]
[Thu Sep 17 15:12:08.343181 2026] [security2:error] [pid 971102:tid 971191] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/var/www/html/.env"] [unique_id "aqxXqOcL08BTTQixEno6ugAASVY"]
[Thu Sep 17 15:12:08.343193 2026] [security2:error] [pid 971102:tid 971208] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/laravel/.env"] [unique_id "aqxXqOcL08BTTQixEno6uwAASWc"]
[Thu Sep 17 15:12:08.344596 2026] [security2:error] [pid 971102:tid 971299] [client 198.20.67.197:41372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/contact.php"] [unique_id "aqxXqOcL08BTTQixEno6vQAAAEE"]
[Thu Sep 17 15:12:08.344683 2026] [security2:error] [pid 971102:tid 971299] [client 198.20.67.197:41372] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/contact.php"] [unique_id "aqxXqOcL08BTTQixEno6vQAAAEE"]
[Thu Sep 17 15:12:08.388106 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:47776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxXqOcL08BTTQixEno6vgAAADw"]
[Thu Sep 17 15:12:08.388174 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:47776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxXqOcL08BTTQixEno6vgAAADw"]
[Thu Sep 17 15:12:08.411711 2026] [security2:error] [pid 971102:tid 971257] [client 198.20.67.197:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/sidinggutters.php"] [unique_id "aqxXqOcL08BTTQixEno6vwAAABc"]
[Thu Sep 17 15:12:08.411777 2026] [security2:error] [pid 971102:tid 971257] [client 198.20.67.197:41388] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/sidinggutters.php"] [unique_id "aqxXqOcL08BTTQixEno6vwAAABc"]
[Thu Sep 17 15:12:08.417939 2026] [security2:error] [pid 971102:tid 971198] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/application/.env"] [unique_id "aqxXqOcL08BTTQixEno6wQAAe10"]
[Thu Sep 17 15:12:08.417970 2026] [security2:error] [pid 971102:tid 971218] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/back/.env"] [unique_id "aqxXqOcL08BTTQixEno6wgAAe3E"]
[Thu Sep 17 15:12:08.417973 2026] [security2:error] [pid 971102:tid 971217] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/backup/.env"] [unique_id "aqxXqOcL08BTTQixEno6wwAAe3A"]
[Thu Sep 17 15:12:08.417999 2026] [security2:error] [pid 971102:tid 971207] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/apps/.env"] [unique_id "aqxXqOcL08BTTQixEno6wAAAe2Y"]
[Thu Sep 17 15:12:08.419334 2026] [security2:error] [pid 971102:tid 971104] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/cms/.env"] [unique_id "aqxXqOcL08BTTQixEno6xAAAUQA"]
[Thu Sep 17 15:12:08.427876 2026] [security2:error] [pid 971102:tid 971192] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/dev/.env"] [unique_id "aqxXqOcL08BTTQixEno6xQAAOFc"]
[Thu Sep 17 15:12:08.428639 2026] [security2:error] [pid 971102:tid 971216] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/prod/.env"] [unique_id "aqxXqOcL08BTTQixEno6xgAAO28"]
[Thu Sep 17 15:12:08.429394 2026] [security2:error] [pid 971102:tid 971196] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/production/.env"] [unique_id "aqxXqOcL08BTTQixEno6xwAAO1s"]
[Thu Sep 17 15:12:08.474784 2026] [security2:error] [pid 971102:tid 971324] [client 198.20.67.197:41400] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chiext.net"] [uri "/home-styles.css"] [unique_id "aqxXqOcL08BTTQixEno6yQAAAFo"]
[Thu Sep 17 15:12:08.510506 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/staging/.env"] [unique_id "aqxXqOcL08BTTQixEno6ygAAc20"]
[Thu Sep 17 15:12:08.512150 2026] [security2:error] [pid 971102:tid 971231] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/new/.env"] [unique_id "aqxXqOcL08BTTQixEno6ywAAc34"]
[Thu Sep 17 15:12:08.512167 2026] [security2:error] [pid 971102:tid 971227] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/old/.env"] [unique_id "aqxXqOcL08BTTQixEno6zQAAc3o"]
[Thu Sep 17 15:12:08.512199 2026] [security2:error] [pid 971102:tid 971204] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/node-api/.env"] [unique_id "aqxXqOcL08BTTQixEno6zgAAc2M"]
[Thu Sep 17 15:12:08.512207 2026] [security2:error] [pid 971102:tid 971160] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/test/.env"] [unique_id "aqxXqOcL08BTTQixEno6zAAAczg"]
[Thu Sep 17 15:12:08.525939 2026] [security2:error] [pid 971102:tid 971230] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/admin-app/.env"] [unique_id "aqxXqOcL08BTTQixEno60AAAD30"]
[Thu Sep 17 15:12:08.526002 2026] [security2:error] [pid 971102:tid 971200] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/api-backend/.env"] [unique_id "aqxXqOcL08BTTQixEno6zwAAD18"]
[Thu Sep 17 15:12:08.526522 2026] [security2:error] [pid 971102:tid 971209] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/administrator/.env"] [unique_id "aqxXqOcL08BTTQixEno60QAAD2g"]
[Thu Sep 17 15:12:08.547620 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/symfony/.env"] [unique_id "aqxXqOcL08BTTQixEno60gAAADU"]
[Thu Sep 17 15:12:08.565071 2026] [security2:error] [pid 971102:tid 971344] [client 84.233.195.150:54254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqOcL08BTTQixEno60wAAAG4"]
[Thu Sep 17 15:12:08.591647 2026] [security2:error] [pid 971102:tid 971327] [client 198.20.67.197:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/financing.php"] [unique_id "aqxXqOcL08BTTQixEno61AAAAF0"]
[Thu Sep 17 15:12:08.591754 2026] [security2:error] [pid 971102:tid 971327] [client 198.20.67.197:41414] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/financing.php"] [unique_id "aqxXqOcL08BTTQixEno61AAAAF0"]
[Thu Sep 17 15:12:08.598912 2026] [security2:error] [pid 971102:tid 971223] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/server/backend/.env"] [unique_id "aqxXqOcL08BTTQixEno61QAAZHY"]
[Thu Sep 17 15:12:08.598946 2026] [security2:error] [pid 971102:tid 971105] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/current/.env"] [unique_id "aqxXqOcL08BTTQixEno61wAAZAE"]
[Thu Sep 17 15:12:08.598945 2026] [security2:error] [pid 971102:tid 971225] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/server/api/.env"] [unique_id "aqxXqOcL08BTTQixEno62AAAZHg"]
[Thu Sep 17 15:12:08.598978 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/public_html/.env"] [unique_id "aqxXqOcL08BTTQixEno61gAAZHk"]
[Thu Sep 17 15:12:08.599557 2026] [security2:error] [pid 971102:tid 971221] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.docker/.env"] [unique_id "aqxXqOcL08BTTQixEno62QAAZHQ"]
[Thu Sep 17 15:12:08.652882 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:35134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/i.php"] [unique_id "aqxXqOcL08BTTQixEno62gAAAF8"]
[Thu Sep 17 15:12:08.653074 2026] [security2:error] [pid 971102:tid 971317] [client 198.20.67.197:41428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/claims.php"] [unique_id "aqxXqOcL08BTTQixEno62wAAAFM"]
[Thu Sep 17 15:12:08.653152 2026] [security2:error] [pid 971102:tid 971317] [client 198.20.67.197:41428] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/claims.php"] [unique_id "aqxXqOcL08BTTQixEno62wAAAFM"]
[Thu Sep 17 15:12:08.675817 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:47788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno63AAAAB4"]
[Thu Sep 17 15:12:08.675928 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:47788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno63AAAAB4"]
[Thu Sep 17 15:12:08.702738 2026] [security2:error] [pid 971102:tid 971220] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/stripe/.env"] [unique_id "aqxXqOcL08BTTQixEno63gAAJXM"]
[Thu Sep 17 15:12:08.702791 2026] [security2:error] [pid 971102:tid 971108] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/aws/.env"] [unique_id "aqxXqOcL08BTTQixEno63wAAJQQ"]
[Thu Sep 17 15:12:08.702803 2026] [security2:error] [pid 971102:tid 971224] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxXqOcL08BTTQixEno64AAAJXc"]
[Thu Sep 17 15:12:08.702813 2026] [security2:error] [pid 971102:tid 971107] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.aws/.env"] [unique_id "aqxXqOcL08BTTQixEno63QAAJQM"]
[Thu Sep 17 15:12:08.711841 2026] [security2:error] [pid 971102:tid 971106] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/v2/.env"] [unique_id "aqxXqOcL08BTTQixEno64wAAJQI"]
[Thu Sep 17 15:12:08.711851 2026] [security2:error] [pid 971102:tid 971116] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/v1/.env"] [unique_id "aqxXqOcL08BTTQixEno65AAAJQw"]
[Thu Sep 17 15:12:08.717135 2026] [security2:error] [pid 971102:tid 971215] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/v3/.env"] [unique_id "aqxXqOcL08BTTQixEno65gAAJW4"]
[Thu Sep 17 15:12:08.717181 2026] [security2:error] [pid 971102:tid 971118] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/media/.env"] [unique_id "aqxXqOcL08BTTQixEno65QAAJQ4"]
[Thu Sep 17 15:12:08.724792 2026] [security2:error] [pid 971102:tid 971341] [client 198.20.67.197:41432] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chiext.net"] [uri "/js.js"] [unique_id "aqxXqOcL08BTTQixEno66QAAAGs"]
[Thu Sep 17 15:12:08.743096 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cache/.env"] [unique_id "aqxXqOcL08BTTQixEno67AAAABw"]
[Thu Sep 17 15:12:08.789775 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno64QAAJXU"]
[Thu Sep 17 15:12:08.793697 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno65wAAJWI"]
[Thu Sep 17 15:12:08.794229 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno64gAAJQY"]
[Thu Sep 17 15:12:08.825161 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.130.148:44852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxXqOcL08BTTQixEno69AAAABs"]
[Thu Sep 17 15:12:08.871004 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno67wAAJQU"]
[Thu Sep 17 15:12:08.871141 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno67QAAJRY"]
[Thu Sep 17 15:12:08.872405 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno68AAAJXs"]
[Thu Sep 17 15:12:08.873006 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno67gAAJRA"]
[Thu Sep 17 15:12:08.880113 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno68QAAJQ8"]
[Thu Sep 17 15:12:08.896495 2026] [security2:error] [pid 971102:tid 971281] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailer/.env"] [unique_id "aqxXqOcL08BTTQixEno6_AAAAC8"]
[Thu Sep 17 15:12:08.899487 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.git/config.bak"] [unique_id "aqxXqOcL08BTTQixEno6_gAAFQg"]
[Thu Sep 17 15:12:08.962061 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:47798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxXqOcL08BTTQixEno6_wAAAHE"]
[Thu Sep 17 15:12:08.962234 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:47798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxXqOcL08BTTQixEno6_wAAAHE"]
[Thu Sep 17 15:12:08.972949 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno69wAAFQc"]
[Thu Sep 17 15:12:08.973073 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-QAAFQo"]
[Thu Sep 17 15:12:08.977007 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno69gAAFRM"]
[Thu Sep 17 15:12:08.978040 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-AAAFRI"]
[Thu Sep 17 15:12:08.989482 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-gAAFRc"]
[Thu Sep 17 15:12:08.989591 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6_QAAFRE"]
[Thu Sep 17 15:12:08.992778 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-wAAFQk"]
[Thu Sep 17 15:12:09.051250 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mail/.env"] [unique_id "aqxXqecL08BTTQixEno7CQAAAEA"]
[Thu Sep 17 15:12:09.053075 2026] [security2:error] [pid 971102:tid 971284] [client 84.233.195.157:55858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqecL08BTTQixEno7CgAAADI"]
[Thu Sep 17 15:12:09.062766 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno7AQAAFX8"]
[Thu Sep 17 15:12:09.062877 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno7AAAAFRg"]
[Thu Sep 17 15:12:09.063005 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno7AgAAFQs"]
[Thu Sep 17 15:12:09.066805 2026] [security2:error] [pid 971102:tid 971153] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxXqecL08BTTQixEno7EQAAFTE"]
[Thu Sep 17 15:12:09.092158 2026] [security2:error] [pid 971102:tid 971274] [client 45.169.98.18:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXqecL08BTTQixEno7EwAAACg"]
[Thu Sep 17 15:12:09.092266 2026] [security2:error] [pid 971102:tid 971274] [client 45.169.98.18:57970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXqecL08BTTQixEno7EwAAACg"]
[Thu Sep 17 15:12:09.097715 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.097730 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.138194 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7DQAAFSE"]
[Thu Sep 17 15:12:09.138349 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7DAAAFSw"]
[Thu Sep 17 15:12:09.142174 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7DgAAFRs"]
[Thu Sep 17 15:12:09.143145 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7CwAAFRQ"]
[Thu Sep 17 15:12:09.163163 2026] [security2:error] [pid 971102:tid 971145] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/id_rsa"] [unique_id "aqxXqecL08BTTQixEno7GAAAFSk"]
[Thu Sep 17 15:12:09.163290 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxXqecL08BTTQixEno7GQAAFTI"]
[Thu Sep 17 15:12:09.168038 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7EgAAFSQ"]
[Thu Sep 17 15:12:09.205344 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/email/.env"] [unique_id "aqxXqecL08BTTQixEno7HQAAABo"]
[Thu Sep 17 15:12:09.242052 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/wordpress/.env"] [unique_id "aqxXqecL08BTTQixEno7HgAAAAA"]
[Thu Sep 17 15:12:09.269440 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxXqecL08BTTQixEno7IwAAADk"]
[Thu Sep 17 15:12:09.269614 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxXqecL08BTTQixEno7IwAAADk"]
[Thu Sep 17 15:12:09.282280 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7FwAAFR4"]
[Thu Sep 17 15:12:09.282445 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7FgAAFS0"]
[Thu Sep 17 15:12:09.301556 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7GgAAFR8"]
[Thu Sep 17 15:12:09.304518 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7GwAAFSY"]
[Thu Sep 17 15:12:09.306998 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7HAAAFRw"]
[Thu Sep 17 15:12:09.346579 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7IAAAFXw"]
[Thu Sep 17 15:12:09.349737 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7IQAAFS4"]
[Thu Sep 17 15:12:09.355017 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7HwAAFR0"]
[Thu Sep 17 15:12:09.364751 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/smtp/.env"] [unique_id "aqxXqecL08BTTQixEno7LQAAAAw"]
[Thu Sep 17 15:12:09.368797 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7IgAAFRo"]
[Thu Sep 17 15:12:09.416787 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7JQAAFTQ"]
[Thu Sep 17 15:12:09.416907 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KQAAFUE"]
[Thu Sep 17 15:12:09.418325 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7JwAAFSg"]
[Thu Sep 17 15:12:09.418961 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KAAAFTY"]
[Thu Sep 17 15:12:09.433334 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KwAAFTM"]
[Thu Sep 17 15:12:09.437005 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7LAAAFUU"]
[Thu Sep 17 15:12:09.452890 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KgAAFSo"]
[Thu Sep 17 15:12:09.474373 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/wp/.env"] [unique_id "aqxXqecL08BTTQixEno7MgAAADo"]
[Thu Sep 17 15:12:09.490591 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:35140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/pi.php"] [unique_id "aqxXqecL08BTTQixEno7NAAAAFU"]
[Thu Sep 17 15:12:09.522183 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailing/.env"] [unique_id "aqxXqecL08BTTQixEno7NwAAAGo"]
[Thu Sep 17 15:12:09.551648 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7MQAAAys"]
[Thu Sep 17 15:12:09.551751 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7MAAAAxU"]
[Thu Sep 17 15:12:09.563031 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:47816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxXqecL08BTTQixEno7PQAAAAs"]
[Thu Sep 17 15:12:09.563144 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:47816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxXqecL08BTTQixEno7PQAAAAs"]
[Thu Sep 17 15:12:09.573578 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7MwAAAyU"]
[Thu Sep 17 15:12:09.573892 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7NgAAAzA"]
[Thu Sep 17 15:12:09.575347 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7NQAAA0Y"]
[Thu Sep 17 15:12:09.611457 2026] [security2:error] [pid 971102:tid 971238] [client 84.233.195.154:54117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqecL08BTTQixEno7QgAAAAQ"]
[Thu Sep 17 15:12:09.629357 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7OgAAAzk"]
[Thu Sep 17 15:12:09.629444 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7OwAAA0M"]
[Thu Sep 17 15:12:09.629527 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7OQAAA0A"]
[Thu Sep 17 15:12:09.639352 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config.php"] [unique_id "aqxXqecL08BTTQixEno7RQAAA1M"]
[Thu Sep 17 15:12:09.644154 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7PAAAAz4"]
[Thu Sep 17 15:12:09.678904 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/notifications/.env"] [unique_id "aqxXqecL08BTTQixEno7RgAAAEg"]
[Thu Sep 17 15:12:09.709902 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxXqecL08BTTQixEno7RwAAACw"]
[Thu Sep 17 15:12:09.825077 2026] [security2:error] [pid 971102:tid 971267] [client 5.189.145.112:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxXqecL08BTTQixEno7UgAAACE"], referer: binance.com
[Thu Sep 17 15:12:09.833806 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/notify/.env"] [unique_id "aqxXqecL08BTTQixEno7VQAAAB0"]
[Thu Sep 17 15:12:09.842519 2026] [core:error] [pid 971102:tid 971348] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.842536 2026] [core:error] [pid 971102:tid 971348] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.851792 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:47826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxXqecL08BTTQixEno7WQAAAGg"]
[Thu Sep 17 15:12:09.945136 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/drupal/.env"] [unique_id "aqxXqecL08BTTQixEno7XAAAAD4"]
[Thu Sep 17 15:12:09.988210 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sender/.env"] [unique_id "aqxXqecL08BTTQixEno7XgAAAGY"]
[Thu Sep 17 15:12:10.008153 2026] [authz_core:error] [pid 971102:tid 971351] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/error_log
[Thu Sep 17 15:12:10.014332 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxXqecL08BTTQixEno7YQAAAHU"]
[Thu Sep 17 15:12:10.109327 2026] [security2:error] [pid 971102:tid 971289] [client 84.233.195.151:64673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqucL08BTTQixEno7ZAAAADc"]
[Thu Sep 17 15:12:10.142908 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/campaign/.env"] [unique_id "aqxXqucL08BTTQixEno7ZgAAABc"]
[Thu Sep 17 15:12:10.158481 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:47826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/wp-includes/sodium_compat/"] [unique_id "aqxXqucL08BTTQixEno7aAAAAEQ"]
[Thu Sep 17 15:12:10.176376 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env"] [unique_id "aqxXqucL08BTTQixEno7agAAAHs"]
[Thu Sep 17 15:12:10.176869 2026] [security2:error] [pid 971102:tid 971315] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/joomla/.env"] [unique_id "aqxXqucL08BTTQixEno7awAAAFE"]
[Thu Sep 17 15:12:10.295972 2026] [security2:error] [pid 971102:tid 971249] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/newsletter/.env"] [unique_id "aqxXqucL08BTTQixEno7bwAAAA8"]
[Thu Sep 17 15:12:10.299625 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7PgAAA0o"]
[Thu Sep 17 15:12:10.302515 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7QAAAA0Q"]
[Thu Sep 17 15:12:10.312754 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7PwAAAz8"]
[Thu Sep 17 15:12:10.322952 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7QQAAA1E"]
[Thu Sep 17 15:12:10.328369 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7QwAAA0k"]
[Thu Sep 17 15:12:10.328868 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7RAAAAy8"]
[Thu Sep 17 15:12:10.330210 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.117.146:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/pinfo.php"] [unique_id "aqxXqucL08BTTQixEno7dQAAADw"]
[Thu Sep 17 15:12:10.363078 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SgAAA0c"]
[Thu Sep 17 15:12:10.363195 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SAAAAyc"]
[Thu Sep 17 15:12:10.365427 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SQAAAz0"]
[Thu Sep 17 15:12:10.379367 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SwAAAzw"]
[Thu Sep 17 15:12:10.386260 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7TAAAA0s"]
[Thu Sep 17 15:12:10.386411 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7TwAAA04"]
[Thu Sep 17 15:12:10.388107 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7UQAAA08"]
[Thu Sep 17 15:12:10.391549 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7UAAAAzc"]
[Thu Sep 17 15:12:10.391727 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7VAAAA0w"]
[Thu Sep 17 15:12:10.403708 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/magento/.env"] [unique_id "aqxXqucL08BTTQixEno7egAAAEc"]
[Thu Sep 17 15:12:10.415035 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7UwAAA1A"]
[Thu Sep 17 15:12:10.447677 2026] [security2:error] [pid 971102:tid 971341] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/ses/.env"] [unique_id "aqxXqucL08BTTQixEno7fgAAAGs"]
[Thu Sep 17 15:12:10.511073 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/aws.php"] [unique_id "aqxXqucL08BTTQixEno7gwAAFEI"]
[Thu Sep 17 15:12:10.511093 2026] [security2:error] [pid 971102:tid 971205] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/stripe.php"] [unique_id "aqxXqucL08BTTQixEno7hQAAFGQ"]
[Thu Sep 17 15:12:10.526403 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7cAAAACM"]
[Thu Sep 17 15:12:10.526427 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7cAAAACM"]
[Thu Sep 17 15:12:10.557257 2026] [security2:error] [pid 971102:tid 971195] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/mail.php"] [unique_id "aqxXqucL08BTTQixEno7iwAAFFo"]
[Thu Sep 17 15:12:10.557264 2026] [security2:error] [pid 971102:tid 971139] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/config.inc.php"] [unique_id "aqxXqucL08BTTQixEno7igAAFCM"]
[Thu Sep 17 15:12:10.559167 2026] [security2:error] [pid 971102:tid 971163] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/nexmo.php"] [unique_id "aqxXqucL08BTTQixEno7jQAAFDs"]
[Thu Sep 17 15:12:10.578754 2026] [security2:error] [pid 971102:tid 971211] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/wp-config.php"] [unique_id "aqxXqucL08BTTQixEno7kQAAFGo"]
[Thu Sep 17 15:12:10.582408 2026] [security2:error] [pid 971102:tid 971193] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sqlerudition.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXqucL08BTTQixEno7kgAAFFg"]
[Thu Sep 17 15:12:10.582408 2026] [security2:error] [pid 971102:tid 971194] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sqlerudition.com"] [uri "/wp-config.php.old"] [unique_id "aqxXqucL08BTTQixEno7kwAAFFk"]
[Thu Sep 17 15:12:10.586622 2026] [security2:error] [pid 971102:tid 971235] [client 84.233.195.155:54258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqucL08BTTQixEno7lAAAAAE"]
[Thu Sep 17 15:12:10.599297 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7gQAAFE0"]
[Thu Sep 17 15:12:10.599480 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7ggAAFFU"]
[Thu Sep 17 15:12:10.599557 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7hAAAFF4"]
[Thu Sep 17 15:12:10.600529 2026] [security2:error] [pid 971102:tid 971360] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sendgrid/.env"] [unique_id "aqxXqucL08BTTQixEno7lgAAAH4"]
[Thu Sep 17 15:12:10.600703 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxXqucL08BTTQixEno7lQAAAC8"]
[Thu Sep 17 15:12:10.601729 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sqlerudition.com"] [uri "/wp-config.php.new"] [unique_id "aqxXqucL08BTTQixEno7lwAAFFw"]
[Thu Sep 17 15:12:10.623726 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxXqucL08BTTQixEno7mAAAAHE"]
[Thu Sep 17 15:12:10.632008 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/shopify/.env"] [unique_id "aqxXqucL08BTTQixEno7mQAAAF4"]
[Thu Sep 17 15:12:10.645481 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7iQAAFFQ"]
[Thu Sep 17 15:12:10.645622 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7jAAAFGU"]
[Thu Sep 17 15:12:10.661380 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7kAAAFFI"]
[Thu Sep 17 15:12:10.669695 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7jwAAFGk"]
[Thu Sep 17 15:12:10.678240 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxXqucL08BTTQixEno7mwAAADI"]
[Thu Sep 17 15:12:10.678333 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:47826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxXqucL08BTTQixEno7mwAAADI"]
[Thu Sep 17 15:12:10.688062 2026] [core:error] [pid 971102:tid 971298] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:10.688077 2026] [core:error] [pid 971102:tid 971298] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:10.694584 2026] [security2:error] [pid 971102:tid 971219] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxXqucL08BTTQixEno7nQAAKHI"]
[Thu Sep 17 15:12:10.706705 2026] [security2:error] [pid 971102:tid 971320] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxXqucL08BTTQixEno7nwAAAFY"]
[Thu Sep 17 15:12:10.752553 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxXqucL08BTTQixEno7owAAKGs"]
[Thu Sep 17 15:12:10.763375 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sparkpost/.env"] [unique_id "aqxXqucL08BTTQixEno7pAAAAGM"]
[Thu Sep 17 15:12:10.783331 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7ngAAKGw"]
[Thu Sep 17 15:12:10.786751 2026] [security2:error] [pid 971102:tid 971192] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxXqucL08BTTQixEno7qgAAKFc"]
[Thu Sep 17 15:12:10.859727 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/prestashop/.env"] [unique_id "aqxXqucL08BTTQixEno7tAAAADk"]
[Thu Sep 17 15:12:10.916412 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/postmark/.env"] [unique_id "aqxXqucL08BTTQixEno7ugAAAFI"]
[Thu Sep 17 15:12:10.978842 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:51372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXqucL08BTTQixEno7wQAAAHA"]
[Thu Sep 17 15:12:11.071354 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailgun/.env"] [unique_id "aqxXq-cL08BTTQixEno7xQAAAFs"]
[Thu Sep 17 15:12:11.081894 2026] [security2:error] [pid 971102:tid 971255] [client 84.233.195.160:63291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXq-cL08BTTQixEno7xgAAABU"]
[Thu Sep 17 15:12:11.085469 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/codeigniter/.env"] [unique_id "aqxXq-cL08BTTQixEno7xwAAAGc"]
[Thu Sep 17 15:12:11.148031 2026] [authz_core:error] [pid 971102:tid 971307] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/error_log
[Thu Sep 17 15:12:11.164854 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXq-cL08BTTQixEno7zQAAAEk"]
[Thu Sep 17 15:12:11.229189 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mandrill/.env"] [unique_id "aqxXq-cL08BTTQixEno70AAAACQ"]
[Thu Sep 17 15:12:11.309994 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:51372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxXq-cL08BTTQixEno70gAAADc"]
[Thu Sep 17 15:12:11.319127 2026] [security2:error] [pid 971102:tid 971302] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cakephp/.env"] [unique_id "aqxXq-cL08BTTQixEno71AAAAEQ"]
[Thu Sep 17 15:12:11.330905 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7ogAAKGc"]
[Thu Sep 17 15:12:11.339946 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7oQAAKFY"]
[Thu Sep 17 15:12:11.352314 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7pwAAKHA"]
[Thu Sep 17 15:12:11.357077 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7pQAAKF0"]
[Thu Sep 17 15:12:11.365246 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7vAAAKH0"]
[Thu Sep 17 15:12:11.365401 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7sQAAKG0"]
[Thu Sep 17 15:12:11.368222 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7uQAAKDg"]
[Thu Sep 17 15:12:11.370513 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7sgAAKHo"]
[Thu Sep 17 15:12:11.372645 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7wAAAKGg"]
[Thu Sep 17 15:12:11.373793 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7pgAAKHE"]
[Thu Sep 17 15:12:11.374082 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7qAAAKGY"]
[Thu Sep 17 15:12:11.380281 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7tgAAKGM"]
[Thu Sep 17 15:12:11.386379 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7qQAAKAA"]
[Thu Sep 17 15:12:11.387142 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7qwAAKG8"]
[Thu Sep 17 15:12:11.389110 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailjet/.env"] [unique_id "aqxXq-cL08BTTQixEno71wAAADs"]
[Thu Sep 17 15:12:11.389416 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7sAAAKH4"]
[Thu Sep 17 15:12:11.406801 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7vgAAKF8"]
[Thu Sep 17 15:12:11.470037 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxXq-cL08BTTQixEno74QAAAAM"]
[Thu Sep 17 15:12:11.495793 2026] [security2:error] [pid 971102:tid 971352] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env~"] [unique_id "aqxXq-cL08BTTQixEno74wAAAHY"]
[Thu Sep 17 15:12:11.551747 2026] [core:error] [pid 971102:tid 971329] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:11.551773 2026] [core:error] [pid 971102:tid 971329] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:11.551808 2026] [security2:error] [pid 971102:tid 971341] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/brevo/.env"] [unique_id "aqxXq-cL08BTTQixEno77gAAAGs"]
[Thu Sep 17 15:12:11.551850 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/zend/.env"] [unique_id "aqxXq-cL08BTTQixEno76gAAAAk"]
[Thu Sep 17 15:12:11.680123 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno73AAAAG8"]
[Thu Sep 17 15:12:11.680144 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno73AAAAG8"]
[Thu Sep 17 15:12:11.714123 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/transactional/.env"] [unique_id "aqxXq-cL08BTTQixEno7-gAAAGI"]
[Thu Sep 17 15:12:11.783634 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/yii/.env"] [unique_id "aqxXq-cL08BTTQixEno7_QAAAEA"]
[Thu Sep 17 15:12:11.835487 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxXq-cL08BTTQixEno7_wAAAFw"]
[Thu Sep 17 15:12:11.835585 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxXq-cL08BTTQixEno7_wAAAFw"]
[Thu Sep 17 15:12:11.867876 2026] [security2:error] [pid 971102:tid 971259] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/bulk/.env"] [unique_id "aqxXq-cL08BTTQixEno8AQAAABk"]
[Thu Sep 17 15:12:11.910388 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/test.php"] [unique_id "aqxXq-cL08BTTQixEno8BAAAACY"]
[Thu Sep 17 15:12:11.990708 2026] [security2:error] [pid 971102:tid 971261] [client 156.192.234.52:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXq-cL08BTTQixEno8CAAAABs"]
[Thu Sep 17 15:12:11.990796 2026] [security2:error] [pid 971102:tid 971261] [client 156.192.234.52:65436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXq-cL08BTTQixEno8CAAAABs"]
[Thu Sep 17 15:12:12.009064 2026] [security2:error] [pid 971102:tid 971250] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxXrOcL08BTTQixEno8CQAAABA"]
[Thu Sep 17 15:12:12.010219 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/laravel5/.env"] [unique_id "aqxXrOcL08BTTQixEno8CgAAAAI"]
[Thu Sep 17 15:12:12.025464 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/aws/.env"] [unique_id "aqxXrOcL08BTTQixEno8CwAAAF0"]
[Thu Sep 17 15:12:12.032371 2026] [security2:error] [pid 971102:tid 971258] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxXrOcL08BTTQixEno8DAAAABg"]
[Thu Sep 17 15:12:12.055362 2026] [security2:error] [pid 971102:tid 971313] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxXrOcL08BTTQixEno8DQAAAE8"]
[Thu Sep 17 15:12:12.080303 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxXrOcL08BTTQixEno8EAAAAEs"]
[Thu Sep 17 15:12:12.105117 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxXrOcL08BTTQixEno8EQAAAFI"]
[Thu Sep 17 15:12:12.120529 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxXrOcL08BTTQixEno8EgAAADo"]
[Thu Sep 17 15:12:12.120593 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:51386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxXrOcL08BTTQixEno8EgAAADo"]
[Thu Sep 17 15:12:12.127552 2026] [security2:error] [pid 971102:tid 971251] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxXrOcL08BTTQixEno8EwAAABE"]
[Thu Sep 17 15:12:12.176853 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/azure/.env"] [unique_id "aqxXrOcL08BTTQixEno8FgAAAHA"]
[Thu Sep 17 15:12:12.219499 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxXrOcL08BTTQixEno8GQAAAEg"]
[Thu Sep 17 15:12:12.236793 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxXrOcL08BTTQixEno8GgAAACc"]
[Thu Sep 17 15:12:12.237989 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxXrOcL08BTTQixEno8GwAAABw"]
[Thu Sep 17 15:12:12.256026 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxXrOcL08BTTQixEno8HAAAAHo"]
[Thu Sep 17 15:12:12.275221 2026] [security2:error] [pid 971102:tid 971348] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxXrOcL08BTTQixEno8HwAAAHI"]
[Thu Sep 17 15:12:12.293734 2026] [security2:error] [pid 971102:tid 971325] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxXrOcL08BTTQixEno8IQAAAFs"]
[Thu Sep 17 15:12:12.296794 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno76wAANgM"]
[Thu Sep 17 15:12:12.298527 2026] [security2:error] [pid 971102:tid 971221] [remote 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno75gAANnQ"]
[Thu Sep 17 15:12:12.300331 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno77AAANgw"]
[Thu Sep 17 15:12:12.308532 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno77QAANnc"]
[Thu Sep 17 15:12:12.312218 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno76AAANgQ"]
[Thu Sep 17 15:12:12.313111 2026] [security2:error] [pid 971102:tid 971337] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxXrOcL08BTTQixEno8JgAAAGc"]
[Thu Sep 17 15:12:12.314651 2026] [core:error] [pid 971102:tid 971285] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:12.314676 2026] [core:error] [pid 971102:tid 971285] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:12.322481 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78wAANmI"]
[Thu Sep 17 15:12:12.329043 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/gcp/.env"] [unique_id "aqxXrOcL08BTTQixEno8KgAAAEY"]
[Thu Sep 17 15:12:12.331723 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno75wAANnM"]
[Thu Sep 17 15:12:12.332524 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78QAANnU"]
[Thu Sep 17 15:12:12.333668 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno77wAANm4"]
[Thu Sep 17 15:12:12.337907 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78AAANg4"]
[Thu Sep 17 15:12:12.340370 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79QAANhY"]
[Thu Sep 17 15:12:12.340484 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79AAANgY"]
[Thu Sep 17 15:12:12.341444 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxXrOcL08BTTQixEno8KwAAAHU"]
[Thu Sep 17 15:12:12.343539 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno75QAANnk"]
[Thu Sep 17 15:12:12.349596 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79gAANgU"]
[Thu Sep 17 15:12:12.362472 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79wAANns"]
[Thu Sep 17 15:12:12.363902 2026] [security2:error] [pid 971102:tid 971246] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxXrOcL08BTTQixEno8LQAAAAw"]
[Thu Sep 17 15:12:12.365033 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78gAANgI"]
[Thu Sep 17 15:12:12.394937 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxXrOcL08BTTQixEno8LgAAAGY"]
[Thu Sep 17 15:12:12.408074 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxXrOcL08BTTQixEno8LwAAAEk"]
[Thu Sep 17 15:12:12.418330 2026] [security2:error] [pid 971102:tid 971335] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxXrOcL08BTTQixEno8MAAAAGU"]
[Thu Sep 17 15:12:12.431504 2026] [security2:error] [pid 971102:tid 971253] [client 185.55.149.49:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8MQAAABM"]
[Thu Sep 17 15:12:12.431583 2026] [security2:error] [pid 971102:tid 971253] [client 185.55.149.49:65281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8MQAAABM"]
[Thu Sep 17 15:12:12.441960 2026] [security2:error] [pid 971102:tid 971266] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxXrOcL08BTTQixEno8MgAAACA"]
[Thu Sep 17 15:12:12.470073 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxXrOcL08BTTQixEno8MwAAAH8"]
[Thu Sep 17 15:12:12.471179 2026] [security2:error] [pid 971102:tid 971289] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxXrOcL08BTTQixEno8NAAAADc"]
[Thu Sep 17 15:12:12.486011 2026] [security2:error] [pid 971102:tid 971302] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cloud/.env"] [unique_id "aqxXrOcL08BTTQixEno8OAAAAEQ"]
[Thu Sep 17 15:12:12.491522 2026] [security2:error] [pid 971102:tid 971315] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxXrOcL08BTTQixEno8OwAAAFE"]
[Thu Sep 17 15:12:12.525066 2026] [security2:error] [pid 971102:tid 971274] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxXrOcL08BTTQixEno8QgAAACg"]
[Thu Sep 17 15:12:12.550439 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxXrOcL08BTTQixEno8QwAAAFA"]
[Thu Sep 17 15:12:12.567644 2026] [security2:error] [pid 971102:tid 971123] [remote 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8NwAAexM"]
[Thu Sep 17 15:12:12.568523 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8NgAAewo"]
[Thu Sep 17 15:12:12.570103 2026] [security2:error] [pid 971102:tid 971352] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxXrOcL08BTTQixEno8RQAAAHY"]
[Thu Sep 17 15:12:12.570513 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8NQAAewc"]
[Thu Sep 17 15:12:12.576444 2026] [authz_core:error] [pid 971102:tid 971305] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/ChaCha20/error_log
[Thu Sep 17 15:12:12.577907 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxXrOcL08BTTQixEno8RAAAAEc"]
[Thu Sep 17 15:12:12.588400 2026] [security2:error] [pid 971102:tid 971349] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxXrOcL08BTTQixEno8RgAAAHM"]
[Thu Sep 17 15:12:12.589016 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8OQAAexI"]
[Thu Sep 17 15:12:12.589388 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8OgAAexc"]
[Thu Sep 17 15:12:12.594344 2026] [security2:error] [pid 971102:tid 971319] [client 208.109.3.10:37738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8FwAAAFU"]
[Thu Sep 17 15:12:12.602325 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8PQAAexE"]
[Thu Sep 17 15:12:12.605042 2026] [security2:error] [pid 971102:tid 971317] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxXrOcL08BTTQixEno8SAAAAFM"]
[Thu Sep 17 15:12:12.607371 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8PgAAewk"]
[Thu Sep 17 15:12:12.607788 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8PwAAeyA"]
[Thu Sep 17 15:12:12.610537 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8QQAAexg"]
[Thu Sep 17 15:12:12.610866 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8QAAAexk"]
[Thu Sep 17 15:12:12.626014 2026] [security2:error] [pid 971102:tid 971341] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxXrOcL08BTTQixEno8SQAAAGs"]
[Thu Sep 17 15:12:12.636026 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/infrastructure/.env"] [unique_id "aqxXrOcL08BTTQixEno8SgAAADA"]
[Thu Sep 17 15:12:12.647339 2026] [security2:error] [pid 971102:tid 971275] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxXrOcL08BTTQixEno8SwAAACk"]
[Thu Sep 17 15:12:12.662238 2026] [security2:error] [pid 971102:tid 971360] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxXrOcL08BTTQixEno8VQAAAH4"]
[Thu Sep 17 15:12:12.681051 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxXrOcL08BTTQixEno8VgAAAC8"]
[Thu Sep 17 15:12:12.698017 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxXrOcL08BTTQixEno8VwAAAG8"]
[Thu Sep 17 15:12:12.702719 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxXrOcL08BTTQixEno8WQAAAF4"]
[Thu Sep 17 15:12:12.718668 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxXrOcL08BTTQixEno8XAAAAHE"]
[Thu Sep 17 15:12:12.725903 2026] [security2:error] [pid 971102:tid 971270] [client 115.244.164.14:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8XQAAACQ"]
[Thu Sep 17 15:12:12.725998 2026] [security2:error] [pid 971102:tid 971270] [client 115.244.164.14:53448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8XQAAACQ"]
[Thu Sep 17 15:12:12.734920 2026] [security2:error] [pid 971102:tid 971294] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxXrOcL08BTTQixEno8XgAAADw"]
[Thu Sep 17 15:12:12.741671 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXrOcL08BTTQixEno8XwAAADI"]
[Thu Sep 17 15:12:12.755317 2026] [security2:error] [pid 971102:tid 971256] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxXrOcL08BTTQixEno8YQAAABY"]
[Thu Sep 17 15:12:12.773719 2026] [security2:error] [pid 971102:tid 971290] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxXrOcL08BTTQixEno8ZAAAADg"]
[Thu Sep 17 15:12:12.785702 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/docker/.env"] [unique_id "aqxXrOcL08BTTQixEno8ZwAAADQ"]
[Thu Sep 17 15:12:12.795957 2026] [security2:error] [pid 971102:tid 971298] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxXrOcL08BTTQixEno8aQAAAEA"]
[Thu Sep 17 15:12:12.796567 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/phpinfo.php"] [unique_id "aqxXrOcL08BTTQixEno8awAAKiY"]
[Thu Sep 17 15:12:12.799058 2026] [security2:error] [pid 971102:tid 971229] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/info.php"] [unique_id "aqxXrOcL08BTTQixEno8bQAAKnw"]
[Thu Sep 17 15:12:12.812061 2026] [security2:error] [pid 971102:tid 971239] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxXrOcL08BTTQixEno8bgAAAAU"]
[Thu Sep 17 15:12:12.828615 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxXrOcL08BTTQixEno8cAAAAFw"]
[Thu Sep 17 15:12:12.844450 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxXrOcL08BTTQixEno8cwAAACY"]
[Thu Sep 17 15:12:12.859802 2026] [security2:error] [pid 971102:tid 971353] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxXrOcL08BTTQixEno8dAAAAHc"]
[Thu Sep 17 15:12:12.882065 2026] [security2:error] [pid 971102:tid 971265] [client 197.200.250.116:42728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8WAAAAB8"]
[Thu Sep 17 15:12:12.925177 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/v1/.env"] [unique_id "aqxXrOcL08BTTQixEno8dgAAABA"]
[Thu Sep 17 15:12:12.928513 2026] [security2:error] [pid 971102:tid 971261] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxXrOcL08BTTQixEno8dwAAABs"]
[Thu Sep 17 15:12:12.935270 2026] [security2:error] [pid 971102:tid 971258] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/k8s/.env"] [unique_id "aqxXrOcL08BTTQixEno8ewAAABg"]
[Thu Sep 17 15:12:12.951193 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxXrOcL08BTTQixEno8fgAAAEs"]
[Thu Sep 17 15:12:12.975896 2026] [security2:error] [pid 971102:tid 971130] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/infos.php"] [unique_id "aqxXrOcL08BTTQixEno8gQAAKho"]
[Thu Sep 17 15:12:12.978096 2026] [security2:error] [pid 971102:tid 971334] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxXrOcL08BTTQixEno8ggAAAGQ"]
[Thu Sep 17 15:12:12.978977 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/php_info.php"] [unique_id "aqxXrOcL08BTTQixEno8gwAAKkE"]
[Thu Sep 17 15:12:13.001165 2026] [security2:error] [pid 971102:tid 971292] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxXrOcL08BTTQixEno8hAAAADo"]
[Thu Sep 17 15:12:13.025423 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxXrecL08BTTQixEno8hwAAAHA"]
[Thu Sep 17 15:12:13.050274 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxXrecL08BTTQixEno8iAAAAGk"]
[Thu Sep 17 15:12:13.078515 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxXrecL08BTTQixEno8iQAAAG0"]
[Thu Sep 17 15:12:13.091242 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/kubernetes/.env"] [unique_id "aqxXrecL08BTTQixEno8igAAAEg"]
[Thu Sep 17 15:12:13.101432 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxXrecL08BTTQixEno8jAAAAAQ"]
[Thu Sep 17 15:12:13.103887 2026] [core:error] [pid 971102:tid 971278] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:13.103908 2026] [core:error] [pid 971102:tid 971278] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:13.114294 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8dQAAAGM"]
[Thu Sep 17 15:12:13.114316 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8dQAAAGM"]
[Thu Sep 17 15:12:13.125118 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxXrecL08BTTQixEno8jQAAABw"]
[Thu Sep 17 15:12:13.151952 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/v2/.env"] [unique_id "aqxXrecL08BTTQixEno8kAAAAD0"]
[Thu Sep 17 15:12:13.151965 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxXrecL08BTTQixEno8jwAAAHo"]
[Thu Sep 17 15:12:13.154836 2026] [security2:error] [pid 971102:tid 971144] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/php.php"] [unique_id "aqxXrecL08BTTQixEno8kQAAKig"]
[Thu Sep 17 15:12:13.157818 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/php-info.php"] [unique_id "aqxXrecL08BTTQixEno8kgAAKjY"]
[Thu Sep 17 15:12:13.174062 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxXrecL08BTTQixEno8kwAAAEI"]
[Thu Sep 17 15:12:13.199572 2026] [security2:error] [pid 971102:tid 971267] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxXrecL08BTTQixEno8lAAAACE"]
[Thu Sep 17 15:12:13.221911 2026] [security2:error] [pid 971102:tid 971279] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxXrecL08BTTQixEno8lwAAAC0"]
[Thu Sep 17 15:12:13.223412 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.117.146:35160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8TgAAAAc"]
[Thu Sep 17 15:12:13.243623 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxXrecL08BTTQixEno8mAAAADM"]
[Thu Sep 17 15:12:13.251036 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/terraform/.env"] [unique_id "aqxXrecL08BTTQixEno8mQAAAGg"]
[Thu Sep 17 15:12:13.257114 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxXrecL08BTTQixEno8mgAAAE4"]
[Thu Sep 17 15:12:13.257247 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxXrecL08BTTQixEno8mgAAAE4"]
[Thu Sep 17 15:12:13.273253 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxXrecL08BTTQixEno8mwAAABI"]
[Thu Sep 17 15:12:13.297251 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxXrecL08BTTQixEno8nAAAAEY"]
[Thu Sep 17 15:12:13.310048 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UQAAKjE"]
[Thu Sep 17 15:12:13.310169 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UgAAKiE"]
[Thu Sep 17 15:12:13.310219 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8VAAAKiw"]
[Thu Sep 17 15:12:13.310332 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UwAAKn8"]
[Thu Sep 17 15:12:13.310384 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8TwAAKgs"]
[Thu Sep 17 15:12:13.310573 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UAAAKg0"]
[Thu Sep 17 15:12:13.319945 2026] [security2:error] [pid 971102:tid 971342] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxXrecL08BTTQixEno8ngAAAGw"]
[Thu Sep 17 15:12:13.334936 2026] [security2:error] [pid 971102:tid 971173] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/infophp.php"] [unique_id "aqxXrecL08BTTQixEno8oAAAKkU"]
[Thu Sep 17 15:12:13.342976 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxXrecL08BTTQixEno8ogAAAB0"]
[Thu Sep 17 15:12:13.356823 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8aAAAKi0"]
[Thu Sep 17 15:12:13.356952 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8agAAKh8"]
[Thu Sep 17 15:12:13.357940 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8bAAAKhw"]
[Thu Sep 17 15:12:13.359007 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8YgAAKik"]
[Thu Sep 17 15:12:13.359261 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8YAAAKhQ"]
[Thu Sep 17 15:12:13.360555 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8ZQAAKh4"]
[Thu Sep 17 15:12:13.366475 2026] [security2:error] [pid 971102:tid 971291] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxXrecL08BTTQixEno8owAAADk"]
[Thu Sep 17 15:12:13.372374 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8ZgAAKiQ"]
[Thu Sep 17 15:12:13.372473 2026] [security2:error] [pid 971102:tid 971296] [client 74.7.230.60:49382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "4p4x.com"] [uri "/robots.txt"] [unique_id "aqxXrecL08BTTQixEno8pAAAAD4"]
[Thu Sep 17 15:12:13.373564 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8YwAAKjI"]
[Thu Sep 17 15:12:13.379174 2026] [security2:error] [pid 971102:tid 971288] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/rest/.env"] [unique_id "aqxXrecL08BTTQixEno8pQAAADY"]
[Thu Sep 17 15:12:13.388825 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxXrecL08BTTQixEno8pgAAAGY"]
[Thu Sep 17 15:12:13.414910 2026] [security2:error] [pid 971102:tid 971253] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxXrecL08BTTQixEno8pwAAABM"]
[Thu Sep 17 15:12:13.414963 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/ansible/.env"] [unique_id "aqxXrecL08BTTQixEno8qAAAACA"]
[Thu Sep 17 15:12:13.429362 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8oQAAKio"]
[Thu Sep 17 15:12:13.438264 2026] [security2:error] [pid 971102:tid 971361] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxXrecL08BTTQixEno8qwAAAH8"]
[Thu Sep 17 15:12:13.449522 2026] [security2:error] [pid 971102:tid 971316] [client 47.79.200.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8gAAAAFI"], referer: https://www.google.com/
[Thu Sep 17 15:12:13.461411 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxXrecL08BTTQixEno8rAAAAHw"]
[Thu Sep 17 15:12:13.485220 2026] [security2:error] [pid 971102:tid 971257] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxXrecL08BTTQixEno8rwAAABc"]
[Thu Sep 17 15:12:13.489561 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8sAAAPxU"]
[Thu Sep 17 15:12:13.489581 2026] [security2:error] [pid 971102:tid 971141] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8sgAAPyU"]
[Thu Sep 17 15:12:13.489590 2026] [security2:error] [pid 971102:tid 971147] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8sQAAPys"]
[Thu Sep 17 15:12:13.489878 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/api/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8swAAPxU"]
[Thu Sep 17 15:12:13.489951 2026] [security2:error] [pid 971102:tid 971152] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8tAAAPzA"]
[Thu Sep 17 15:12:13.510528 2026] [security2:error] [pid 971102:tid 971274] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxXrecL08BTTQixEno8tgAAACg"]
[Thu Sep 17 15:12:13.532866 2026] [security2:error] [pid 971102:tid 971352] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxXrecL08BTTQixEno8uwAAAHY"]
[Thu Sep 17 15:12:13.547059 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:51394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXrecL08BTTQixEno8wgAAAHM"]
[Thu Sep 17 15:12:13.547219 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:51394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXrecL08BTTQixEno8wgAAAHM"]
[Thu Sep 17 15:12:13.554218 2026] [security2:error] [pid 971102:tid 971172] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/database.sql"] [unique_id "aqxXrecL08BTTQixEno8wwAAGkQ"]
[Thu Sep 17 15:12:13.556426 2026] [security2:error] [pid 971102:tid 971249] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxXrecL08BTTQixEno8xQAAAA8"]
[Thu Sep 17 15:12:13.570217 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.git/.env"] [unique_id "aqxXrecL08BTTQixEno8xgAAAFU"]
[Thu Sep 17 15:12:13.579211 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxXrecL08BTTQixEno8xwAAAHs"]
[Thu Sep 17 15:12:13.593823 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8tQAAGjk"]
[Thu Sep 17 15:12:13.610964 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/graphql/.env"] [unique_id "aqxXrecL08BTTQixEno8yQAAAF8"]
[Thu Sep 17 15:12:13.611312 2026] [security2:error] [pid 971102:tid 971282] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxXrecL08BTTQixEno8ygAAADA"]
[Thu Sep 17 15:12:13.627576 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vgAAGj4"]
[Thu Sep 17 15:12:13.627715 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vAAAGkA"]
[Thu Sep 17 15:12:13.627814 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8wQAAGko"]
[Thu Sep 17 15:12:13.627855 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vwAAGkg"]
[Thu Sep 17 15:12:13.630462 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vQAAGlM"]
[Thu Sep 17 15:12:13.630590 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8wAAAGiI"]
[Thu Sep 17 15:12:13.638308 2026] [security2:error] [pid 971102:tid 971275] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxXrecL08BTTQixEno8zQAAACk"]
[Thu Sep 17 15:12:13.649942 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8xAAAGj8"]
[Thu Sep 17 15:12:13.673849 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxXrecL08BTTQixEno80wAAAAE"]
[Thu Sep 17 15:12:13.696597 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8ywAAGlE"]
[Thu Sep 17 15:12:13.702325 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxXrecL08BTTQixEno81AAAAF4"]
[Thu Sep 17 15:12:13.729888 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxXrecL08BTTQixEno81gAAACM"]
[Thu Sep 17 15:12:13.731579 2026] [security2:error] [pid 971102:tid 971254] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/ci/.env"] [unique_id "aqxXrecL08BTTQixEno81wAAABQ"]
[Thu Sep 17 15:12:13.750440 2026] [security2:error] [pid 971102:tid 971290] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxXrecL08BTTQixEno82QAAADg"]
[Thu Sep 17 15:12:13.772291 2026] [security2:error] [pid 971102:tid 971286] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxXrecL08BTTQixEno82gAAADQ"]
[Thu Sep 17 15:12:13.793934 2026] [security2:error] [pid 971102:tid 971298] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxXrecL08BTTQixEno83AAAAEA"]
[Thu Sep 17 15:12:13.807124 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/wp-config.backup.php"] [unique_id "aqxXrecL08BTTQixEno83wAAGjc"]
[Thu Sep 17 15:12:13.809369 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.130.148:44884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aqxXrecL08BTTQixEno84QAAAAk"]
[Thu Sep 17 15:12:13.819097 2026] [security2:error] [pid 971102:tid 971239] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxXrecL08BTTQixEno85QAAAAU"]
[Thu Sep 17 15:12:13.843747 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxXrecL08BTTQixEno86AAAAFw"]
[Thu Sep 17 15:12:13.843829 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxXrecL08BTTQixEno86AAAAFw"]
[Thu Sep 17 15:12:13.844207 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxXrecL08BTTQixEno85wAAACY"]
[Thu Sep 17 15:12:13.844927 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/gateway/.env"] [unique_id "aqxXrecL08BTTQixEno86QAAAHc"]
[Thu Sep 17 15:12:13.866411 2026] [security2:error] [pid 971102:tid 971261] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxXrecL08BTTQixEno87AAAABs"]
[Thu Sep 17 15:12:13.887373 2026] [security2:error] [pid 971102:tid 971258] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxXrecL08BTTQixEno87gAAABg"]
[Thu Sep 17 15:12:13.888200 2026] [security2:error] [pid 971102:tid 971309] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cd/.env"] [unique_id "aqxXrecL08BTTQixEno87wAAAEs"]
[Thu Sep 17 15:12:13.908626 2026] [security2:error] [pid 971102:tid 971264] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxXrecL08BTTQixEno88AAAAB4"]
[Thu Sep 17 15:12:13.930988 2026] [security2:error] [pid 971102:tid 971248] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxXrecL08BTTQixEno89AAAAA4"]
[Thu Sep 17 15:12:13.952844 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxXrecL08BTTQixEno89QAAAHA"]
[Thu Sep 17 15:12:13.974305 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxXrecL08BTTQixEno89wAAAGk"]
[Thu Sep 17 15:12:13.997391 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxXrecL08BTTQixEno8-wAAAEo"]
[Thu Sep 17 15:12:14.018643 2026] [security2:error] [pid 971102:tid 971320] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxXrucL08BTTQixEno8_AAAAFY"]
[Thu Sep 17 15:12:14.041929 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxXrucL08BTTQixEno8_QAAAEg"]
[Thu Sep 17 15:12:14.043145 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.130.148:44884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aqxXrucL08BTTQixEno8_gAAAH0"]
[Thu Sep 17 15:12:14.048407 2026] [security2:error] [pid 971102:tid 971238] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/jenkins/.env"] [unique_id "aqxXrucL08BTTQixEno8_wAAAAQ"]
[Thu Sep 17 15:12:14.067113 2026] [security2:error] [pid 971102:tid 971278] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxXrucL08BTTQixEno9AAAAACw"]
[Thu Sep 17 15:12:14.071984 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/microservice/.env"] [unique_id "aqxXrucL08BTTQixEno9AQAAAAs"]
[Thu Sep 17 15:12:14.076786 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.117.146:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/p.php"] [unique_id "aqxXrucL08BTTQixEno9AwAAAGI"]
[Thu Sep 17 15:12:14.089254 2026] [security2:error] [pid 971102:tid 971311] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxXrucL08BTTQixEno9BAAAAE0"]
[Thu Sep 17 15:12:14.111946 2026] [security2:error] [pid 971102:tid 971273] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxXrucL08BTTQixEno9BQAAACc"]
[Thu Sep 17 15:12:14.125575 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxXrucL08BTTQixEno9BgAAAGM"]
[Thu Sep 17 15:12:14.146068 2026] [security2:error] [pid 971102:tid 971322] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxXrucL08BTTQixEno9BwAAAFg"]
[Thu Sep 17 15:12:14.166807 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxXrucL08BTTQixEno9CgAAAHo"]
[Thu Sep 17 15:12:14.190972 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxXrucL08BTTQixEno9DAAAAEI"]
[Thu Sep 17 15:12:14.206271 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/gitlab/.env"] [unique_id "aqxXrucL08BTTQixEno9DQAAAAg"]
[Thu Sep 17 15:12:14.215739 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxXrucL08BTTQixEno9DwAAAFk"]
[Thu Sep 17 15:12:14.238319 2026] [security2:error] [pid 971102:tid 971267] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxXrucL08BTTQixEno9EAAAACE"]
[Thu Sep 17 15:12:14.261172 2026] [security2:error] [pid 971102:tid 971348] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxXrucL08BTTQixEno9EQAAAHI"]
[Thu Sep 17 15:12:14.288167 2026] [security2:error] [pid 971102:tid 971325] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxXrucL08BTTQixEno9FQAAAFs"]
[Thu Sep 17 15:12:14.293530 2026] [authz_core:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/error_log
[Thu Sep 17 15:12:14.298844 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/service/.env"] [unique_id "aqxXrucL08BTTQixEno9FgAAABU"]
[Thu Sep 17 15:12:14.304793 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxXrucL08BTTQixEno9EgAAADU"]
[Thu Sep 17 15:12:14.313151 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxXrucL08BTTQixEno9FwAAADM"]
[Thu Sep 17 15:12:14.322158 2026] [security2:error] [pid 971102:tid 971283] [client 209.59.91.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9CwAAADE"], referer: http://m.facebook.com
[Thu Sep 17 15:12:14.332613 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8zgAAGkk"]
[Thu Sep 17 15:12:14.332754 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno80gAAGj0"]
[Thu Sep 17 15:12:14.344843 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno80QAAGic"]
[Thu Sep 17 15:12:14.345088 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxXrucL08BTTQixEno9GAAAABI"]
[Thu Sep 17 15:12:14.350108 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8zwAAGkc"]
[Thu Sep 17 15:12:14.352389 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno80AAAGi8"]
[Thu Sep 17 15:12:14.361651 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/github/.env"] [unique_id "aqxXrucL08BTTQixEno9GgAAACU"]
[Thu Sep 17 15:12:14.363831 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno82wAAGk4"]
[Thu Sep 17 15:12:14.364001 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno83QAAGk8"]
[Thu Sep 17 15:12:14.364372 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno87QAAGjs"]
[Thu Sep 17 15:12:14.364524 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno84AAAGks"]
[Thu Sep 17 15:12:14.366237 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno84wAAGkI"]
[Thu Sep 17 15:12:14.367508 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno83gAAGkw"]
[Thu Sep 17 15:12:14.368854 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno85gAAGlo"]
[Thu Sep 17 15:12:14.369259 2026] [security2:error] [pid 971102:tid 971205] [remote 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno85AAAGmQ"]
[Thu Sep 17 15:12:14.375547 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxXrucL08BTTQixEno9HAAAAB0"]
[Thu Sep 17 15:12:14.381200 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno84gAAGlA"]
[Thu Sep 17 15:12:14.384945 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8-gAAGlg"]
[Thu Sep 17 15:12:14.386948 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno82AAAGjw"]
[Thu Sep 17 15:12:14.400355 2026] [security2:error] [pid 971102:tid 971288] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxXrucL08BTTQixEno9HgAAADY"]
[Thu Sep 17 15:12:14.401814 2026] [core:error] [pid 971102:tid 971291] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:14.401827 2026] [core:error] [pid 971102:tid 971291] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:14.425384 2026] [security2:error] [pid 971102:tid 971276] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxXrucL08BTTQixEno9HwAAACo"]
[Thu Sep 17 15:12:14.445166 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXrucL08BTTQixEno9IQAAAH8"]
[Thu Sep 17 15:12:14.447514 2026] [security2:error] [pid 971102:tid 971335] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxXrucL08BTTQixEno9IgAAAGU"]
[Thu Sep 17 15:12:14.467099 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxXrucL08BTTQixEno9IwAAAFI"]
[Thu Sep 17 15:12:14.485957 2026] [security2:error] [pid 971102:tid 971302] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxXrucL08BTTQixEno9JAAAAEQ"]
[Thu Sep 17 15:12:14.522999 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxXrucL08BTTQixEno9JwAAAHw"]
[Thu Sep 17 15:12:14.524820 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/v3/.env"] [unique_id "aqxXrucL08BTTQixEno9KAAAABc"]
[Thu Sep 17 15:12:14.525524 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/actions/.env"] [unique_id "aqxXrucL08BTTQixEno9KgAAAE8"]
[Thu Sep 17 15:12:14.564104 2026] [security2:error] [pid 971102:tid 971208] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/sites/default/settings.local.php"] [unique_id "aqxXrucL08BTTQixEno9NgAAUWc"]
[Thu Sep 17 15:12:14.565054 2026] [security2:error] [pid 971102:tid 971162] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/vendor/.env"] [unique_id "aqxXrucL08BTTQixEno9MQAAUTo"]
[Thu Sep 17 15:12:14.565181 2026] [security2:error] [pid 971102:tid 971355] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxXrucL08BTTQixEno9NwAAAHk"]
[Thu Sep 17 15:12:14.565868 2026] [authz_core:error] [pid 971102:tid 971213] [remote 45.138.12.28:33672] AH01630: client denied by server configuration: /home4/drivihap/public_html/sqlerudition/.htpasswd
[Thu Sep 17 15:12:14.594064 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxXrucL08BTTQixEno9OgAAAFA"]
[Thu Sep 17 15:12:14.595810 2026] [security2:error] [pid 971102:tid 971354] [client 104.28.198.244:22911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrucL08BTTQixEno9OwAAAHg"]
[Thu Sep 17 15:12:14.595956 2026] [security2:error] [pid 971102:tid 971354] [client 104.28.198.244:22911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrucL08BTTQixEno9OwAAAHg"]
[Thu Sep 17 15:12:14.613299 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9JgAAUV4"]
[Thu Sep 17 15:12:14.618890 2026] [security2:error] [pid 971102:tid 971301] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxXrucL08BTTQixEno9PAAAAEM"]
[Thu Sep 17 15:12:14.678731 2026] [security2:error] [pid 971102:tid 971319] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxXrucL08BTTQixEno9PQAAAFU"]
[Thu Sep 17 15:12:14.680806 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/circleci/.env"] [unique_id "aqxXrucL08BTTQixEno9PgAAAHs"]
[Thu Sep 17 15:12:14.707367 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxXrucL08BTTQixEno9PwAAAA0"]
[Thu Sep 17 15:12:14.726700 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxXrucL08BTTQixEno9QAAAACs"]
[Thu Sep 17 15:12:14.747184 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxXrucL08BTTQixEno9RAAAAHU"]
[Thu Sep 17 15:12:14.747235 2026] [security2:error] [pid 971102:tid 971198] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/panel/.env"] [unique_id "aqxXrucL08BTTQixEno9RgAAUV0"]
[Thu Sep 17 15:12:14.749996 2026] [security2:error] [pid 971102:tid 971274] [client 5.255.106.237:51448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.daristore.com"] [uri "/"] [unique_id "aqxXrucL08BTTQixEno9SAAAACg"]
[Thu Sep 17 15:12:14.751743 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/dev/.env"] [unique_id "aqxXrucL08BTTQixEno9SQAAADA"]
[Thu Sep 17 15:12:14.775336 2026] [security2:error] [pid 971102:tid 971305] [client 5.255.106.237:51462] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "daristore.com"] [uri "/mail"] [unique_id "aqxXrucL08BTTQixEno9SgAAAEc"]
[Thu Sep 17 15:12:14.787362 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9OQAAAD8"]
[Thu Sep 17 15:12:14.787378 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9OQAAAD8"]
[Thu Sep 17 15:12:14.795232 2026] [security2:error] [pid 971102:tid 971349] [client 5.255.106.237:51482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.daristore.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxXrucL08BTTQixEno9TAAAAHM"]
[Thu Sep 17 15:12:14.796144 2026] [security2:error] [pid 971102:tid 971249] [client 5.255.106.237:51476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "daristore.com"] [uri "/webmail"] [unique_id "aqxXrucL08BTTQixEno9TQAAAA8"]
[Thu Sep 17 15:12:14.798171 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.local.swp"] [unique_id "aqxXrucL08BTTQixEno9TgAAUW0"]
[Thu Sep 17 15:12:14.837163 2026] [security2:error] [pid 971102:tid 971328] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/travis/.env"] [unique_id "aqxXrucL08BTTQixEno9UQAAAF4"]
[Thu Sep 17 15:12:14.917064 2026] [security2:error] [pid 971102:tid 971284] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxXrucL08BTTQixEno9UwAAADI"]
[Thu Sep 17 15:12:14.927184 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxXrucL08BTTQixEno9VQAAACM"]
[Thu Sep 17 15:12:14.927272 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxXrucL08BTTQixEno9VQAAACM"]
[Thu Sep 17 15:12:14.962591 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/debug.php"] [unique_id "aqxXrucL08BTTQixEno9VgAAAF8"]
[Thu Sep 17 15:12:14.978948 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/staging/.env"] [unique_id "aqxXrucL08BTTQixEno9VwAAAEU"]
[Thu Sep 17 15:12:14.987892 2026] [security2:error] [pid 971102:tid 971243] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxXrucL08BTTQixEno9WAAAAAk"]
[Thu Sep 17 15:12:14.990039 2026] [security2:error] [pid 971102:tid 971261] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/buildkite/.env"] [unique_id "aqxXrucL08BTTQixEno9WQAAABs"]
[Thu Sep 17 15:12:15.026099 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxXr-cL08BTTQixEno9WgAAAEs"]
[Thu Sep 17 15:12:15.052468 2026] [security2:error] [pid 971102:tid 971292] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxXr-cL08BTTQixEno9XQAAADo"]
[Thu Sep 17 15:12:15.082772 2026] [security2:error] [pid 971102:tid 971318] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxXr-cL08BTTQixEno9XgAAAFQ"]
[Thu Sep 17 15:12:15.105926 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxXr-cL08BTTQixEno9XwAAAEo"]
[Thu Sep 17 15:12:15.116293 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.130.148:60306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aqxXr-cL08BTTQixEno9YAAAADw"]
[Thu Sep 17 15:12:15.136091 2026] [security2:error] [pid 971102:tid 971334] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxXr-cL08BTTQixEno9YQAAAGQ"]
[Thu Sep 17 15:12:15.146760 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mysql/.env"] [unique_id "aqxXr-cL08BTTQixEno9YgAAAH0"]
[Thu Sep 17 15:12:15.160136 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxXr-cL08BTTQixEno9YwAAAAQ"]
[Thu Sep 17 15:12:15.177725 2026] [security2:error] [pid 971102:tid 971327] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxXr-cL08BTTQixEno9ZAAAAF0"]
[Thu Sep 17 15:12:15.201651 2026] [security2:error] [pid 971102:tid 971278] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxXr-cL08BTTQixEno9ZQAAACw"]
[Thu Sep 17 15:12:15.204227 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/vendor/.env"] [unique_id "aqxXr-cL08BTTQixEno9ZgAAABE"]
[Thu Sep 17 15:12:15.217554 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxXr-cL08BTTQixEno9ZwAAAAs"]
[Thu Sep 17 15:12:15.221685 2026] [security2:error] [pid 971102:tid 971324] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxXr-cL08BTTQixEno9aAAAAFo"]
[Thu Sep 17 15:12:15.251478 2026] [security2:error] [pid 971102:tid 971332] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxXr-cL08BTTQixEno9aQAAAGI"]
[Thu Sep 17 15:12:15.257866 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9JQAAUVU"]
[Thu Sep 17 15:12:15.260600 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9KQAAUVw"]
[Thu Sep 17 15:12:15.274598 2026] [security2:error] [pid 971102:tid 971250] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxXr-cL08BTTQixEno9agAAABA"]
[Thu Sep 17 15:12:15.297790 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxXr-cL08BTTQixEno9awAAAAY"]
[Thu Sep 17 15:12:15.299709 2026] [security2:error] [pid 971102:tid 971265] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/postgres/.env"] [unique_id "aqxXr-cL08BTTQixEno9bAAAAB8"]
[Thu Sep 17 15:12:15.299801 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9KwAAUVQ"]
[Thu Sep 17 15:12:15.302845 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9NAAAUWs"]
[Thu Sep 17 15:12:15.303085 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LQAAUVI"]
[Thu Sep 17 15:12:15.303140 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LAAAUWU"]
[Thu Sep 17 15:12:15.303873 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LwAAUVc"]
[Thu Sep 17 15:12:15.304145 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9MAAAUWA"]
[Thu Sep 17 15:12:15.304185 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9MgAAUXI"]
[Thu Sep 17 15:12:15.304218 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LgAAUWk"]
[Thu Sep 17 15:12:15.304257 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9OAAAUVY"]
[Thu Sep 17 15:12:15.306530 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9NQAAUVs"]
[Thu Sep 17 15:12:15.316166 2026] [security2:error] [pid 971102:tid 971273] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxXr-cL08BTTQixEno9bgAAACc"]
[Thu Sep 17 15:12:15.333289 2026] [security2:error] [pid 971102:tid 971333] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxXr-cL08BTTQixEno9bwAAAGM"]
[Thu Sep 17 15:12:15.349152 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9RQAAUXA"]
[Thu Sep 17 15:12:15.349239 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9RwAAUX0"]
[Thu Sep 17 15:12:15.351540 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxXr-cL08BTTQixEno9cQAAABw"]
[Thu Sep 17 15:12:15.368799 2026] [security2:error] [pid 971102:tid 971295] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxXr-cL08BTTQixEno9dAAAAD0"]
[Thu Sep 17 15:12:15.371246 2026] [authz_core:error] [pid 971102:tid 971344] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/error_log
[Thu Sep 17 15:12:15.373357 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxXr-cL08BTTQixEno9cwAAAG4"]
[Thu Sep 17 15:12:15.384715 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxXr-cL08BTTQixEno9eQAAAFk"]
[Thu Sep 17 15:12:15.386442 2026] [core:error] [pid 971102:tid 971234] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:15.386455 2026] [core:error] [pid 971102:tid 971234] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:15.407194 2026] [security2:error] [pid 971102:tid 971255] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxXr-cL08BTTQixEno9fAAAABU"]
[Thu Sep 17 15:12:15.425044 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxXr-cL08BTTQixEno9fQAAADM"]
[Thu Sep 17 15:12:15.429735 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/lib/.env"] [unique_id "aqxXr-cL08BTTQixEno9fgAAAGg"]
[Thu Sep 17 15:12:15.448948 2026] [security2:error] [pid 971102:tid 971312] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxXr-cL08BTTQixEno9gAAAAE4"]
[Thu Sep 17 15:12:15.449754 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mongodb/.env"] [unique_id "aqxXr-cL08BTTQixEno9gQAAABI"]
[Thu Sep 17 15:12:15.475037 2026] [security2:error] [pid 971102:tid 971337] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxXr-cL08BTTQixEno9ggAAAGc"]
[Thu Sep 17 15:12:15.498592 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxXr-cL08BTTQixEno9gwAAAB0"]
[Thu Sep 17 15:12:15.518645 2026] [security2:error] [pid 971102:tid 971296] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxXr-cL08BTTQixEno9hAAAAD4"]
[Thu Sep 17 15:12:15.521476 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxXr-cL08BTTQixEno9hQAAABo"]
[Thu Sep 17 15:12:15.542802 2026] [security2:error] [pid 971102:tid 971288] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxXr-cL08BTTQixEno9hgAAADY"]
[Thu Sep 17 15:12:15.567613 2026] [security2:error] [pid 971102:tid 971291] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxXr-cL08BTTQixEno9hwAAADk"]
[Thu Sep 17 15:12:15.596413 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.117.146:35186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXr-cL08BTTQixEno9iAAAAFs"]
[Thu Sep 17 15:12:15.597336 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxXr-cL08BTTQixEno9iQAAAGY"]
[Thu Sep 17 15:12:15.616747 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/redis/.env"] [unique_id "aqxXr-cL08BTTQixEno9igAAAAc"]
[Thu Sep 17 15:12:15.631881 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxXr-cL08BTTQixEno9iwAAAEk"]
[Thu Sep 17 15:12:15.662765 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/resources/.env"] [unique_id "aqxXr-cL08BTTQixEno9jQAAAGU"]
[Thu Sep 17 15:12:15.669883 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxXr-cL08BTTQixEno9jwAAAHw"]
[Thu Sep 17 15:12:15.694625 2026] [security2:error] [pid 971102:tid 971257] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxXr-cL08BTTQixEno9kQAAABc"]
[Thu Sep 17 15:12:15.725369 2026] [security2:error] [pid 971102:tid 971313] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxXr-cL08BTTQixEno9kgAAAE8"]
[Thu Sep 17 15:12:15.747371 2026] [security2:error] [pid 971102:tid 971355] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxXr-cL08BTTQixEno9kwAAAHk"]
[Thu Sep 17 15:12:15.771944 2026] [security2:error] [pid 971102:tid 971352] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/elasticsearch/.env"] [unique_id "aqxXr-cL08BTTQixEno9lAAAAHY"]
[Thu Sep 17 15:12:15.782754 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxXr-cL08BTTQixEno9lQAAAFA"]
[Thu Sep 17 15:12:15.803520 2026] [security2:error] [pid 971102:tid 971266] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxXr-cL08BTTQixEno9lgAAACA"]
[Thu Sep 17 15:12:15.824817 2026] [security2:error] [pid 971102:tid 971319] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxXr-cL08BTTQixEno9mAAAAFU"]
[Thu Sep 17 15:12:15.851567 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxXr-cL08BTTQixEno9mgAAAHs"]
[Thu Sep 17 15:12:15.860831 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXr-cL08BTTQixEno9jgAAAFI"]
[Thu Sep 17 15:12:15.860850 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXr-cL08BTTQixEno9jgAAAFI"]
[Thu Sep 17 15:12:15.873423 2026] [security2:error] [pid 971102:tid 971340] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxXr-cL08BTTQixEno9mwAAAGo"]
[Thu Sep 17 15:12:15.890754 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxXr-cL08BTTQixEno9nQAAAEY"]
[Thu Sep 17 15:12:15.898584 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/assets/.env"] [unique_id "aqxXr-cL08BTTQixEno9ngAAAA0"]
[Thu Sep 17 15:12:15.907197 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxXr-cL08BTTQixEno9nwAAAHU"]
[Thu Sep 17 15:12:15.921029 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/rabbitmq/.env"] [unique_id "aqxXr-cL08BTTQixEno9owAAAEc"]
[Thu Sep 17 15:12:15.923918 2026] [security2:error] [pid 971102:tid 971341] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxXr-cL08BTTQixEno9pAAAAGs"]
[Thu Sep 17 15:12:15.946814 2026] [security2:error] [pid 971102:tid 971293] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxXr-cL08BTTQixEno9pQAAADs"]
[Thu Sep 17 15:12:15.974135 2026] [security2:error] [pid 971102:tid 971349] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxXr-cL08BTTQixEno9pgAAAHM"]
[Thu Sep 17 15:12:15.993300 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxXr-cL08BTTQixEno9pwAAAAE"]
[Thu Sep 17 15:12:16.017435 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxXsOcL08BTTQixEno9qAAAAF4"]
[Thu Sep 17 15:12:16.024154 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:51418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXsOcL08BTTQixEno9qQAAACQ"]
[Thu Sep 17 15:12:16.024221 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXsOcL08BTTQixEno9qQAAACQ"]
[Thu Sep 17 15:12:16.034081 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxXsOcL08BTTQixEno9qgAAAAo"]
[Thu Sep 17 15:12:16.050822 2026] [security2:error] [pid 971102:tid 971256] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxXsOcL08BTTQixEno9qwAAABY"]
[Thu Sep 17 15:12:16.070285 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/kafka/.env"] [unique_id "aqxXsOcL08BTTQixEno9rAAAADI"]
[Thu Sep 17 15:12:16.071631 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxXsOcL08BTTQixEno9rQAAACM"]
[Thu Sep 17 15:12:16.094947 2026] [security2:error] [pid 971102:tid 971286] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxXsOcL08BTTQixEno9rgAAADQ"]
[Thu Sep 17 15:12:16.111741 2026] [security2:error] [pid 971102:tid 971239] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxXsOcL08BTTQixEno9rwAAAAU"]
[Thu Sep 17 15:12:16.127926 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/uploads/.env"] [unique_id "aqxXsOcL08BTTQixEno9sAAAAFw"]
[Thu Sep 17 15:12:16.138964 2026] [security2:error] [pid 971102:tid 971353] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxXsOcL08BTTQixEno9swAAAHc"]
[Thu Sep 17 15:12:16.155942 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxXsOcL08BTTQixEno9tAAAAEU"]
[Thu Sep 17 15:12:16.181786 2026] [security2:error] [pid 971102:tid 971261] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxXsOcL08BTTQixEno9tQAAABs"]
[Thu Sep 17 15:12:16.201958 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxXsOcL08BTTQixEno9tgAAAEs"]
[Thu Sep 17 15:12:16.219028 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxXsOcL08BTTQixEno9uQAAAGk"]
[Thu Sep 17 15:12:16.219748 2026] [security2:error] [pid 971102:tid 971318] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/queue/.env"] [unique_id "aqxXsOcL08BTTQixEno9ugAAAFQ"]
[Thu Sep 17 15:12:16.247260 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxXsOcL08BTTQixEno9uwAAAHE"]
[Thu Sep 17 15:12:16.250805 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:16.250823 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:16.267150 2026] [security2:error] [pid 971102:tid 971280] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxXsOcL08BTTQixEno9vQAAAC4"]
[Thu Sep 17 15:12:16.285137 2026] [security2:error] [pid 971102:tid 971259] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxXsOcL08BTTQixEno9vwAAABk"]
[Thu Sep 17 15:12:16.311204 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXsOcL08BTTQixEno9wgAAAEg"]
[Thu Sep 17 15:12:16.311334 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:51420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXsOcL08BTTQixEno9wgAAAEg"]
[Thu Sep 17 15:12:16.319136 2026] [security2:error] [pid 971102:tid 971359] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxXsOcL08BTTQixEno9xAAAAH0"]
[Thu Sep 17 15:12:16.343542 2026] [security2:error] [pid 971102:tid 971327] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxXsOcL08BTTQixEno9xQAAAF0"]
[Thu Sep 17 15:12:16.360943 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/internal/.env"] [unique_id "aqxXsOcL08BTTQixEno9xgAAACw"]
[Thu Sep 17 15:12:16.361083 2026] [security2:error] [pid 971102:tid 971251] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxXsOcL08BTTQixEno9xwAAABE"]
[Thu Sep 17 15:12:16.371789 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/worker/.env"] [unique_id "aqxXsOcL08BTTQixEno9yAAAAAs"]
[Thu Sep 17 15:12:16.378114 2026] [security2:error] [pid 971102:tid 971324] [client 8.228.10.213:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxXsOcL08BTTQixEno9yQAAAFo"]
[Thu Sep 17 15:12:16.400260 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:35200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXsOcL08BTTQixEno9ygAAACY"]
[Thu Sep 17 15:12:16.446346 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.10.213:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/info.php"] [unique_id "aqxXsOcL08BTTQixEno9zAAAAAY"]
[Thu Sep 17 15:12:16.509107 2026] [security2:error] [pid 971102:tid 971295] [client 8.228.10.213:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/php.php"] [unique_id "aqxXsOcL08BTTQixEno9zgAAAD0"]
[Thu Sep 17 15:12:16.522130 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/job/.env"] [unique_id "aqxXsOcL08BTTQixEno9zwAAAAA"]
[Thu Sep 17 15:12:16.573922 2026] [security2:error] [pid 971102:tid 971255] [client 8.228.10.213:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/i.php"] [unique_id "aqxXsOcL08BTTQixEno90QAAABU"]
[Thu Sep 17 15:12:16.591776 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/tools/.env"] [unique_id "aqxXsOcL08BTTQixEno90gAAADU"]
[Thu Sep 17 15:12:16.602189 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXsOcL08BTTQixEno90wAAAEI"]
[Thu Sep 17 15:12:16.602280 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:51434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXsOcL08BTTQixEno90wAAAEI"]
[Thu Sep 17 15:12:16.640771 2026] [security2:error] [pid 971102:tid 971338] [client 8.228.10.213:37478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxXsOcL08BTTQixEno91AAAAGg"]
[Thu Sep 17 15:12:16.672874 2026] [security2:error] [pid 971102:tid 971312] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/test/.env"] [unique_id "aqxXsOcL08BTTQixEno91QAAAE4"]
[Thu Sep 17 15:12:16.714767 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.10.213:37488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxXsOcL08BTTQixEno91gAAABI"]
[Thu Sep 17 15:12:16.773363 2026] [security2:error] [pid 971102:tid 971250] [client 186.105.232.15:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno92AAAABA"]
[Thu Sep 17 15:12:16.773510 2026] [security2:error] [pid 971102:tid 971250] [client 186.105.232.15:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno92AAAABA"]
[Thu Sep 17 15:12:16.801162 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/test.php"] [unique_id "aqxXsOcL08BTTQixEno92QAAAGY"]
[Thu Sep 17 15:12:16.818616 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/scripts/.env"] [unique_id "aqxXsOcL08BTTQixEno92gAAABM"]
[Thu Sep 17 15:12:16.822461 2026] [security2:error] [pid 971102:tid 971356] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/qa/.env"] [unique_id "aqxXsOcL08BTTQixEno93AAAAHo"]
[Thu Sep 17 15:12:16.883453 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXsOcL08BTTQixEno94wAAAHk"]
[Thu Sep 17 15:12:16.883590 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:51448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXsOcL08BTTQixEno94wAAAHk"]
[Thu Sep 17 15:12:16.929340 2026] [security2:error] [pid 971102:tid 971263] [client 114.198.138.124:60441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno95AAAAB0"]
[Thu Sep 17 15:12:16.929457 2026] [security2:error] [pid 971102:tid 971263] [client 114.198.138.124:60441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno95AAAAB0"]
[Thu Sep 17 15:12:16.935948 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/p.php"] [unique_id "aqxXsOcL08BTTQixEno95QAAAFA"]
[Thu Sep 17 15:12:16.974060 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/preview/.env"] [unique_id "aqxXsOcL08BTTQixEno96AAAAHs"]
[Thu Sep 17 15:12:17.003498 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxXsecL08BTTQixEno96QAAAFI"]
[Thu Sep 17 15:12:17.045614 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/bin/.env"] [unique_id "aqxXsecL08BTTQixEno96gAAAHU"]
[Thu Sep 17 15:12:17.052992 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.10.213:37526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno96wAAAA0"]
[Thu Sep 17 15:12:17.125384 2026] [security2:error] [pid 971102:tid 971349] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/beta/.env"] [unique_id "aqxXsecL08BTTQixEno97AAAAHM"]
[Thu Sep 17 15:12:17.130260 2026] [security2:error] [pid 971102:tid 971274] [client 8.228.10.213:37534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno97QAAACg"]
[Thu Sep 17 15:12:17.160869 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXsecL08BTTQixEno97gAAAF4"]
[Thu Sep 17 15:12:17.160987 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:51460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXsecL08BTTQixEno97gAAAF4"]
[Thu Sep 17 15:12:17.204898 2026] [security2:error] [pid 971102:tid 971270] [client 8.228.10.213:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno97wAAACQ"]
[Thu Sep 17 15:12:17.268380 2026] [security2:error] [pid 971102:tid 971254] [client 8.228.10.213:37550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno98wAAABQ"]
[Thu Sep 17 15:12:17.275265 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sbin/.env"] [unique_id "aqxXsecL08BTTQixEno99AAAACM"]
[Thu Sep 17 15:12:17.275905 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/uat/.env"] [unique_id "aqxXsecL08BTTQixEno99QAAADg"]
[Thu Sep 17 15:12:17.286734 2026] [core:error] [pid 971102:tid 971286] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:17.286749 2026] [core:error] [pid 971102:tid 971286] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:17.314844 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:35206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno99wAAAEc"]
[Thu Sep 17 15:12:17.342770 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.10.213:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno9-AAAAEU"]
[Thu Sep 17 15:12:17.403796 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno9_AAAAHE"]
[Thu Sep 17 15:12:17.426885 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/stage/.env"] [unique_id "aqxXsecL08BTTQixEno9_QAAAF8"]
[Thu Sep 17 15:12:17.472927 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:51462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxXsecL08BTTQixEno9_gAAAC4"]
[Thu Sep 17 15:12:17.473031 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:51462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxXsecL08BTTQixEno9_gAAAC4"]
[Thu Sep 17 15:12:17.501985 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/local/.env"] [unique_id "aqxXsecL08BTTQixEno-AAAAAGQ"]
[Thu Sep 17 15:12:17.556376 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxXsecL08BTTQixEno-AwAAAAQ"]
[Thu Sep 17 15:12:17.577726 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/development/.env"] [unique_id "aqxXsecL08BTTQixEno-BAAAACY"]
[Thu Sep 17 15:12:17.628483 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.10.213:37598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxXsecL08BTTQixEno-BgAAAAY"]
[Thu Sep 17 15:12:17.687977 2026] [security2:error] [pid 971102:tid 971234] [client 8.228.10.213:37614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno-BwAAAAA"]
[Thu Sep 17 15:12:17.735208 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/portal/.env"] [unique_id "aqxXsecL08BTTQixEno-CAAAACE"]
[Thu Sep 17 15:12:17.736798 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/production/.env"] [unique_id "aqxXsecL08BTTQixEno-CQAAABU"]
[Thu Sep 17 15:12:17.762072 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxXsecL08BTTQixEno-CwAAAAg"]
[Thu Sep 17 15:12:17.762173 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:51468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxXsecL08BTTQixEno-CwAAAAg"]
[Thu Sep 17 15:12:17.780429 2026] [security2:error] [pid 971102:tid 971287] [client 8.228.10.213:37628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno-DAAAADU"]
[Thu Sep 17 15:12:17.780571 2026] [security2:error] [pid 971102:tid 971318] [client 154.190.208.131:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsecL08BTTQixEno-DQAAAFQ"]
[Thu Sep 17 15:12:17.788415 2026] [security2:error] [pid 971102:tid 971318] [client 154.190.208.131:41559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsecL08BTTQixEno-DQAAAFQ"]
[Thu Sep 17 15:12:17.840415 2026] [security2:error] [pid 971102:tid 971350] [client 8.228.10.213:37642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxXsecL08BTTQixEno-EAAAAHQ"]
[Thu Sep 17 15:12:17.890540 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/config/app/.env"] [unique_id "aqxXsecL08BTTQixEno-EgAAAG8"]
[Thu Sep 17 15:12:17.905350 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.10.213:37654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxXsecL08BTTQixEno-EwAAAAM"]
[Thu Sep 17 15:12:17.961805 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/dashboard/.env"] [unique_id "aqxXsecL08BTTQixEno-FQAAABo"]
[Thu Sep 17 15:12:18.055732 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.0.94:41438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-GAAAAEk"]
[Thu Sep 17 15:12:18.078541 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:51476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxXsucL08BTTQixEno-GwAAAHo"]
[Thu Sep 17 15:12:18.078632 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:51476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxXsucL08BTTQixEno-GwAAAHo"]
[Thu Sep 17 15:12:18.137184 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXsucL08BTTQixEno-IAAAAFA"]
[Thu Sep 17 15:12:18.192227 2026] [security2:error] [pid 971102:tid 971304] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/panel/.env"] [unique_id "aqxXsucL08BTTQixEno-JQAAAEY"]
[Thu Sep 17 15:12:18.206999 2026] [security2:error] [pid 971102:tid 971340] [client 8.228.10.213:37672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-JgAAAGo"]
[Thu Sep 17 15:12:18.221617 2026] [core:error] [pid 971102:tid 971341] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.221635 2026] [core:error] [pid 971102:tid 971341] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.293420 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.10.213:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-KQAAAAE"]
[Thu Sep 17 15:12:18.340193 2026] [autoindex:error] [pid 971102:tid 971351] [client 172.239.147.162:59116] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:12:18.342810 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.117.146:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-LQAAAB0"]
[Thu Sep 17 15:12:18.353203 2026] [security2:error] [pid 971102:tid 971317] [client 8.228.10.213:37690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-LwAAAFM"]
[Thu Sep 17 15:12:18.356028 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxXsucL08BTTQixEno-MAAAAEQ"]
[Thu Sep 17 15:12:18.356107 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:51484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxXsucL08BTTQixEno-MAAAAEQ"]
[Thu Sep 17 15:12:18.403656 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.10.213:37700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-MgAAAFw"]
[Thu Sep 17 15:12:18.421738 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/crm/.env"] [unique_id "aqxXsucL08BTTQixEno-MwAAAAk"]
[Thu Sep 17 15:12:18.485781 2026] [security2:error] [pid 971102:tid 971248] [client 8.228.10.213:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-NwAAAA4"]
[Thu Sep 17 15:12:18.537180 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/info.php"] [unique_id "aqxXsucL08BTTQixEno-OQAAADQ"]
[Thu Sep 17 15:12:18.568068 2026] [security2:error] [pid 971102:tid 971296] [client 8.228.10.213:37728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxXsucL08BTTQixEno-OgAAAD4"]
[Thu Sep 17 15:12:18.646812 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.10.213:37734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxXsucL08BTTQixEno-PAAAAEg"]
[Thu Sep 17 15:12:18.651289 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/erp/.env"] [unique_id "aqxXsucL08BTTQixEno-PQAAAH0"]
[Thu Sep 17 15:12:18.665197 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxXsucL08BTTQixEno-PgAAAEs"]
[Thu Sep 17 15:12:18.665318 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:51486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxXsucL08BTTQixEno-PgAAAEs"]
[Thu Sep 17 15:12:18.723183 2026] [security2:error] [pid 971102:tid 971245] [client 8.228.10.213:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxXsucL08BTTQixEno-PwAAAAs"]
[Thu Sep 17 15:12:18.782383 2026] [security2:error] [pid 971102:tid 971320] [client 8.228.10.213:42008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxXsucL08BTTQixEno-QwAAAFY"]
[Thu Sep 17 15:12:18.874142 2026] [security2:error] [pid 971102:tid 971299] [client 8.228.10.213:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxXsucL08BTTQixEno-SwAAAEE"]
[Thu Sep 17 15:12:18.879087 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/shop/.env"] [unique_id "aqxXsucL08BTTQixEno-TAAAAAg"]
[Thu Sep 17 15:12:18.925411 2026] [security2:error] [pid 971102:tid 971300] [client 82.102.18.118:46406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxXsucL08BTTQixEno-TQAAAEI"]
[Thu Sep 17 15:12:18.954269 2026] [security2:error] [pid 971102:tid 971350] [client 8.228.10.213:42028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-UQAAAHQ"]
[Thu Sep 17 15:12:18.967292 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxXsucL08BTTQixEno-UwAAAAM"]
[Thu Sep 17 15:12:18.970878 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.970897 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.993582 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.0.94:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/php.php"] [unique_id "aqxXsucL08BTTQixEno-VQAAAAA"]
[Thu Sep 17 15:12:19.037983 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.10.213:42030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-WQAAAG0"]
[Thu Sep 17 15:12:19.105552 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/store/.env"] [unique_id "aqxXs-cL08BTTQixEno-WwAAAHo"]
[Thu Sep 17 15:12:19.121510 2026] [authz_core:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Poly1305/error_log
[Thu Sep 17 15:12:19.122377 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxXs-cL08BTTQixEno-XAAAAEA"]
[Thu Sep 17 15:12:19.134760 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.10.213:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-XQAAAEk"]
[Thu Sep 17 15:12:19.192388 2026] [security2:error] [pid 971102:tid 971301] [client 5.189.145.112:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxXs-cL08BTTQixEno-XgAAAEM"], referer: binance.com
[Thu Sep 17 15:12:19.208469 2026] [security2:error] [pid 971102:tid 971354] [client 8.228.10.213:42048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-XwAAAHg"]
[Thu Sep 17 15:12:19.265897 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXs-cL08BTTQixEno-YAAAADs"]
[Thu Sep 17 15:12:19.292985 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:42058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-YQAAAHs"]
[Thu Sep 17 15:12:19.293844 2026] [security2:error] [pid 971102:tid 971236] [client 34.32.117.146:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-YgAAAAI"]
[Thu Sep 17 15:12:19.332452 2026] [security2:error] [pid 971102:tid 971282] [client 82.102.18.118:45184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxXs-cL08BTTQixEno-YwAAADA"]
[Thu Sep 17 15:12:19.333226 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/saas/.env"] [unique_id "aqxXs-cL08BTTQixEno-ZgAAACg"]
[Thu Sep 17 15:12:19.361845 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-cgAAAF4"]
[Thu Sep 17 15:12:19.428261 2026] [security2:error] [pid 971102:tid 971355] [client 8.228.10.213:42082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-dQAAAHk"]
[Thu Sep 17 15:12:19.456668 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.0.94:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/i.php"] [unique_id "aqxXs-cL08BTTQixEno-dgAAABI"]
[Thu Sep 17 15:12:19.492870 2026] [security2:error] [pid 971102:tid 971317] [client 8.228.10.213:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-eAAAAFM"]
[Thu Sep 17 15:12:19.576537 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxXs-cL08BTTQixEno-eQAAAAk"]
[Thu Sep 17 15:12:19.586751 2026] [security2:error] [pid 971102:tid 971305] [client 8.228.10.213:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-egAAAEc"]
[Thu Sep 17 15:12:19.592011 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXs-cL08BTTQixEno-ewAAAB0"]
[Thu Sep 17 15:12:19.592105 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXs-cL08BTTQixEno-ewAAAB0"]
[Thu Sep 17 15:12:19.649333 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXs-cL08BTTQixEno-dAAAAE0"]
[Thu Sep 17 15:12:19.649355 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXs-cL08BTTQixEno-dAAAAE0"]
[Thu Sep 17 15:12:19.668519 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:42114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-fAAAAHw"]
[Thu Sep 17 15:12:19.685926 2026] [security2:error] [pid 971102:tid 971329] [client 82.102.18.118:45200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxXs-cL08BTTQixEno-fwAAAF8"]
[Thu Sep 17 15:12:19.731039 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:42126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-gAAAAFI"]
[Thu Sep 17 15:12:19.742664 2026] [core:error] [pid 971102:tid 971259] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:19.742680 2026] [core:error] [pid 971102:tid 971259] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:19.790509 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxXs-cL08BTTQixEno-ggAAAD4"]
[Thu Sep 17 15:12:19.790614 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxXs-cL08BTTQixEno-ggAAAD4"]
[Thu Sep 17 15:12:19.808867 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/project/.env"] [unique_id "aqxXs-cL08BTTQixEno-hAAAAGQ"]
[Thu Sep 17 15:12:19.814025 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.10.213:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-hQAAAAo"]
[Thu Sep 17 15:12:19.890583 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:42150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-hwAAAAQ"]
[Thu Sep 17 15:12:19.911980 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.0.94:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/pi.php"] [unique_id "aqxXs-cL08BTTQixEno-iwAAAAU"]
[Thu Sep 17 15:12:19.962236 2026] [security2:error] [pid 971102:tid 971292] [client 8.228.10.213:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-kAAAADo"]
[Thu Sep 17 15:12:20.035311 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/admin-panel/.env"] [unique_id "aqxXtOcL08BTTQixEno-kwAAAEE"]
[Thu Sep 17 15:12:20.056985 2026] [security2:error] [pid 971102:tid 971242] [client 82.102.18.118:45204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtOcL08BTTQixEno-lAAAAAg"]
[Thu Sep 17 15:12:20.078053 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxXtOcL08BTTQixEno-lQAAADU"]
[Thu Sep 17 15:12:20.078172 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxXtOcL08BTTQixEno-lQAAADU"]
[Thu Sep 17 15:12:20.190890 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.117.146:41878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXtOcL08BTTQixEno-ngAAAGI"]
[Thu Sep 17 15:12:20.261801 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/control-panel/.env"] [unique_id "aqxXtOcL08BTTQixEno-pwAAAFs"]
[Thu Sep 17 15:12:20.360451 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/pinfo.php"] [unique_id "aqxXtOcL08BTTQixEno-rAAAACo"]
[Thu Sep 17 15:12:20.373635 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxXtOcL08BTTQixEno-rgAAABM"]
[Thu Sep 17 15:12:20.373733 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:56514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxXtOcL08BTTQixEno-rgAAABM"]
[Thu Sep 17 15:12:20.406043 2026] [security2:error] [pid 971102:tid 971314] [client 82.102.18.118:45220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtOcL08BTTQixEno-sAAAAFA"]
[Thu Sep 17 15:12:20.413915 2026] [security2:error] [pid 971102:tid 971360] [client 159.65.113.230:60711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "snowhillstokes.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXtOcL08BTTQixEno-sQAAAH4"]
[Thu Sep 17 15:12:20.489291 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/user-panel/.env"] [unique_id "aqxXtOcL08BTTQixEno-tgAAAD8"]
[Thu Sep 17 15:12:20.542214 2026] [core:error] [pid 971102:tid 971289] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:20.542233 2026] [core:error] [pid 971102:tid 971289] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:20.653699 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxXtOcL08BTTQixEno-wgAAAE0"]
[Thu Sep 17 15:12:20.653781 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:56526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxXtOcL08BTTQixEno-wgAAAE0"]
[Thu Sep 17 15:12:20.673783 2026] [security2:error] [pid 971102:tid 971250] [client 148.227.121.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxXs-cL08BTTQixEno-WgAAABA"], referer: https://darfieldearthship.com/
[Thu Sep 17 15:12:20.716896 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/node/.env"] [unique_id "aqxXtOcL08BTTQixEno-xgAAAA8"]
[Thu Sep 17 15:12:20.722443 2026] [security2:error] [pid 971102:tid 971361] [client 159.65.113.230:60714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "snowhillstokes.org"] [uri "/"] [unique_id "aqxXtOcL08BTTQixEno-xwAAAH8"]
[Thu Sep 17 15:12:20.772013 2026] [security2:error] [pid 971102:tid 971334] [client 82.102.18.118:45224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtOcL08BTTQixEno-zQAAAGQ"]
[Thu Sep 17 15:12:20.810753 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.0.94:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/test.php"] [unique_id "aqxXtOcL08BTTQixEno-0AAAAA4"]
[Thu Sep 17 15:12:20.937422 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxXtOcL08BTTQixEno-4QAAAF0"]
[Thu Sep 17 15:12:20.937547 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:56542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxXtOcL08BTTQixEno-4QAAAF0"]
[Thu Sep 17 15:12:20.944571 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/express/.env"] [unique_id "aqxXtOcL08BTTQixEno-4wAAAEI"]
[Thu Sep 17 15:12:21.004247 2026] [security2:error] [pid 971102:tid 971234] [client 52.231.79.181:1873] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/1.php"] [unique_id "aqxXtecL08BTTQixEno-6gAAAAA"]
[Thu Sep 17 15:12:21.004355 2026] [security2:error] [pid 971102:tid 971234] [client 52.231.79.181:1873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/1.php"] [unique_id "aqxXtecL08BTTQixEno-6gAAAAA"]
[Thu Sep 17 15:12:21.061048 2026] [security2:error] [pid 971102:tid 971298] [client 159.65.113.230:60718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "snowhillstokes.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXtecL08BTTQixEno-6wAAAEA"]
[Thu Sep 17 15:12:21.141156 2026] [security2:error] [pid 971102:tid 971325] [client 52.231.79.181:1895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/new.php"] [unique_id "aqxXtecL08BTTQixEno-7gAAAFs"]
[Thu Sep 17 15:12:21.143000 2026] [security2:error] [pid 971102:tid 971258] [client 82.102.18.118:45226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtecL08BTTQixEno-7wAAABg"]
[Thu Sep 17 15:12:21.173018 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/next/.env"] [unique_id "aqxXtecL08BTTQixEno-8AAAAGA"]
[Thu Sep 17 15:12:21.219523 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxXtecL08BTTQixEno-8wAAAEQ"]
[Thu Sep 17 15:12:21.219602 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:56546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxXtecL08BTTQixEno-8wAAAEQ"]
[Thu Sep 17 15:12:21.331963 2026] [core:error] [pid 971102:tid 971270] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:21.331982 2026] [core:error] [pid 971102:tid 971270] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:21.381745 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.117.146:41884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXtOcL08BTTQixEno-3wAAAHw"]
[Thu Sep 17 15:12:21.399607 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/nuxt/.env"] [unique_id "aqxXtecL08BTTQixEno-_gAAABA"]
[Thu Sep 17 15:12:21.474382 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.0.94:52470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXtecL08BTTQixEno-9AAAAA0"]
[Thu Sep 17 15:12:21.497587 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxXtecL08BTTQixEno-_wAAACA"]
[Thu Sep 17 15:12:21.497687 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:56552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxXtecL08BTTQixEno-_wAAACA"]
[Thu Sep 17 15:12:21.502710 2026] [security2:error] [pid 971102:tid 971279] [client 82.102.18.118:28527] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtecL08BTTQixEno_AAAAAC0"]
[Thu Sep 17 15:12:21.540247 2026] [security2:error] [pid 971102:tid 971280] [client 52.231.79.181:1893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/num.php"] [unique_id "aqxXtecL08BTTQixEno_AQAAAC4"]
[Thu Sep 17 15:12:21.623299 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/p.php"] [unique_id "aqxXtecL08BTTQixEno_BAAAAFI"]
[Thu Sep 17 15:12:21.625494 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/nest/.env"] [unique_id "aqxXtecL08BTTQixEno_BQAAADQ"]
[Thu Sep 17 15:12:21.788315 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxXtecL08BTTQixEno_BwAAABc"]
[Thu Sep 17 15:12:21.788396 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:56558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxXtecL08BTTQixEno_BwAAABc"]
[Thu Sep 17 15:12:21.851052 2026] [security2:error] [pid 971102:tid 971248] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/react/.env"] [unique_id "aqxXtecL08BTTQixEno_CgAAAA4"]
[Thu Sep 17 15:12:21.865113 2026] [security2:error] [pid 971102:tid 971308] [client 82.102.18.118:45244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtecL08BTTQixEno_CwAAAEo"]
[Thu Sep 17 15:12:22.068553 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.068571 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.073195 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxXtucL08BTTQixEno_EwAAAHQ"]
[Thu Sep 17 15:12:22.073265 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxXtucL08BTTQixEno_EwAAAHQ"]
[Thu Sep 17 15:12:22.084418 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/vue/.env"] [unique_id "aqxXtucL08BTTQixEno_FAAAAEI"]
[Thu Sep 17 15:12:22.090486 2026] [security2:error] [pid 971102:tid 971291] [client 52.231.79.181:1880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/admin.php"] [unique_id "aqxXtucL08BTTQixEno_FQAAADk"]
[Thu Sep 17 15:12:22.102516 2026] [security2:error] [pid 971102:tid 971303] [client 34.32.0.94:52474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/debug.php"] [unique_id "aqxXtucL08BTTQixEno_FgAAAEU"]
[Thu Sep 17 15:12:22.227863 2026] [security2:error] [pid 971102:tid 971332] [client 82.102.18.118:45250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtucL08BTTQixEno_FwAAAGI"]
[Thu Sep 17 15:12:22.311911 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/angular/.env"] [unique_id "aqxXtucL08BTTQixEno_GQAAAAA"]
[Thu Sep 17 15:12:22.357419 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:56580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxXtucL08BTTQixEno_GwAAABo"]
[Thu Sep 17 15:12:22.512749 2026] [security2:error] [pid 971102:tid 971268] [client 52.231.79.181:1868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/13.php"] [unique_id "aqxXtucL08BTTQixEno_JAAAACI"]
[Thu Sep 17 15:12:22.522006 2026] [security2:error] [pid 971102:tid 971271] [client 156.192.234.52:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXtucL08BTTQixEno_JQAAACU"]
[Thu Sep 17 15:12:22.524196 2026] [authz_core:error] [pid 971102:tid 971310] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/error_log
[Thu Sep 17 15:12:22.524273 2026] [security2:error] [pid 971102:tid 971271] [client 156.192.234.52:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXtucL08BTTQixEno_JQAAACU"]
[Thu Sep 17 15:12:22.529384 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxXtucL08BTTQixEno_IwAAAEw"]
[Thu Sep 17 15:12:22.537784 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/svelte/.env"] [unique_id "aqxXtucL08BTTQixEno_JgAAAEA"]
[Thu Sep 17 15:12:22.571243 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.0.94:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXtucL08BTTQixEno_KQAAAAs"]
[Thu Sep 17 15:12:22.583392 2026] [security2:error] [pid 971102:tid 971335] [client 82.102.18.118:45262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtucL08BTTQixEno_KgAAAGU"]
[Thu Sep 17 15:12:22.672102 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:56580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/wp-includes/sodium_compat/"] [unique_id "aqxXtucL08BTTQixEno_LQAAAGA"]
[Thu Sep 17 15:12:22.773433 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/vite/.env"] [unique_id "aqxXtucL08BTTQixEno_MwAAAHk"]
[Thu Sep 17 15:12:22.825904 2026] [core:error] [pid 971102:tid 971353] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.825930 2026] [core:error] [pid 971102:tid 971353] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.899229 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:41884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/php-info.php"] [unique_id "aqxXtucL08BTTQixEno_OwAAADs"]
[Thu Sep 17 15:12:22.943821 2026] [security2:error] [pid 971102:tid 971284] [client 82.102.18.118:45264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtucL08BTTQixEno_PAAAADI"]
[Thu Sep 17 15:12:22.946491 2026] [security2:error] [pid 971102:tid 971290] [client 52.231.79.181:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/222.php"] [unique_id "aqxXtucL08BTTQixEno_PQAAADg"]
[Thu Sep 17 15:12:23.000053 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxXtucL08BTTQixEno_QQAAABA"]
[Thu Sep 17 15:12:23.016743 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXtucL08BTTQixEno_NQAAAAk"]
[Thu Sep 17 15:12:23.016763 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXtucL08BTTQixEno_NQAAAAk"]
[Thu Sep 17 15:12:23.030885 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXt-cL08BTTQixEno_QgAAAF8"]
[Thu Sep 17 15:12:23.121320 2026] [security2:error] [pid 971102:tid 971288] [client 185.55.149.49:54292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RAAAADY"]
[Thu Sep 17 15:12:23.121440 2026] [security2:error] [pid 971102:tid 971288] [client 185.55.149.49:54292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RAAAADY"]
[Thu Sep 17 15:12:23.158313 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:56580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxXt-cL08BTTQixEno_RQAAAHI"]
[Thu Sep 17 15:12:23.158398 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:56580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxXt-cL08BTTQixEno_RQAAAHI"]
[Thu Sep 17 15:12:23.226790 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/backups/.env"] [unique_id "aqxXt-cL08BTTQixEno_RgAAAC4"]
[Thu Sep 17 15:12:23.272426 2026] [security2:error] [pid 971102:tid 971339] [client 115.244.164.14:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RwAAAGk"]
[Thu Sep 17 15:12:23.272503 2026] [security2:error] [pid 971102:tid 971339] [client 115.244.164.14:54106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RwAAAGk"]
[Thu Sep 17 15:12:23.290092 2026] [security2:error] [pid 971102:tid 971269] [client 82.102.18.118:45274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxXt-cL08BTTQixEno_SAAAACM"]
[Thu Sep 17 15:12:23.378580 2026] [security2:error] [pid 971102:tid 971319] [client 52.231.79.181:1876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/aa.php"] [unique_id "aqxXt-cL08BTTQixEno_TAAAAFU"]
[Thu Sep 17 15:12:23.449618 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXt-cL08BTTQixEno_TQAAACs"]
[Thu Sep 17 15:12:23.457518 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxXt-cL08BTTQixEno_TgAAABc"]
[Thu Sep 17 15:12:23.484713 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.0.94:52496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXt-cL08BTTQixEno_TwAAAH8"]
[Thu Sep 17 15:12:23.615464 2026] [authz_core:error] [pid 971102:tid 971256] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/error_log
[Thu Sep 17 15:12:23.644673 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXt-cL08BTTQixEno_VQAAABY"]
[Thu Sep 17 15:12:23.653160 2026] [security2:error] [pid 971102:tid 971352] [client 82.102.18.118:45282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxXt-cL08BTTQixEno_VgAAAHY"]
[Thu Sep 17 15:12:23.686520 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/tmp/.env"] [unique_id "aqxXt-cL08BTTQixEno_WAAAAFk"]
[Thu Sep 17 15:12:23.687396 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:23.687410 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:23.691856 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.117.146:41896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpversion.php"] [unique_id "aqxXt-cL08BTTQixEno_WQAAAA4"]
[Thu Sep 17 15:12:23.786321 2026] [security2:error] [pid 971102:tid 971349] [client 47.79.206.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.npae.net"] [uri "/index.php"] [unique_id "aqxXt-cL08BTTQixEno_QwAAAHM"], referer: https://www.google.com/
[Thu Sep 17 15:12:23.792334 2026] [security2:error] [pid 971102:tid 971262] [client 52.231.79.181:1882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/abcd.php"] [unique_id "aqxXt-cL08BTTQixEno_WwAAABw"]
[Thu Sep 17 15:12:23.793420 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/wp-includes/sodium_compat/src/"] [unique_id "aqxXt-cL08BTTQixEno_XAAAAEU"]
[Thu Sep 17 15:12:23.913769 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/temp/.env"] [unique_id "aqxXt-cL08BTTQixEno_YgAAAGw"]
[Thu Sep 17 15:12:23.939163 2026] [security2:error] [pid 971102:tid 971350] [client 34.32.0.94:52510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXt-cL08BTTQixEno_ZAAAAHQ"]
[Thu Sep 17 15:12:23.942342 2026] [security2:error] [pid 971102:tid 971276] [client 134.185.85.61:56329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thechurchinirving.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxXt-cL08BTTQixEno_ZQAAACo"]
[Thu Sep 17 15:12:24.026750 2026] [security2:error] [pid 971102:tid 971240] [client 82.102.18.118:45292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuOcL08BTTQixEno_awAAAAY"]
[Thu Sep 17 15:12:24.140540 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/lab/.env"] [unique_id "aqxXuOcL08BTTQixEno_bwAAABg"]
[Thu Sep 17 15:12:24.144336 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXt-cL08BTTQixEno_YwAAADw"]
[Thu Sep 17 15:12:24.144351 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXt-cL08BTTQixEno_YwAAADw"]
[Thu Sep 17 15:12:24.229498 2026] [security2:error] [pid 971102:tid 971299] [client 52.231.79.181:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/about.php"] [unique_id "aqxXuOcL08BTTQixEno_cQAAAEE"]
[Thu Sep 17 15:12:24.283173 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxXuOcL08BTTQixEno_dAAAACk"]
[Thu Sep 17 15:12:24.325891 2026] [security2:error] [pid 971102:tid 971354] [client 134.185.85.61:62792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thechurchinirving.com"] [uri "/media/system/js/core.js"] [unique_id "aqxXuOcL08BTTQixEno_dwAAAHg"]
[Thu Sep 17 15:12:24.375747 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cronlab/.env"] [unique_id "aqxXuOcL08BTTQixEno_egAAAFM"]
[Thu Sep 17 15:12:24.380839 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.130.148:42952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "aqxXuOcL08BTTQixEno_fAAAAGs"]
[Thu Sep 17 15:12:24.396610 2026] [security2:error] [pid 971102:tid 971353] [client 82.102.18.118:45294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuOcL08BTTQixEno_fQAAAHc"]
[Thu Sep 17 15:12:24.401828 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.0.94:35860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXuOcL08BTTQixEno_fgAAADA"]
[Thu Sep 17 15:12:24.446122 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxXuOcL08BTTQixEno_fwAAACg"]
[Thu Sep 17 15:12:24.589984 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXuOcL08BTTQixEno_hwAAADs"]
[Thu Sep 17 15:12:24.605983 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cron/.env"] [unique_id "aqxXuOcL08BTTQixEno_iAAAAB8"]
[Thu Sep 17 15:12:24.613028 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.130.148:42952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "aqxXuOcL08BTTQixEno_iQAAADI"]
[Thu Sep 17 15:12:24.637270 2026] [security2:error] [pid 971102:tid 971270] [client 52.231.79.181:1878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/admin.php"] [unique_id "aqxXuOcL08BTTQixEno_igAAACQ"]
[Thu Sep 17 15:12:24.667752 2026] [security2:error] [pid 971102:tid 971356] [client 34.32.117.146:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/_phpinfo.php"] [unique_id "aqxXuOcL08BTTQixEno_iwAAAHo"]
[Thu Sep 17 15:12:24.766836 2026] [security2:error] [pid 971102:tid 971266] [client 82.102.18.118:45298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuOcL08BTTQixEno_jQAAACA"]
[Thu Sep 17 15:12:24.836151 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/en/.env"] [unique_id "aqxXuOcL08BTTQixEno_kAAAABs"]
[Thu Sep 17 15:12:24.852830 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.0.94:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXuOcL08BTTQixEno_lQAAAA0"]
[Thu Sep 17 15:12:24.900527 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:24.900554 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:24.918060 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXuOcL08BTTQixEno_jAAAAF4"]
[Thu Sep 17 15:12:24.918078 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXuOcL08BTTQixEno_jAAAAF4"]
[Thu Sep 17 15:12:25.053131 2026] [security2:error] [pid 971102:tid 971296] [client 52.231.79.181:1864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/adminfuns.php"] [unique_id "aqxXuecL08BTTQixEno_mAAAAD4"]
[Thu Sep 17 15:12:25.059200 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxXuecL08BTTQixEno_mQAAAFY"]
[Thu Sep 17 15:12:25.059269 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxXuecL08BTTQixEno_mQAAAFY"]
[Thu Sep 17 15:12:25.082542 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxXuecL08BTTQixEno_mgAAABU"]
[Thu Sep 17 15:12:25.123894 2026] [security2:error] [pid 971102:tid 971238] [client 82.102.18.118:45302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuecL08BTTQixEno_mwAAAAQ"]
[Thu Sep 17 15:12:25.310015 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/psnlink/.env"] [unique_id "aqxXuecL08BTTQixEno_nQAAAF0"]
[Thu Sep 17 15:12:25.348394 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxXuecL08BTTQixEno_oAAAAAM"]
[Thu Sep 17 15:12:25.348495 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:56594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxXuecL08BTTQixEno_oAAAAAM"]
[Thu Sep 17 15:12:25.457539 2026] [security2:error] [pid 971102:tid 971292] [client 52.231.79.181:1896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxXuecL08BTTQixEno_owAAADo"]
[Thu Sep 17 15:12:25.510032 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.0.94:35876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXuecL08BTTQixEno_ngAAABY"]
[Thu Sep 17 15:12:25.536545 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/exapi/.env"] [unique_id "aqxXuecL08BTTQixEno_pAAAAGc"]
[Thu Sep 17 15:12:25.626222 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxXuecL08BTTQixEno_rQAAAHQ"]
[Thu Sep 17 15:12:25.626319 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxXuecL08BTTQixEno_rQAAAHQ"]
[Thu Sep 17 15:12:25.667062 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:35876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/php-info.php"] [unique_id "aqxXuecL08BTTQixEno_rgAAACo"]
[Thu Sep 17 15:12:25.744041 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.117.146:41902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXuecL08BTTQixEno_sAAAAHs"]
[Thu Sep 17 15:12:25.764250 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sitemaps/.env"] [unique_id "aqxXuecL08BTTQixEno_sQAAAH4"]
[Thu Sep 17 15:12:25.874123 2026] [security2:error] [pid 971102:tid 971281] [client 52.231.79.181:1918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/ae.php"] [unique_id "aqxXuecL08BTTQixEno_tQAAAC8"]
[Thu Sep 17 15:12:25.908042 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:25.908059 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:25.911885 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxXuecL08BTTQixEno_twAAAGA"]
[Thu Sep 17 15:12:25.911984 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:56616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxXuecL08BTTQixEno_twAAAGA"]
[Thu Sep 17 15:12:26.157327 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.0.94:35884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpversion.php"] [unique_id "aqxXuucL08BTTQixEno_uwAAABI"]
[Thu Sep 17 15:12:26.182523 2026] [security2:error] [pid 971102:tid 971239] [client 104.28.198.244:22831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXuucL08BTTQixEno_vQAAAAU"]
[Thu Sep 17 15:12:26.182656 2026] [security2:error] [pid 971102:tid 971239] [client 104.28.198.244:22831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXuucL08BTTQixEno_vQAAAAU"]
[Thu Sep 17 15:12:26.184153 2026] [security2:error] [pid 971102:tid 971282] [client 172.86.81.177:50098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ravenindustries-net.geekngamer.com"] [uri "/index.php"] [unique_id "aqxXuucL08BTTQixEno_vAAAADA"]
[Thu Sep 17 15:12:26.208597 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxXuucL08BTTQixEno_vgAAADU"]
[Thu Sep 17 15:12:26.208704 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxXuucL08BTTQixEno_vgAAADU"]
[Thu Sep 17 15:12:26.233567 2026] [security2:error] [pid 971102:tid 971259] [client 5.189.145.112:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxXuucL08BTTQixEno_vwAAABk"], referer: binance.com
[Thu Sep 17 15:12:26.277877 2026] [security2:error] [pid 971102:tid 971341] [client 52.231.79.181:1914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/akcc.php"] [unique_id "aqxXuucL08BTTQixEno_wAAAAGs"]
[Thu Sep 17 15:12:26.560563 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxXuucL08BTTQixEno_ygAAACQ"]
[Thu Sep 17 15:12:26.570670 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:41906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/server-info.php"] [unique_id "aqxXuucL08BTTQixEno_ywAAAE8"]
[Thu Sep 17 15:12:26.623590 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.0.94:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/_phpinfo.php"] [unique_id "aqxXuucL08BTTQixEno_zQAAAHk"]
[Thu Sep 17 15:12:26.674093 2026] [security2:error] [pid 971102:tid 971359] [client 52.231.79.181:1881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/bak.php"] [unique_id "aqxXuucL08BTTQixEno_0AAAAH0"]
[Thu Sep 17 15:12:26.717492 2026] [authz_core:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/AES/error_log
[Thu Sep 17 15:12:26.718736 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxXuucL08BTTQixEno_0wAAACs"]
[Thu Sep 17 15:12:26.730805 2026] [core:error] [pid 971102:tid 971257] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:26.730821 2026] [core:error] [pid 971102:tid 971257] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:26.852409 2026] [security2:error] [pid 971102:tid 971279] [client 34.31.203.120:1072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxXuucL08BTTQixEno_zAAALSs"]
[Thu Sep 17 15:12:26.867451 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXuucL08BTTQixEno_2AAAADQ"]
[Thu Sep 17 15:12:26.970878 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/logs/.env"] [unique_id "aqxXuucL08BTTQixEno_2wAAABU"]
[Thu Sep 17 15:12:27.089207 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.0.94:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXu-cL08BTTQixEno_4QAAABE"]
[Thu Sep 17 15:12:27.138969 2026] [security2:error] [pid 971102:tid 971316] [client 34.31.203.120:1072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxXuucL08BTTQixEno_2QAAUhU"]
[Thu Sep 17 15:12:27.247637 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_3QAAAAI"]
[Thu Sep 17 15:12:27.247674 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_3QAAAAI"]
[Thu Sep 17 15:12:27.387477 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxXu-cL08BTTQixEno_6wAAABw"]
[Thu Sep 17 15:12:27.387582 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxXu-cL08BTTQixEno_6wAAABw"]
[Thu Sep 17 15:12:27.506728 2026] [core:error] [pid 971102:tid 971240] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:27.506751 2026] [core:error] [pid 971102:tid 971240] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:27.545130 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/server-info.php"] [unique_id "aqxXu-cL08BTTQixEno_9AAAACo"]
[Thu Sep 17 15:12:27.561588 2026] [security2:error] [pid 971102:tid 971278] [client 114.198.138.124:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_9gAAACw"]
[Thu Sep 17 15:12:27.561691 2026] [security2:error] [pid 971102:tid 971278] [client 114.198.138.124:61229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_9gAAACw"]
[Thu Sep 17 15:12:27.590590 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.117.146:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/server-status.php"] [unique_id "aqxXu-cL08BTTQixEno_9wAAADk"]
[Thu Sep 17 15:12:27.653883 2026] [security2:error] [pid 971102:tid 971300] [client 173.252.95.13:36688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_7QAAAEI"]
[Thu Sep 17 15:12:27.654220 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cache/.env"] [unique_id "aqxXu-cL08BTTQixEno_-QAAAEA"]
[Thu Sep 17 15:12:27.660682 2026] [security2:error] [pid 971102:tid 971358] [client 186.105.232.15:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_-AAAAHw"]
[Thu Sep 17 15:12:27.660794 2026] [security2:error] [pid 971102:tid 971358] [client 186.105.232.15:54686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_-AAAAHw"]
[Thu Sep 17 15:12:27.674075 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxXu-cL08BTTQixEno_-gAAAGo"]
[Thu Sep 17 15:12:27.674166 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:56646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxXu-cL08BTTQixEno_-gAAAGo"]
[Thu Sep 17 15:12:27.680715 2026] [security2:error] [pid 971102:tid 971260] [client 52.231.79.181:1866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/cc.php"] [unique_id "aqxXu-cL08BTTQixEno_-wAAABo"]
[Thu Sep 17 15:12:27.758984 2026] [security2:error] [pid 971102:tid 971325] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_9QAAAFs"]
[Thu Sep 17 15:12:27.882022 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailer/.env"] [unique_id "aqxXu-cL08BTTQixEnpAAwAAAB0"]
[Thu Sep 17 15:12:27.956958 2026] [security2:error] [pid 971102:tid 971265] [client 159.223.126.126:48882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXu-cL08BTTQixEnpABAAAAB8"]
[Thu Sep 17 15:12:27.969519 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxXu-cL08BTTQixEnpABQAAABA"]
[Thu Sep 17 15:12:27.969647 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:56652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxXu-cL08BTTQixEnpABQAAABA"]
[Thu Sep 17 15:12:28.001599 2026] [security2:error] [pid 971102:tid 971341] [client 34.32.0.94:35934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/server-status.php"] [unique_id "aqxXvOcL08BTTQixEnpABgAAAGs"]
[Thu Sep 17 15:12:28.076394 2026] [security2:error] [pid 971102:tid 971290] [client 52.231.79.181:1856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/chosen.php"] [unique_id "aqxXvOcL08BTTQixEnpABwAAADg"]
[Thu Sep 17 15:12:28.114329 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mail/.env"] [unique_id "aqxXvOcL08BTTQixEnpACAAAABM"]
[Thu Sep 17 15:12:28.190614 2026] [security2:error] [pid 971102:tid 971305] [client 159.223.126.126:48886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpACQAAAEc"]
[Thu Sep 17 15:12:28.219593 2026] [security2:error] [pid 971102:tid 971275] [client 78.46.190.63:16960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpACgAAACk"], referer: https://eris.media
[Thu Sep 17 15:12:28.232492 2026] [core:error] [pid 971102:tid 971347] [client 34.166.130.148:42986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:28.232508 2026] [core:error] [pid 971102:tid 971347] [client 34.166.130.148:42986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:28.266345 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxXvOcL08BTTQixEnpADgAAAGg"]
[Thu Sep 17 15:12:28.266458 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:56668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxXvOcL08BTTQixEnpADgAAAGg"]
[Thu Sep 17 15:12:28.300590 2026] [security2:error] [pid 971102:tid 971284] [client 154.190.208.131:42160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvOcL08BTTQixEnpADwAAADI"]
[Thu Sep 17 15:12:28.312294 2026] [security2:error] [pid 971102:tid 971284] [client 154.190.208.131:42160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvOcL08BTTQixEnpADwAAADI"]
[Thu Sep 17 15:12:28.353108 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/email/.env"] [unique_id "aqxXvOcL08BTTQixEnpAEwAAAFU"]
[Thu Sep 17 15:12:28.410291 2026] [security2:error] [pid 971102:tid 971359] [client 159.223.126.126:48892] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpAFQAAAH0"]
[Thu Sep 17 15:12:28.497116 2026] [security2:error] [pid 971102:tid 971277] [client 52.231.79.181:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/classwithtostring.php"] [unique_id "aqxXvOcL08BTTQixEnpAGgAAACs"]
[Thu Sep 17 15:12:28.565306 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxXvOcL08BTTQixEnpAGwAAAEo"]
[Thu Sep 17 15:12:28.582985 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/smtp/.env"] [unique_id "aqxXvOcL08BTTQixEnpAHAAAAFY"]
[Thu Sep 17 15:12:28.642605 2026] [security2:error] [pid 971102:tid 971279] [client 159.223.126.126:48906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpAHQAAAC0"]
[Thu Sep 17 15:12:28.671657 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.0.94:35944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpAFwAAADs"]
[Thu Sep 17 15:12:28.720141 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxXvOcL08BTTQixEnpAHwAAADE"]
[Thu Sep 17 15:12:28.817355 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailing/.env"] [unique_id "aqxXvOcL08BTTQixEnpAIQAAAHI"]
[Thu Sep 17 15:12:28.850624 2026] [security2:error] [pid 971102:tid 971268] [client 159.223.126.126:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpAJAAAACI"]
[Thu Sep 17 15:12:28.871006 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXvOcL08BTTQixEnpAJgAAAAI"]
[Thu Sep 17 15:12:28.909629 2026] [security2:error] [pid 971102:tid 971327] [client 52.231.79.181:1891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-signup.php"] [unique_id "aqxXvOcL08BTTQixEnpAKQAAAF0"]
[Thu Sep 17 15:12:28.925602 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:60076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpAGQAAAE8"]
[Thu Sep 17 15:12:28.970438 2026] [core:error] [pid 971102:tid 971343] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:28.970457 2026] [core:error] [pid 971102:tid 971343] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:29.014187 2026] [security2:error] [pid 971102:tid 971292] [client 34.32.0.94:35944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpAIwAAADo"]
[Thu Sep 17 15:12:29.052668 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/notifications/.env"] [unique_id "aqxXvecL08BTTQixEnpALwAAAFg"]
[Thu Sep 17 15:12:29.058648 2026] [security2:error] [pid 971102:tid 971240] [client 159.223.126.126:48916] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvecL08BTTQixEnpAMAAAAAY"]
[Thu Sep 17 15:12:29.163705 2026] [security2:error] [pid 971102:tid 971278] [client 34.32.0.94:35944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXvecL08BTTQixEnpAMwAAACw"]
[Thu Sep 17 15:12:29.281476 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/notify/.env"] [unique_id "aqxXvecL08BTTQixEnpAOAAAAEE"]
[Thu Sep 17 15:12:29.320098 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvecL08BTTQixEnpAMQAAAGA"]
[Thu Sep 17 15:12:29.320121 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvecL08BTTQixEnpAMQAAAGA"]
[Thu Sep 17 15:12:29.323406 2026] [security2:error] [pid 971102:tid 971300] [client 52.231.79.181:1888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/doc.php"] [unique_id "aqxXvecL08BTTQixEnpAOwAAAEI"]
[Thu Sep 17 15:12:29.463896 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxXvecL08BTTQixEnpAQAAAABI"]
[Thu Sep 17 15:12:29.463997 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxXvecL08BTTQixEnpAQAAAABI"]
[Thu Sep 17 15:12:29.516507 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sender/.env"] [unique_id "aqxXvecL08BTTQixEnpAQQAAACg"]
[Thu Sep 17 15:12:29.641705 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.0.94:35958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXvecL08BTTQixEnpARgAAADA"]
[Thu Sep 17 15:12:29.741213 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxXvecL08BTTQixEnpASQAAAG8"]
[Thu Sep 17 15:12:29.741316 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:56698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxXvecL08BTTQixEnpASQAAAG8"]
[Thu Sep 17 15:12:29.745415 2026] [security2:error] [pid 971102:tid 971344] [client 52.231.79.181:1872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/edit.php"] [unique_id "aqxXvecL08BTTQixEnpASgAAAG4"]
[Thu Sep 17 15:12:29.749379 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/campaign/.env"] [unique_id "aqxXvecL08BTTQixEnpASwAAAGI"]
[Thu Sep 17 15:12:29.751049 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:29.751061 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:29.982243 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/newsletter/.env"] [unique_id "aqxXvecL08BTTQixEnpAVAAAACA"]
[Thu Sep 17 15:12:30.020758 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxXvucL08BTTQixEnpAVQAAAFo"]
[Thu Sep 17 15:12:30.020883 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:36266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxXvucL08BTTQixEnpAVQAAAFo"]
[Thu Sep 17 15:12:30.073656 2026] [security2:error] [pid 971102:tid 971246] [client 45.169.98.18:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvucL08BTTQixEnpAVgAAAAw"]
[Thu Sep 17 15:12:30.073784 2026] [security2:error] [pid 971102:tid 971246] [client 45.169.98.18:59099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvucL08BTTQixEnpAVgAAAAw"]
[Thu Sep 17 15:12:30.111062 2026] [security2:error] [pid 971102:tid 971280] [client 34.32.0.94:35964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXvucL08BTTQixEnpAVwAAAC4"]
[Thu Sep 17 15:12:30.150014 2026] [security2:error] [pid 971102:tid 971261] [client 52.231.79.181:1857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/worksec.php"] [unique_id "aqxXvucL08BTTQixEnpAWgAAABs"]
[Thu Sep 17 15:12:30.159584 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.117.146:60076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXvecL08BTTQixEnpATQAAACk"]
[Thu Sep 17 15:12:30.213649 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/ses/.env"] [unique_id "aqxXvucL08BTTQixEnpAXAAAABU"]
[Thu Sep 17 15:12:30.298907 2026] [security2:error] [pid 971102:tid 971333] [client 88.99.80.227:43570] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxXvucL08BTTQixEnpAXgAAAGM"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:12:30.314729 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxXvucL08BTTQixEnpAYQAAAHI"]
[Thu Sep 17 15:12:30.447735 2026] [security2:error] [pid 971102:tid 971265] [client 47.79.206.108:15722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxXvucL08BTTQixEnpAXQAAAB8"], referer: https://www.google.com/
[Thu Sep 17 15:12:30.449253 2026] [fcgid:warn] [pid 971102:tid 971244] (70014)End of file found: [client 66.132.224.237:33594] mod_fcgid: can't get data from http client
[Thu Sep 17 15:12:30.449280 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sendgrid/.env"] [unique_id "aqxXvucL08BTTQixEnpAZAAAAE8"]
[Thu Sep 17 15:12:30.453421 2026] [security2:error] [pid 971102:tid 971304] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "aqxXvucL08BTTQixEnpAZgAAAEY"]
[Thu Sep 17 15:12:30.476958 2026] [authz_core:error] [pid 971102:tid 971343] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/ChaCha20/error_log
[Thu Sep 17 15:12:30.479557 2026] [security2:error] [pid 971102:tid 971343] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxXvucL08BTTQixEnpAZwAAAG0"]
[Thu Sep 17 15:12:30.573459 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXvucL08BTTQixEnpAaAAAAF0"]
[Thu Sep 17 15:12:30.581967 2026] [security2:error] [pid 971102:tid 971352] [client 52.231.79.181:1867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/ultra.php"] [unique_id "aqxXvucL08BTTQixEnpAaQAAAHY"]
[Thu Sep 17 15:12:30.632758 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXvucL08BTTQixEnpAagAAAC8"]
[Thu Sep 17 15:12:30.681740 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sparkpost/.env"] [unique_id "aqxXvucL08BTTQixEnpAawAAADo"]
[Thu Sep 17 15:12:30.683433 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "aqxXvucL08BTTQixEnpAbAAAADw"]
[Thu Sep 17 15:12:30.780471 2026] [security2:error] [pid 971102:tid 971264] [client 88.99.80.227:43572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxXvucL08BTTQixEnpAbwAAAB4"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:12:30.911400 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aqxXvucL08BTTQixEnpAdgAAABo"]
[Thu Sep 17 15:12:30.914448 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/postmark/.env"] [unique_id "aqxXvucL08BTTQixEnpAdwAAAD8"]
[Thu Sep 17 15:12:30.959576 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvucL08BTTQixEnpAcAAAAFg"]
[Thu Sep 17 15:12:30.959595 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvucL08BTTQixEnpAcAAAAFg"]
[Thu Sep 17 15:12:30.987288 2026] [security2:error] [pid 971102:tid 971291] [client 52.231.79.181:1885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/gecko.php"] [unique_id "aqxXvucL08BTTQixEnpAeAAAADk"]
[Thu Sep 17 15:12:31.006719 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.117.146:60076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXv-cL08BTTQixEnpAeQAAABY"]
[Thu Sep 17 15:12:31.018311 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.0.94:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXv-cL08BTTQixEnpAegAAAHw"]
[Thu Sep 17 15:12:31.103542 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxXv-cL08BTTQixEnpAfAAAAEI"]
[Thu Sep 17 15:12:31.103618 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxXv-cL08BTTQixEnpAfAAAAEI"]
[Thu Sep 17 15:12:31.139775 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "aqxXv-cL08BTTQixEnpAfQAAACg"]
[Thu Sep 17 15:12:31.142184 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailgun/.env"] [unique_id "aqxXv-cL08BTTQixEnpAfgAAADU"]
[Thu Sep 17 15:12:31.281184 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.221.252:43406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXv-cL08BTTQixEnpAfwAAAGs"]
[Thu Sep 17 15:12:31.367422 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "aqxXv-cL08BTTQixEnpAhAAAADA"]
[Thu Sep 17 15:12:31.368823 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mandrill/.env"] [unique_id "aqxXv-cL08BTTQixEnpAhQAAADg"]
[Thu Sep 17 15:12:31.381135 2026] [security2:error] [pid 971102:tid 971250] [client 52.231.79.181:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/goods.php"] [unique_id "aqxXv-cL08BTTQixEnpAhgAAABA"]
[Thu Sep 17 15:12:31.381634 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXv-cL08BTTQixEnpAhwAAABM"]
[Thu Sep 17 15:12:31.381719 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXv-cL08BTTQixEnpAhwAAABM"]
[Thu Sep 17 15:12:31.479565 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.0.94:35994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXv-cL08BTTQixEnpAiAAAAHg"]
[Thu Sep 17 15:12:31.595859 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailjet/.env"] [unique_id "aqxXv-cL08BTTQixEnpAigAAAAU"]
[Thu Sep 17 15:12:31.595862 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "aqxXv-cL08BTTQixEnpAiQAAACQ"]
[Thu Sep 17 15:12:31.657794 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.117.146:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXv-cL08BTTQixEnpAjAAAAG8"]
[Thu Sep 17 15:12:31.664487 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:36290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxXv-cL08BTTQixEnpAjQAAAHs"]
[Thu Sep 17 15:12:31.664570 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:36290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxXv-cL08BTTQixEnpAjQAAAHs"]
[Thu Sep 17 15:12:31.808915 2026] [security2:error] [pid 971102:tid 971259] [client 52.231.79.181:1859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/man.php"] [unique_id "aqxXv-cL08BTTQixEnpAkwAAABk"]
[Thu Sep 17 15:12:31.808948 2026] [authz_core:error] [pid 971102:tid 971249] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:31.822080 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/brevo/.env"] [unique_id "aqxXv-cL08BTTQixEnpAlQAAAGY"]
[Thu Sep 17 15:12:31.849895 2026] [core:error] [pid 971102:tid 971324] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:31.849909 2026] [core:error] [pid 971102:tid 971324] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:31.927123 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXv-cL08BTTQixEnpAmgAAAAE"]
[Thu Sep 17 15:12:31.948724 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:36302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxXv-cL08BTTQixEnpAmwAAACk"]
[Thu Sep 17 15:12:31.963433 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.221.252:43422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXv-cL08BTTQixEnpAnAAAAGQ"]
[Thu Sep 17 15:12:32.052072 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/transactional/.env"] [unique_id "aqxXwOcL08BTTQixEnpAnQAAADI"]
[Thu Sep 17 15:12:32.102209 2026] [authz_core:error] [pid 971102:tid 971279] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Curve25519/error_log
[Thu Sep 17 15:12:32.109199 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxXwOcL08BTTQixEnpAngAAAC0"]
[Thu Sep 17 15:12:32.233641 2026] [security2:error] [pid 971102:tid 971318] [client 52.231.79.181:1874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-settings.php"] [unique_id "aqxXwOcL08BTTQixEnpAoAAAAFQ"]
[Thu Sep 17 15:12:32.254098 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:36302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXwOcL08BTTQixEnpAogAAACI"]
[Thu Sep 17 15:12:32.286415 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/bulk/.env"] [unique_id "aqxXwOcL08BTTQixEnpApQAAACU"]
[Thu Sep 17 15:12:32.392106 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXwOcL08BTTQixEnpAqgAAAFk"]
[Thu Sep 17 15:12:32.514429 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxXwOcL08BTTQixEnpArAAAADw"]
[Thu Sep 17 15:12:32.589876 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "aqxXwOcL08BTTQixEnpAsgAAAEo"]
[Thu Sep 17 15:12:32.618195 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwOcL08BTTQixEnpAqQAAAA4"]
[Thu Sep 17 15:12:32.618218 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwOcL08BTTQixEnpAqQAAAA4"]
[Thu Sep 17 15:12:32.629180 2026] [security2:error] [pid 971102:tid 971292] [client 52.231.79.181:1912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/k.php"] [unique_id "aqxXwOcL08BTTQixEnpAtQAAADo"]
[Thu Sep 17 15:12:32.658517 2026] [security2:error] [pid 971102:tid 971237] [client 34.32.117.146:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXwOcL08BTTQixEnpAtgAAAAM"]
[Thu Sep 17 15:12:32.742484 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/azure/.env"] [unique_id "aqxXwOcL08BTTQixEnpAtwAAAHw"]
[Thu Sep 17 15:12:32.760797 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxXwOcL08BTTQixEnpAuAAAAFs"]
[Thu Sep 17 15:12:32.760934 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:36302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxXwOcL08BTTQixEnpAuAAAAFs"]
[Thu Sep 17 15:12:32.770456 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.221.252:43434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXwOcL08BTTQixEnpAuQAAAB4"]
[Thu Sep 17 15:12:32.823211 2026] [security2:error] [pid 971102:tid 971288] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "aqxXwOcL08BTTQixEnpAvQAAADY"]
[Thu Sep 17 15:12:32.853580 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.0.94:36020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php~"] [unique_id "aqxXwOcL08BTTQixEnpAvgAAADk"]
[Thu Sep 17 15:12:32.955282 2026] [security2:error] [pid 971102:tid 971250] [client 5.189.145.112:61269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxXwOcL08BTTQixEnpAwAAAABA"], referer: binance.com
[Thu Sep 17 15:12:32.970355 2026] [security2:error] [pid 971102:tid 971285] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/gcp/.env"] [unique_id "aqxXwOcL08BTTQixEnpAwQAAADM"]
[Thu Sep 17 15:12:33.026939 2026] [security2:error] [pid 971102:tid 971272] [client 52.231.79.181:1870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/autoload_classmap.php"] [unique_id "aqxXwecL08BTTQixEnpAwgAAACY"]
[Thu Sep 17 15:12:33.053205 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "aqxXwecL08BTTQixEnpAwwAAAGI"]
[Thu Sep 17 15:12:33.057988 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:36314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxXwecL08BTTQixEnpAxQAAAFM"]
[Thu Sep 17 15:12:33.075277 2026] [security2:error] [pid 971102:tid 971322] [client 156.192.234.52:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpAxgAAAFg"]
[Thu Sep 17 15:12:33.076757 2026] [security2:error] [pid 971102:tid 971322] [client 156.192.234.52:50247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpAxgAAAFg"]
[Thu Sep 17 15:12:33.095194 2026] [security2:error] [pid 971102:tid 971170] [remote 216.73.217.142:38405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxXwecL08BTTQixEnpAxAAAGkI"]
[Thu Sep 17 15:12:33.197842 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cloud/.env"] [unique_id "aqxXwecL08BTTQixEnpAxwAAAEs"]
[Thu Sep 17 15:12:33.219098 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxXwecL08BTTQixEnpAyAAAAHo"]
[Thu Sep 17 15:12:33.284511 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "aqxXwecL08BTTQixEnpAyQAAADQ"]
[Thu Sep 17 15:12:33.317902 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/info.php.bak"] [unique_id "aqxXwecL08BTTQixEnpAygAAACQ"]
[Thu Sep 17 15:12:33.362048 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:36314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxXwecL08BTTQixEnpAzQAAAGk"]
[Thu Sep 17 15:12:33.423241 2026] [security2:error] [pid 971102:tid 971328] [client 52.231.79.181:1879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/profile.php"] [unique_id "aqxXwecL08BTTQixEnpAzgAAAF4"]
[Thu Sep 17 15:12:33.427022 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/infrastructure/.env"] [unique_id "aqxXwecL08BTTQixEnpAzwAAACM"]
[Thu Sep 17 15:12:33.450337 2026] [security2:error] [pid 971102:tid 971289] [client 34.32.117.146:60114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXwecL08BTTQixEnpA0QAAADc"]
[Thu Sep 17 15:12:33.514910 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "aqxXwecL08BTTQixEnpA1AAAAF8"]
[Thu Sep 17 15:12:33.655132 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/docker/.env"] [unique_id "aqxXwecL08BTTQixEnpA2AAAAFY"]
[Thu Sep 17 15:12:33.696195 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwecL08BTTQixEnpA0wAAAA0"]
[Thu Sep 17 15:12:33.696218 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwecL08BTTQixEnpA0wAAAA0"]
[Thu Sep 17 15:12:33.713163 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.221.252:43446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXwecL08BTTQixEnpA2QAAACo"]
[Thu Sep 17 15:12:33.745919 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/core/app/.env"] [unique_id "aqxXwecL08BTTQixEnpA2gAAABU"]
[Thu Sep 17 15:12:33.759399 2026] [security2:error] [pid 971102:tid 971280] [client 185.55.149.49:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA2wAAAC4"]
[Thu Sep 17 15:12:33.759492 2026] [security2:error] [pid 971102:tid 971280] [client 185.55.149.49:54929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA2wAAAC4"]
[Thu Sep 17 15:12:33.777805 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXwecL08BTTQixEnpA3AAAADI"]
[Thu Sep 17 15:12:33.822606 2026] [security2:error] [pid 971102:tid 971302] [client 52.231.79.181:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/server.php"] [unique_id "aqxXwecL08BTTQixEnpA3wAAAEQ"]
[Thu Sep 17 15:12:33.824705 2026] [security2:error] [pid 971102:tid 971246] [client 115.244.164.14:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA4AAAAAw"]
[Thu Sep 17 15:12:33.824784 2026] [security2:error] [pid 971102:tid 971246] [client 115.244.164.14:54762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA4AAAAAw"]
[Thu Sep 17 15:12:33.837081 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:36314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXwecL08BTTQixEnpA4QAAAHI"]
[Thu Sep 17 15:12:33.837153 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:36314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXwecL08BTTQixEnpA4QAAAHI"]
[Thu Sep 17 15:12:33.882538 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/k8s/.env"] [unique_id "aqxXwecL08BTTQixEnpA4gAAAB8"]
[Thu Sep 17 15:12:33.979488 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "aqxXwecL08BTTQixEnpA5wAAAG0"]
[Thu Sep 17 15:12:33.980095 2026] [security2:error] [pid 971102:tid 971321] [client 162.241.226.11:47980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mechapteriaao.org"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxXwecL08BTTQixEnpA5gAAAFc"]
[Thu Sep 17 15:12:34.111422 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/kubernetes/.env"] [unique_id "aqxXwucL08BTTQixEnpA7QAAABE"]
[Thu Sep 17 15:12:34.171265 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXwucL08BTTQixEnpA8AAAADo"]
[Thu Sep 17 15:12:34.171386 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:36316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXwucL08BTTQixEnpA8AAAADo"]
[Thu Sep 17 15:12:34.212259 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "aqxXwucL08BTTQixEnpA8QAAAHw"]
[Thu Sep 17 15:12:34.226632 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXwucL08BTTQixEnpA8gAAACs"]
[Thu Sep 17 15:12:34.232104 2026] [security2:error] [pid 971102:tid 971316] [client 52.231.79.181:1902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/shell.php"] [unique_id "aqxXwucL08BTTQixEnpA8wAAAFI"]
[Thu Sep 17 15:12:34.235873 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.0.94:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXwucL08BTTQixEnpA9AAAADw"]
[Thu Sep 17 15:12:34.338850 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/terraform/.env"] [unique_id "aqxXwucL08BTTQixEnpA9wAAAGA"]
[Thu Sep 17 15:12:34.451905 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "aqxXwucL08BTTQixEnpA-gAAAEk"]
[Thu Sep 17 15:12:34.461460 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:36332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXwucL08BTTQixEnpA-wAAADk"]
[Thu Sep 17 15:12:34.461542 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:36332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXwucL08BTTQixEnpA-wAAADk"]
[Thu Sep 17 15:12:34.565392 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/ansible/.env"] [unique_id "aqxXwucL08BTTQixEnpA_wAAAB0"]
[Thu Sep 17 15:12:34.644085 2026] [security2:error] [pid 971102:tid 971238] [client 52.231.79.181:1903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/t.php"] [unique_id "aqxXwucL08BTTQixEnpBAQAAAAQ"]
[Thu Sep 17 15:12:34.688794 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/bootstrap/.env"] [unique_id "aqxXwucL08BTTQixEnpBAwAAAHg"]
[Thu Sep 17 15:12:34.700225 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.0.94:47512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXwucL08BTTQixEnpBBAAAAFE"]
[Thu Sep 17 15:12:34.769208 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXwucL08BTTQixEnpBBgAAAG4"]
[Thu Sep 17 15:12:34.769324 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:36334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXwucL08BTTQixEnpBBgAAAG4"]
[Thu Sep 17 15:12:34.793710 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.git/.env"] [unique_id "aqxXwucL08BTTQixEnpBBwAAACY"]
[Thu Sep 17 15:12:34.920128 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "aqxXwucL08BTTQixEnpBDAAAAAU"]
[Thu Sep 17 15:12:35.021468 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/ci/.env"] [unique_id "aqxXw-cL08BTTQixEnpBDgAAAGk"]
[Thu Sep 17 15:12:35.044220 2026] [security2:error] [pid 971102:tid 971300] [client 52.231.79.181:1906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/hello.php"] [unique_id "aqxXw-cL08BTTQixEnpBDwAAAEI"]
[Thu Sep 17 15:12:35.071469 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXw-cL08BTTQixEnpBEgAAACM"]
[Thu Sep 17 15:12:35.071569 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXw-cL08BTTQixEnpBEgAAACM"]
[Thu Sep 17 15:12:35.152514 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "aqxXw-cL08BTTQixEnpBFAAAAF8"]
[Thu Sep 17 15:12:35.153793 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:47514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXw-cL08BTTQixEnpBFQAAACQ"]
[Thu Sep 17 15:12:35.248626 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cd/.env"] [unique_id "aqxXw-cL08BTTQixEnpBGAAAAGQ"]
[Thu Sep 17 15:12:35.278130 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.117.146:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXw-cL08BTTQixEnpBGgAAAGY"]
[Thu Sep 17 15:12:35.387178 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "aqxXw-cL08BTTQixEnpBHgAAAHk"]
[Thu Sep 17 15:12:35.422655 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxXw-cL08BTTQixEnpBIAAAAA0"]
[Thu Sep 17 15:12:35.422773 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:36358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxXw-cL08BTTQixEnpBIAAAAA0"]
[Thu Sep 17 15:12:35.475158 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/jenkins/.env"] [unique_id "aqxXw-cL08BTTQixEnpBIQAAAC4"]
[Thu Sep 17 15:12:35.606279 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:47528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXw-cL08BTTQixEnpBJAAAACo"]
[Thu Sep 17 15:12:35.620873 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "aqxXw-cL08BTTQixEnpBJQAAAE8"]
[Thu Sep 17 15:12:35.705142 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:36360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxXw-cL08BTTQixEnpBKQAAAFc"]
[Thu Sep 17 15:12:35.705241 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:36360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxXw-cL08BTTQixEnpBKQAAAFc"]
[Thu Sep 17 15:12:35.705927 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/gitlab/.env"] [unique_id "aqxXw-cL08BTTQixEnpBKAAAAG0"]
[Thu Sep 17 15:12:35.857869 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/current/.env"] [unique_id "aqxXw-cL08BTTQixEnpBKwAAAFQ"]
[Thu Sep 17 15:12:35.893381 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.117.146:60148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXw-cL08BTTQixEnpBLgAAACA"]
[Thu Sep 17 15:12:35.933438 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/github/.env"] [unique_id "aqxXw-cL08BTTQixEnpBLwAAAC0"]
[Thu Sep 17 15:12:35.991842 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxXw-cL08BTTQixEnpBMAAAAAs"]
[Thu Sep 17 15:12:35.991935 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:36364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxXw-cL08BTTQixEnpBMAAAAAs"]
[Thu Sep 17 15:12:36.054980 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:47540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXxOcL08BTTQixEnpBMQAAABw"]
[Thu Sep 17 15:12:36.089733 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/release/.env"] [unique_id "aqxXxOcL08BTTQixEnpBNQAAACk"]
[Thu Sep 17 15:12:36.168277 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/actions/.env"] [unique_id "aqxXxOcL08BTTQixEnpBOAAAAEU"]
[Thu Sep 17 15:12:36.286521 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxXxOcL08BTTQixEnpBOgAAACs"]
[Thu Sep 17 15:12:36.286604 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:36376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxXxOcL08BTTQixEnpBOgAAACs"]
[Thu Sep 17 15:12:36.322899 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/releases/.env"] [unique_id "aqxXxOcL08BTTQixEnpBOwAAAFI"]
[Thu Sep 17 15:12:36.401950 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/circleci/.env"] [unique_id "aqxXxOcL08BTTQixEnpBPQAAAGU"]
[Thu Sep 17 15:12:36.534520 2026] [security2:error] [pid 971102:tid 971295] [client 34.32.0.94:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXxOcL08BTTQixEnpBQQAAAD0"]
[Thu Sep 17 15:12:36.557015 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "aqxXxOcL08BTTQixEnpBQgAAAB0"]
[Thu Sep 17 15:12:36.572987 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxXxOcL08BTTQixEnpBRQAAAC8"]
[Thu Sep 17 15:12:36.573085 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:36384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxXxOcL08BTTQixEnpBRQAAAC8"]
[Thu Sep 17 15:12:36.629678 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/travis/.env"] [unique_id "aqxXxOcL08BTTQixEnpBRwAAADA"]
[Thu Sep 17 15:12:36.669418 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.117.146:60154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXxOcL08BTTQixEnpBSgAAAAo"]
[Thu Sep 17 15:12:36.791681 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "aqxXxOcL08BTTQixEnpBSwAAACw"]
[Thu Sep 17 15:12:36.860904 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:36400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxXxOcL08BTTQixEnpBTwAAAFE"]
[Thu Sep 17 15:12:36.862935 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/buildkite/.env"] [unique_id "aqxXxOcL08BTTQixEnpBUAAAAG4"]
[Thu Sep 17 15:12:37.015590 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.0.94:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXxecL08BTTQixEnpBVAAAADM"]
[Thu Sep 17 15:12:37.024507 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/build/.env"] [unique_id "aqxXxecL08BTTQixEnpBVgAAAHs"]
[Thu Sep 17 15:12:37.037569 2026] [authz_core:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Poly1305/error_log
[Thu Sep 17 15:12:37.038958 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxXxecL08BTTQixEnpBVQAAAHo"]
[Thu Sep 17 15:12:37.081435 2026] [authz_core:error] [pid 971102:tid 971338] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:37.097283 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mysql/.env"] [unique_id "aqxXxecL08BTTQixEnpBXAAAAEI"]
[Thu Sep 17 15:12:37.122429 2026] [security2:error] [pid 971102:tid 971322] [client 162.241.226.11:47982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mechapteriaao.org"] [uri "/wp-cron.php"] [unique_id "aqxXxecL08BTTQixEnpBXwAAAFg"]
[Thu Sep 17 15:12:37.183004 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:36400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXxecL08BTTQixEnpBYQAAAEE"]
[Thu Sep 17 15:12:37.259049 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/dist/.env"] [unique_id "aqxXxecL08BTTQixEnpBYgAAAGY"]
[Thu Sep 17 15:12:37.329337 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/postgres/.env"] [unique_id "aqxXxecL08BTTQixEnpBYwAAAGw"]
[Thu Sep 17 15:12:37.457624 2026] [security2:error] [pid 971102:tid 971261] [client 34.32.117.146:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php~"] [unique_id "aqxXxecL08BTTQixEnpBaAAAABs"]
[Thu Sep 17 15:12:37.486569 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:47562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXxecL08BTTQixEnpBaQAAAAE"]
[Thu Sep 17 15:12:37.492345 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "aqxXxecL08BTTQixEnpBagAAAFY"]
[Thu Sep 17 15:12:37.550412 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXxecL08BTTQixEnpBZAAAAF4"]
[Thu Sep 17 15:12:37.550439 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXxecL08BTTQixEnpBZAAAAF4"]
[Thu Sep 17 15:12:37.557591 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mongodb/.env"] [unique_id "aqxXxecL08BTTQixEnpBbAAAAHE"]
[Thu Sep 17 15:12:37.725006 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "aqxXxecL08BTTQixEnpBcgAAACo"]
[Thu Sep 17 15:12:37.726270 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxXxecL08BTTQixEnpBcwAAADs"]
[Thu Sep 17 15:12:37.726346 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:36400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxXxecL08BTTQixEnpBcwAAADs"]
[Thu Sep 17 15:12:37.785367 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/redis/.env"] [unique_id "aqxXxecL08BTTQixEnpBdAAAAH0"]
[Thu Sep 17 15:12:37.945624 2026] [security2:error] [pid 971102:tid 971249] [client 34.32.0.94:47568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXxecL08BTTQixEnpBdgAAAA8"]
[Thu Sep 17 15:12:37.958932 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "aqxXxecL08BTTQixEnpBdwAAACE"]
[Thu Sep 17 15:12:38.003314 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:36402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxXxucL08BTTQixEnpBegAAACI"]
[Thu Sep 17 15:12:38.003424 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:36402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxXxucL08BTTQixEnpBegAAACI"]
[Thu Sep 17 15:12:38.012363 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/elasticsearch/.env"] [unique_id "aqxXxucL08BTTQixEnpBewAAAEw"]
[Thu Sep 17 15:12:38.041269 2026] [security2:error] [pid 971102:tid 971311] [client 114.198.138.124:61850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBfAAAAE0"]
[Thu Sep 17 15:12:38.041360 2026] [security2:error] [pid 971102:tid 971311] [client 114.198.138.124:61850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBfAAAAE0"]
[Thu Sep 17 15:12:38.191795 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "aqxXxucL08BTTQixEnpBfwAAAEU"]
[Thu Sep 17 15:12:38.240603 2026] [security2:error] [pid 971102:tid 971304] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/rabbitmq/.env"] [unique_id "aqxXxucL08BTTQixEnpBggAAAEY"]
[Thu Sep 17 15:12:38.285246 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxXxucL08BTTQixEnpBgwAAAAI"]
[Thu Sep 17 15:12:38.285327 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:36408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxXxucL08BTTQixEnpBgwAAAAI"]
[Thu Sep 17 15:12:38.384613 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.117.146:38348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/info.php.bak"] [unique_id "aqxXxucL08BTTQixEnpBhwAAACk"]
[Thu Sep 17 15:12:38.410073 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXxucL08BTTQixEnpBiAAAAFI"]
[Thu Sep 17 15:12:38.421621 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/live/.env"] [unique_id "aqxXxucL08BTTQixEnpBiwAAAE4"]
[Thu Sep 17 15:12:38.468187 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/kafka/.env"] [unique_id "aqxXxucL08BTTQixEnpBjgAAABQ"]
[Thu Sep 17 15:12:38.564858 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:36418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxXxucL08BTTQixEnpBkgAAABg"]
[Thu Sep 17 15:12:38.566609 2026] [security2:error] [pid 971102:tid 971191] [remote 216.73.217.142:38405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxXxucL08BTTQixEnpBkwAANFY"]
[Thu Sep 17 15:12:38.651004 2026] [security2:error] [pid 971102:tid 971306] [client 162.241.226.11:47984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mechapteriaao.org"] [uri "/wp-cron.php"] [unique_id "aqxXxucL08BTTQixEnpBlwAAAEg"]
[Thu Sep 17 15:12:38.651300 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "aqxXxucL08BTTQixEnpBmAAAABM"]
[Thu Sep 17 15:12:38.700490 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/queue/.env"] [unique_id "aqxXxucL08BTTQixEnpBmQAAADg"]
[Thu Sep 17 15:12:38.719034 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxXxucL08BTTQixEnpBmgAAAFE"]
[Thu Sep 17 15:12:38.731206 2026] [security2:error] [pid 971102:tid 971335] [client 186.105.232.15:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBmwAAAGU"]
[Thu Sep 17 15:12:38.731351 2026] [security2:error] [pid 971102:tid 971335] [client 186.105.232.15:55351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBmwAAAGU"]
[Thu Sep 17 15:12:38.841376 2026] [security2:error] [pid 971102:tid 971341] [client 154.190.208.131:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBngAAAGs"]
[Thu Sep 17 15:12:38.846701 2026] [security2:error] [pid 971102:tid 971341] [client 154.190.208.131:41410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBngAAAGs"]
[Thu Sep 17 15:12:38.858756 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:36418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXxucL08BTTQixEnpBnwAAABo"]
[Thu Sep 17 15:12:38.868414 2026] [security2:error] [pid 971102:tid 971344] [client 34.32.0.94:47578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXxucL08BTTQixEnpBoAAAAG4"]
[Thu Sep 17 15:12:38.881499 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "aqxXxucL08BTTQixEnpBoQAAAHs"]
[Thu Sep 17 15:12:38.927797 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/worker/.env"] [unique_id "aqxXxucL08BTTQixEnpBpQAAAEc"]
[Thu Sep 17 15:12:39.121480 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "aqxXx-cL08BTTQixEnpBrAAAAAU"]
[Thu Sep 17 15:12:39.158057 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/job/.env"] [unique_id "aqxXx-cL08BTTQixEnpBrQAAAGY"]
[Thu Sep 17 15:12:39.224617 2026] [security2:error] [pid 971102:tid 971269] [client 34.32.117.146:38356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXx-cL08BTTQixEnpBswAAACM"]
[Thu Sep 17 15:12:39.242384 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXx-cL08BTTQixEnpBpwAAAFo"]
[Thu Sep 17 15:12:39.242409 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXx-cL08BTTQixEnpBpwAAAFo"]
[Thu Sep 17 15:12:39.319403 2026] [security2:error] [pid 971102:tid 971342] [client 34.32.0.94:47590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXx-cL08BTTQixEnpBtgAAAGw"]
[Thu Sep 17 15:12:39.355590 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/opt/.env"] [unique_id "aqxXx-cL08BTTQixEnpBtwAAAHE"]
[Thu Sep 17 15:12:39.387401 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxXx-cL08BTTQixEnpBuQAAADI"]
[Thu Sep 17 15:12:39.422812 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:36418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxXx-cL08BTTQixEnpBugAAAEQ"]
[Thu Sep 17 15:12:39.422914 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:36418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxXx-cL08BTTQixEnpBugAAAEQ"]
[Thu Sep 17 15:12:39.585498 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "aqxXx-cL08BTTQixEnpBxgAAAA8"]
[Thu Sep 17 15:12:39.614382 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/qa/.env"] [unique_id "aqxXx-cL08BTTQixEnpByAAAAFQ"]
[Thu Sep 17 15:12:39.725210 2026] [authz_core:error] [pid 971102:tid 971327] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:12:39.783471 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.0.94:47602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/core/phpinfo.php"] [unique_id "aqxXx-cL08BTTQixEnpBzgAAAE0"]
[Thu Sep 17 15:12:39.826445 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "aqxXx-cL08BTTQixEnpBzwAAAAM"]
[Thu Sep 17 15:12:39.841816 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/preview/.env"] [unique_id "aqxXx-cL08BTTQixEnpB0AAAAC0"]
[Thu Sep 17 15:12:39.866865 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxXx-cL08BTTQixEnpB0QAAAEY"]
[Thu Sep 17 15:12:39.866993 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:36424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxXx-cL08BTTQixEnpB0QAAAEY"]
[Thu Sep 17 15:12:39.931170 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.117.146:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXx-cL08BTTQixEnpB0gAAABU"]
[Thu Sep 17 15:12:40.057995 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "aqxXyOcL08BTTQixEnpB2wAAAFI"]
[Thu Sep 17 15:12:40.069059 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/beta/.env"] [unique_id "aqxXyOcL08BTTQixEnpB3AAAAE4"]
[Thu Sep 17 15:12:40.145151 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:36054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxXyOcL08BTTQixEnpB3gAAABQ"]
[Thu Sep 17 15:12:40.145266 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:36054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxXyOcL08BTTQixEnpB3gAAABQ"]
[Thu Sep 17 15:12:40.256073 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:47604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxXyOcL08BTTQixEnpB4AAAAEo"]
[Thu Sep 17 15:12:40.297241 2026] [security2:error] [pid 971102:tid 971281] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "aqxXyOcL08BTTQixEnpB4gAAAC8"]
[Thu Sep 17 15:12:40.297241 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/uat/.env"] [unique_id "aqxXyOcL08BTTQixEnpB4QAAADA"]
[Thu Sep 17 15:12:40.424622 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxXyOcL08BTTQixEnpB5AAAABM"]
[Thu Sep 17 15:12:40.424760 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxXyOcL08BTTQixEnpB5AAAABM"]
[Thu Sep 17 15:12:40.527596 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/stage/.env"] [unique_id "aqxXyOcL08BTTQixEnpB6AAAACY"]
[Thu Sep 17 15:12:40.533445 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "aqxXyOcL08BTTQixEnpB6QAAAGI"]
[Thu Sep 17 15:12:40.554806 2026] [security2:error] [pid 971102:tid 971325] [client 45.169.98.18:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXyOcL08BTTQixEnpB6gAAAFs"]
[Thu Sep 17 15:12:40.554948 2026] [security2:error] [pid 971102:tid 971325] [client 45.169.98.18:59659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXyOcL08BTTQixEnpB6gAAAFs"]
[Thu Sep 17 15:12:40.683963 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.117.146:38366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXyOcL08BTTQixEnpB7AAAAFE"]
[Thu Sep 17 15:12:40.702850 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:36074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxXyOcL08BTTQixEnpB7gAAAGg"]
[Thu Sep 17 15:12:40.702927 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:36074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxXyOcL08BTTQixEnpB7gAAAGg"]
[Thu Sep 17 15:12:40.721723 2026] [security2:error] [pid 971102:tid 971287] [client 5.189.145.112:64170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxXyOcL08BTTQixEnpB8gAAADU"], referer: binance.com
[Thu Sep 17 15:12:40.743973 2026] [access_compat:error] [pid 971102:tid 971339] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/jixo-5-mask-parade-collectors-edition
[Thu Sep 17 15:12:40.754794 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/development/.env"] [unique_id "aqxXyOcL08BTTQixEnpB9QAAAFM"]
[Thu Sep 17 15:12:40.767510 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/drupal/.env"] [unique_id "aqxXyOcL08BTTQixEnpB9gAAACQ"]
[Thu Sep 17 15:12:40.935397 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyOcL08BTTQixEnpB8QAAABo"]
[Thu Sep 17 15:12:40.981168 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxXyOcL08BTTQixEnpB-gAAABc"]
[Thu Sep 17 15:12:40.981280 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxXyOcL08BTTQixEnpB-gAAABc"]
[Thu Sep 17 15:12:40.982413 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxXyOcL08BTTQixEnpB-wAAAFo"]
[Thu Sep 17 15:12:41.000903 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/joomla/.env"] [unique_id "aqxXyOcL08BTTQixEnpB_QAAABs"]
[Thu Sep 17 15:12:41.210249 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/config/app/.env"] [unique_id "aqxXyecL08BTTQixEnpCAgAAAHE"]
[Thu Sep 17 15:12:41.231510 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/magento/.env"] [unique_id "aqxXyecL08BTTQixEnpCBAAAAHU"]
[Thu Sep 17 15:12:41.262844 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:36100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXyecL08BTTQixEnpCBwAAAB8"]
[Thu Sep 17 15:12:41.321441 2026] [security2:error] [pid 971102:tid 971349] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpB_wAAAHM"]
[Thu Sep 17 15:12:41.422186 2026] [authz_core:error] [pid 971102:tid 971299] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/error_log
[Thu Sep 17 15:12:41.436441 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.194.17:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php"] [unique_id "aqxXyecL08BTTQixEnpCCwAAAA8"]
[Thu Sep 17 15:12:41.445869 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXyecL08BTTQixEnpCCgAAAEE"]
[Thu Sep 17 15:12:41.464537 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.117.146:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXyecL08BTTQixEnpCDQAAADI"]
[Thu Sep 17 15:12:41.464537 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/shopify/.env"] [unique_id "aqxXyecL08BTTQixEnpCDAAAACE"]
[Thu Sep 17 15:12:41.586044 2026] [autoindex:error] [pid 971102:tid 971276] [client 104.252.111.195:34234] AH01276: Cannot serve directory /home4/wisdomel/public_html/enchantedpapers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:12:41.598887 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:36100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/wp-includes/sodium_compat/src/"] [unique_id "aqxXyecL08BTTQixEnpCFgAAAA0"]
[Thu Sep 17 15:12:41.640056 2026] [security2:error] [pid 971102:tid 971126] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxXyecL08BTTQixEnpCFwAADhY"]
[Thu Sep 17 15:12:41.679858 2026] [security2:error] [pid 971102:tid 971310] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCDgAAAEw"]
[Thu Sep 17 15:12:41.697743 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/prestashop/.env"] [unique_id "aqxXyecL08BTTQixEnpCGAAAAHY"]
[Thu Sep 17 15:12:41.931538 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/codeigniter/.env"] [unique_id "aqxXyecL08BTTQixEnpCHQAAAGM"]
[Thu Sep 17 15:12:41.951150 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCGgAAAE0"]
[Thu Sep 17 15:12:41.951177 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCGgAAAE0"]
[Thu Sep 17 15:12:42.048813 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCGwAAAEY"]
[Thu Sep 17 15:12:42.097231 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:36100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxXyucL08BTTQixEnpCIgAAAGo"]
[Thu Sep 17 15:12:42.097354 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:36100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxXyucL08BTTQixEnpCIgAAAGo"]
[Thu Sep 17 15:12:42.103416 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:38374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXyucL08BTTQixEnpCIwAAACs"]
[Thu Sep 17 15:12:42.119395 2026] [security2:error] [pid 971102:tid 971246] [client 34.166.194.17:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/info.php"] [unique_id "aqxXyucL08BTTQixEnpCJAAAAAw"]
[Thu Sep 17 15:12:42.162361 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cakephp/.env"] [unique_id "aqxXyucL08BTTQixEnpCJwAAADk"]
[Thu Sep 17 15:12:42.385902 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxXyucL08BTTQixEnpCKwAAABM"]
[Thu Sep 17 15:12:42.386029 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxXyucL08BTTQixEnpCKwAAABM"]
[Thu Sep 17 15:12:42.402987 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyucL08BTTQixEnpCKQAAACU"]
[Thu Sep 17 15:12:42.406169 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/zend/.env"] [unique_id "aqxXyucL08BTTQixEnpCLAAAACw"]
[Thu Sep 17 15:12:42.639231 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/yii/.env"] [unique_id "aqxXyucL08BTTQixEnpCMwAAADU"]
[Thu Sep 17 15:12:42.694118 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:36118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxXyucL08BTTQixEnpCNwAAACc"]
[Thu Sep 17 15:12:42.775799 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyucL08BTTQixEnpCMQAAAAo"]
[Thu Sep 17 15:12:42.820252 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.194.17:38200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/php.php"] [unique_id "aqxXyucL08BTTQixEnpCOQAAAHo"]
[Thu Sep 17 15:12:42.854930 2026] [authz_core:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/ChaCha20/error_log
[Thu Sep 17 15:12:42.856998 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxXyucL08BTTQixEnpCOgAAACQ"]
[Thu Sep 17 15:12:42.872994 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/laravel5/.env"] [unique_id "aqxXyucL08BTTQixEnpCOwAAAAU"]
[Thu Sep 17 15:12:42.975907 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXyucL08BTTQixEnpCQAAAAF8"]
[Thu Sep 17 15:12:43.005156 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:36118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXy-cL08BTTQixEnpCQgAAAFo"]
[Thu Sep 17 15:12:43.106921 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "aqxXy-cL08BTTQixEnpCQwAAAEA"]
[Thu Sep 17 15:12:43.123875 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyucL08BTTQixEnpCPAAAAFg"]
[Thu Sep 17 15:12:43.318025 2026] [authz_core:error] [pid 971102:tid 971345] [client 20.244.34.24:50174] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:43.341309 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "aqxXy-cL08BTTQixEnpCSwAAAB8"]
[Thu Sep 17 15:12:43.374483 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCRgAAAEI"]
[Thu Sep 17 15:12:43.374507 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCRgAAAEI"]
[Thu Sep 17 15:12:43.482537 2026] [security2:error] [pid 971102:tid 971351] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCSQAAAHU"]
[Thu Sep 17 15:12:43.513363 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.194.17:38212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/i.php"] [unique_id "aqxXy-cL08BTTQixEnpCUAAAAGw"]
[Thu Sep 17 15:12:43.521592 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxXy-cL08BTTQixEnpCUQAAAA8"]
[Thu Sep 17 15:12:43.521722 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:36118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxXy-cL08BTTQixEnpCUQAAAA8"]
[Thu Sep 17 15:12:43.578019 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/v3/.env"] [unique_id "aqxXy-cL08BTTQixEnpCUwAAADI"]
[Thu Sep 17 15:12:43.670084 2026] [authz_core:error] [pid 971102:tid 971242] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:12:43.704140 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXy-cL08BTTQixEnpCWwAAAFU"]
[Thu Sep 17 15:12:43.704476 2026] [security2:error] [pid 971102:tid 971302] [client 156.192.234.52:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXy-cL08BTTQixEnpCWgAAAEQ"]
[Thu Sep 17 15:12:43.704619 2026] [security2:error] [pid 971102:tid 971302] [client 156.192.234.52:50856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXy-cL08BTTQixEnpCWgAAAEQ"]
[Thu Sep 17 15:12:43.813782 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:36132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxXy-cL08BTTQixEnpCXwAAAE0"]
[Thu Sep 17 15:12:43.813808 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/v1/.env"] [unique_id "aqxXy-cL08BTTQixEnpCXgAAAGM"]
[Thu Sep 17 15:12:43.813876 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:36132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxXy-cL08BTTQixEnpCXwAAAE0"]
[Thu Sep 17 15:12:43.830323 2026] [security2:error] [pid 971102:tid 971259] [client 40.77.167.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wheresmymap.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCEwAAABk"]
[Thu Sep 17 15:12:43.874961 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCVwAAAF0"]
[Thu Sep 17 15:12:44.055893 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/v2/.env"] [unique_id "aqxXzOcL08BTTQixEnpCZQAAAAA"]
[Thu Sep 17 15:12:44.103278 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxXzOcL08BTTQixEnpCZgAAAH0"]
[Thu Sep 17 15:12:44.103391 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:36140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxXzOcL08BTTQixEnpCZgAAAH0"]
[Thu Sep 17 15:12:44.209796 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/pi.php"] [unique_id "aqxXzOcL08BTTQixEnpCbAAAAEM"]
[Thu Sep 17 15:12:44.265626 2026] [security2:error] [pid 971102:tid 971268] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpCZAAAACI"]
[Thu Sep 17 15:12:44.288776 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/rest/.env"] [unique_id "aqxXzOcL08BTTQixEnpCcAAAAFs"]
[Thu Sep 17 15:12:44.362252 2026] [security2:error] [pid 971102:tid 971361] [client 115.244.164.14:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCdQAAAH8"]
[Thu Sep 17 15:12:44.362421 2026] [security2:error] [pid 971102:tid 971361] [client 115.244.164.14:55416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCdQAAAH8"]
[Thu Sep 17 15:12:44.385818 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxXzOcL08BTTQixEnpCdgAAAG4"]
[Thu Sep 17 15:12:44.432292 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:55570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCeQAAAAk"]
[Thu Sep 17 15:12:44.433882 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:55570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCeQAAAAk"]
[Thu Sep 17 15:12:44.521222 2026] [security2:error] [pid 971102:tid 971289] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/graphql/.env"] [unique_id "aqxXzOcL08BTTQixEnpCfQAAADc"]
[Thu Sep 17 15:12:44.545415 2026] [authz_core:error] [pid 971102:tid 971290] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Curve25519/error_log
[Thu Sep 17 15:12:44.554962 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxXzOcL08BTTQixEnpCfgAAADg"]
[Thu Sep 17 15:12:44.641960 2026] [security2:error] [pid 971102:tid 971295] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpCdwAAAD0"]
[Thu Sep 17 15:12:44.693344 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.117.146:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXzOcL08BTTQixEnpCgAAAAHg"]
[Thu Sep 17 15:12:44.695494 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXzOcL08BTTQixEnpCgQAAAF8"]
[Thu Sep 17 15:12:44.754986 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/gateway/.env"] [unique_id "aqxXzOcL08BTTQixEnpCggAAAFo"]
[Thu Sep 17 15:12:44.768260 2026] [fcgid:warn] [pid 971102:tid 971261] (70014)End of file found: [client 66.132.224.237:29952] mod_fcgid: can't get data from http client
[Thu Sep 17 15:12:44.908545 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.194.17:38222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/pinfo.php"] [unique_id "aqxXzOcL08BTTQixEnpChgAAAHA"]
[Thu Sep 17 15:12:44.986524 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/microservice/.env"] [unique_id "aqxXzOcL08BTTQixEnpCigAAABA"]
[Thu Sep 17 15:12:45.056416 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpChQAAAFg"]
[Thu Sep 17 15:12:45.056438 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpChQAAAFg"]
[Thu Sep 17 15:12:45.083422 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpChAAAAEA"]
[Thu Sep 17 15:12:45.193948 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxXzecL08BTTQixEnpCjgAAAHU"]
[Thu Sep 17 15:12:45.194101 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxXzecL08BTTQixEnpCjgAAAHU"]
[Thu Sep 17 15:12:45.216916 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/service/.env"] [unique_id "aqxXzecL08BTTQixEnpCjwAAAGw"]
[Thu Sep 17 15:12:45.448676 2026] [security2:error] [pid 971102:tid 971314] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/v3/.env"] [unique_id "aqxXzecL08BTTQixEnpClQAAAFA"]
[Thu Sep 17 15:12:45.455420 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCkAAAADI"]
[Thu Sep 17 15:12:45.478739 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:36152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxXzecL08BTTQixEnpClgAAABE"]
[Thu Sep 17 15:12:45.604433 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.194.17:38236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/test.php"] [unique_id "aqxXzecL08BTTQixEnpClwAAAHY"]
[Thu Sep 17 15:12:45.639005 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxXzecL08BTTQixEnpCmgAAABw"]
[Thu Sep 17 15:12:45.680321 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/dev/.env"] [unique_id "aqxXzecL08BTTQixEnpCngAAAHM"]
[Thu Sep 17 15:12:45.781852 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:36152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxXzecL08BTTQixEnpCnwAAABU"]
[Thu Sep 17 15:12:45.819037 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCmAAAAAc"]
[Thu Sep 17 15:12:45.855038 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.117.146:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXzecL08BTTQixEnpCoQAAAAs"]
[Thu Sep 17 15:12:45.912677 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/staging/.env"] [unique_id "aqxXzecL08BTTQixEnpCowAAAF0"]
[Thu Sep 17 15:12:46.143536 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "aqxXzucL08BTTQixEnpCrAAAADA"]
[Thu Sep 17 15:12:46.194917 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCpAAAACs"]
[Thu Sep 17 15:12:46.194943 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCpAAAACs"]
[Thu Sep 17 15:12:46.376373 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/lib/.env"] [unique_id "aqxXzucL08BTTQixEnpCtAAAACU"]
[Thu Sep 17 15:12:46.429832 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:36152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxXzucL08BTTQixEnpCtQAAADM"]
[Thu Sep 17 15:12:46.430006 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:36152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxXzucL08BTTQixEnpCtQAAADM"]
[Thu Sep 17 15:12:46.580513 2026] [autoindex:error] [pid 971102:tid 971156] [remote 93.152.209.11:24946] AH01276: Cannot serve directory /home1/ggwqjxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:12:46.612989 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/resources/.env"] [unique_id "aqxXzucL08BTTQixEnpCuwAAACg"]
[Thu Sep 17 15:12:46.717165 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:36166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxXzucL08BTTQixEnpCvQAAADg"]
[Thu Sep 17 15:12:46.717290 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:36166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxXzucL08BTTQixEnpCvQAAADg"]
[Thu Sep 17 15:12:46.780666 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.194.17:38248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/p.php"] [unique_id "aqxXzucL08BTTQixEnpCvwAAAAU"]
[Thu Sep 17 15:12:46.840054 2026] [security2:error] [pid 971102:tid 971289] [client 34.32.117.146:38416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXzucL08BTTQixEnpCwAAAADc"]
[Thu Sep 17 15:12:46.844172 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/assets/.env"] [unique_id "aqxXzucL08BTTQixEnpCwQAAAFw"]
[Thu Sep 17 15:12:47.000345 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxXzucL08BTTQixEnpCxQAAABc"]
[Thu Sep 17 15:12:47.000456 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxXzucL08BTTQixEnpCxQAAABc"]
[Thu Sep 17 15:12:47.073111 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/uploads/.env"] [unique_id "aqxXz-cL08BTTQixEnpCxwAAAEA"]
[Thu Sep 17 15:12:47.278655 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxXz-cL08BTTQixEnpCzgAAACM"]
[Thu Sep 17 15:12:47.278777 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxXz-cL08BTTQixEnpCzgAAACM"]
[Thu Sep 17 15:12:47.304965 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "aqxXz-cL08BTTQixEnpC0AAAAFY"]
[Thu Sep 17 15:12:47.460709 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.194.17:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/debug.php"] [unique_id "aqxXz-cL08BTTQixEnpC1QAAAA8"]
[Thu Sep 17 15:12:47.525772 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.117.146:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXz-cL08BTTQixEnpC2AAAADQ"]
[Thu Sep 17 15:12:47.542171 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/tools/.env"] [unique_id "aqxXz-cL08BTTQixEnpC3gAAAAg"]
[Thu Sep 17 15:12:47.773458 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:36194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxXz-cL08BTTQixEnpC7AAAAAc"]
[Thu Sep 17 15:12:47.773567 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:36194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxXz-cL08BTTQixEnpC7AAAAAc"]
[Thu Sep 17 15:12:47.775314 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/scripts/.env"] [unique_id "aqxXz-cL08BTTQixEnpC7QAAAFc"]
[Thu Sep 17 15:12:47.794838 2026] [security2:error] [pid 971102:tid 971248] [client 5.189.145.112:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxXz-cL08BTTQixEnpC7gAAAA4"], referer: binance.com
[Thu Sep 17 15:12:48.008608 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/bin/.env"] [unique_id "aqxX0OcL08BTTQixEnpC9gAAAG0"]
[Thu Sep 17 15:12:48.014751 2026] [security2:error] [pid 971102:tid 971316] [client 4.240.114.86:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX0OcL08BTTQixEnpC-AAAAFI"], referer: binance.com
[Thu Sep 17 15:12:48.079699 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxX0OcL08BTTQixEnpC_AAAADY"]
[Thu Sep 17 15:12:48.079830 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:36198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxX0OcL08BTTQixEnpC_AAAADY"]
[Thu Sep 17 15:12:48.175415 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.194.17:41720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxX0OcL08BTTQixEnpDAAAAABg"]
[Thu Sep 17 15:12:48.246622 2026] [security2:error] [pid 971102:tid 971281] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sbin/.env"] [unique_id "aqxX0OcL08BTTQixEnpDAgAAAC8"]
[Thu Sep 17 15:12:48.321775 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxX0OcL08BTTQixEnpDAwAAADA"]
[Thu Sep 17 15:12:48.368839 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxX0OcL08BTTQixEnpDCAAAAEc"]
[Thu Sep 17 15:12:48.368951 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:36200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxX0OcL08BTTQixEnpDCAAAAEc"]
[Thu Sep 17 15:12:48.390083 2026] [security2:error] [pid 971102:tid 971291] [client 208.109.3.10:20164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxX0OcL08BTTQixEnpC9wAAADk"]
[Thu Sep 17 15:12:48.480040 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "aqxX0OcL08BTTQixEnpDDAAAAGI"]
[Thu Sep 17 15:12:48.526264 2026] [security2:error] [pid 971102:tid 971317] [client 40.77.167.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wheresmymap.com"] [uri "/index.php"] [unique_id "aqxX0OcL08BTTQixEnpDCQAAAFM"]
[Thu Sep 17 15:12:48.658173 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:36202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxX0OcL08BTTQixEnpDGwAAAGU"]
[Thu Sep 17 15:12:48.658273 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:36202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxX0OcL08BTTQixEnpDGwAAAGU"]
[Thu Sep 17 15:12:48.696715 2026] [security2:error] [pid 971102:tid 971243] [client 114.198.138.124:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0OcL08BTTQixEnpDHAAAAAk"]
[Thu Sep 17 15:12:48.696809 2026] [security2:error] [pid 971102:tid 971243] [client 114.198.138.124:56717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0OcL08BTTQixEnpDHAAAAAk"]
[Thu Sep 17 15:12:48.713560 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "aqxX0OcL08BTTQixEnpDHQAAAD0"]
[Thu Sep 17 15:12:48.864954 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.194.17:41736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/test/phpinfo.php"] [unique_id "aqxX0OcL08BTTQixEnpDIQAAAAU"]
[Thu Sep 17 15:12:48.950221 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/dashboard/.env"] [unique_id "aqxX0OcL08BTTQixEnpDJAAAAF4"]
[Thu Sep 17 15:12:48.970406 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:36204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxX0OcL08BTTQixEnpDJwAAABs"]
[Thu Sep 17 15:12:48.970505 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:36204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxX0OcL08BTTQixEnpDJwAAABs"]
[Thu Sep 17 15:12:49.070548 2026] [access_compat:error] [pid 971102:tid 971309] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/category
[Thu Sep 17 15:12:49.184057 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/panel/.env"] [unique_id "aqxX0ecL08BTTQixEnpDMQAAAHY"]
[Thu Sep 17 15:12:49.256253 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:36210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxX0ecL08BTTQixEnpDMwAAACk"]
[Thu Sep 17 15:12:49.256361 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:36210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxX0ecL08BTTQixEnpDMwAAACk"]
[Thu Sep 17 15:12:49.349849 2026] [security2:error] [pid 971102:tid 971280] [client 104.28.198.244:22819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDNwAAAC4"]
[Thu Sep 17 15:12:49.349995 2026] [security2:error] [pid 971102:tid 971280] [client 104.28.198.244:22819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDNwAAAC4"]
[Thu Sep 17 15:12:49.365081 2026] [security2:error] [pid 971102:tid 971340] [client 154.190.208.131:42012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDOAAAAGo"]
[Thu Sep 17 15:12:49.365235 2026] [security2:error] [pid 971102:tid 971340] [client 154.190.208.131:42012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDOAAAAGo"]
[Thu Sep 17 15:12:49.416641 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "aqxX0ecL08BTTQixEnpDOwAAAAs"]
[Thu Sep 17 15:12:49.563285 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.194.17:41744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxX0ecL08BTTQixEnpDQgAAAAY"]
[Thu Sep 17 15:12:49.567445 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxX0ecL08BTTQixEnpDQwAAADw"]
[Thu Sep 17 15:12:49.567532 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:36216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxX0ecL08BTTQixEnpDQwAAADw"]
[Thu Sep 17 15:12:49.646423 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/erp/.env"] [unique_id "aqxX0ecL08BTTQixEnpDRQAAAEo"]
[Thu Sep 17 15:12:49.723805 2026] [security2:error] [pid 971102:tid 971303] [client 186.105.232.15:56005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDSwAAAEU"]
[Thu Sep 17 15:12:49.723928 2026] [security2:error] [pid 971102:tid 971303] [client 186.105.232.15:56005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDSwAAAEU"]
[Thu Sep 17 15:12:49.867511 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:60350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxX0ecL08BTTQixEnpDTwAAAF0"]
[Thu Sep 17 15:12:49.867632 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:60350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxX0ecL08BTTQixEnpDTwAAAF0"]
[Thu Sep 17 15:12:49.878097 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/shop/.env"] [unique_id "aqxX0ecL08BTTQixEnpDUAAAACU"]
[Thu Sep 17 15:12:50.113319 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/store/.env"] [unique_id "aqxX0ucL08BTTQixEnpDVgAAAFM"]
[Thu Sep 17 15:12:50.164943 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:60354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxX0ucL08BTTQixEnpDWgAAACQ"]
[Thu Sep 17 15:12:50.259383 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.194.17:41756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/old/phpinfo.php"] [unique_id "aqxX0ucL08BTTQixEnpDXAAAAHw"]
[Thu Sep 17 15:12:50.323598 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.117.146:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxX0ecL08BTTQixEnpDNAAAAAg"]
[Thu Sep 17 15:12:50.350817 2026] [authz_core:error] [pid 971102:tid 971278] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Poly1305/error_log
[Thu Sep 17 15:12:50.352773 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxX0ucL08BTTQixEnpDXgAAACw"]
[Thu Sep 17 15:12:50.494535 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:60354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxX0ucL08BTTQixEnpDYgAAAFw"]
[Thu Sep 17 15:12:50.808226 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/saas/.env"] [unique_id "aqxX0ucL08BTTQixEnpDbwAAABo"]
[Thu Sep 17 15:12:50.838563 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX0ucL08BTTQixEnpDZQAAAF8"]
[Thu Sep 17 15:12:50.838588 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX0ucL08BTTQixEnpDZQAAAF8"]
[Thu Sep 17 15:12:50.942993 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:41770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxX0ucL08BTTQixEnpDdAAAAEA"]
[Thu Sep 17 15:12:50.986637 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxX0ucL08BTTQixEnpDeAAAAHU"]
[Thu Sep 17 15:12:50.986762 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxX0ucL08BTTQixEnpDeAAAAHU"]
[Thu Sep 17 15:12:51.015484 2026] [security2:error] [pid 971102:tid 971309] [client 45.169.98.18:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0-cL08BTTQixEnpDewAAAEs"]
[Thu Sep 17 15:12:51.015608 2026] [security2:error] [pid 971102:tid 971309] [client 45.169.98.18:60212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0-cL08BTTQixEnpDewAAAEs"]
[Thu Sep 17 15:12:51.039240 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/client/.env"] [unique_id "aqxX0-cL08BTTQixEnpDfAAAAC4"]
[Thu Sep 17 15:12:51.047973 2026] [security2:error] [pid 971102:tid 971320] [client 34.32.117.146:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/core/phpinfo.php"] [unique_id "aqxX0-cL08BTTQixEnpDfQAAAFY"]
[Thu Sep 17 15:12:51.193752 2026] [security2:error] [pid 971102:tid 971343] [client 157.230.170.38:58733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "iradtech.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX0-cL08BTTQixEnpDhAAAAG0"]
[Thu Sep 17 15:12:51.236711 2026] [security2:error] [pid 971102:tid 971288] [client 157.230.170.38:58735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "iradtech.com"] [uri "/"] [unique_id "aqxX0-cL08BTTQixEnpDhQAAADY"]
[Thu Sep 17 15:12:51.263574 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxX0-cL08BTTQixEnpDhwAAABM"]
[Thu Sep 17 15:12:51.263690 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:60370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxX0-cL08BTTQixEnpDhwAAABM"]
[Thu Sep 17 15:12:51.270278 2026] [security2:error] [pid 971102:tid 971235] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "aqxX0-cL08BTTQixEnpDiAAAAAE"]
[Thu Sep 17 15:12:51.288632 2026] [security2:error] [pid 971102:tid 971308] [client 157.230.170.38:58739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "iradtech.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX0-cL08BTTQixEnpDigAAAEo"]
[Thu Sep 17 15:12:51.500246 2026] [security2:error] [pid 971102:tid 971248] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/admin-panel/.env"] [unique_id "aqxX0-cL08BTTQixEnpDkAAAAA4"]
[Thu Sep 17 15:12:51.643363 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:41772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/public/phpinfo.php"] [unique_id "aqxX0-cL08BTTQixEnpDlAAAAH0"]
[Thu Sep 17 15:12:51.669125 2026] [security2:error] [pid 971102:tid 971302] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX0-cL08BTTQixEnpDiwAARG0"], referer: http://www.makingreligionhealthy.com/old/
[Thu Sep 17 15:12:51.676305 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:60378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxX0-cL08BTTQixEnpDmQAAAH8"]
[Thu Sep 17 15:12:51.731410 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/control-panel/.env"] [unique_id "aqxX0-cL08BTTQixEnpDnAAAAGg"]
[Thu Sep 17 15:12:51.833620 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxX0-cL08BTTQixEnpDngAAAFM"]
[Thu Sep 17 15:12:51.885705 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.117.146:59720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxX0-cL08BTTQixEnpDoQAAAE0"]
[Thu Sep 17 15:12:51.964679 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/user-panel/.env"] [unique_id "aqxX0-cL08BTTQixEnpDpQAAABg"]
[Thu Sep 17 15:12:51.973978 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:60378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxX0-cL08BTTQixEnpDpwAAAAI"]
[Thu Sep 17 15:12:52.194824 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/node/.env"] [unique_id "aqxX1OcL08BTTQixEnpDrQAAAD8"]
[Thu Sep 17 15:12:52.337300 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDqQAAACQ"]
[Thu Sep 17 15:12:52.337330 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDqQAAACQ"]
[Thu Sep 17 15:12:52.429176 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/express/.env"] [unique_id "aqxX1OcL08BTTQixEnpDuQAAAEA"]
[Thu Sep 17 15:12:52.432349 2026] [security2:error] [pid 971102:tid 971356] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDqgAAemU"], referer: https://www.makingreligionhealthy.com/old/
[Thu Sep 17 15:12:52.488779 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxX1OcL08BTTQixEnpDvQAAAFU"]
[Thu Sep 17 15:12:52.488878 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxX1OcL08BTTQixEnpDvQAAAFU"]
[Thu Sep 17 15:12:52.642100 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.194.17:41780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/php-info.php"] [unique_id "aqxX1OcL08BTTQixEnpDwwAAAEs"]
[Thu Sep 17 15:12:52.659598 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/next/.env"] [unique_id "aqxX1OcL08BTTQixEnpDxQAAAFY"]
[Thu Sep 17 15:12:52.775255 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxX1OcL08BTTQixEnpDzwAAAAs"]
[Thu Sep 17 15:12:52.775381 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:60390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxX1OcL08BTTQixEnpDzwAAAAs"]
[Thu Sep 17 15:12:52.888980 2026] [security2:error] [pid 971102:tid 971288] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/nuxt/.env"] [unique_id "aqxX1OcL08BTTQixEnpD0wAAADY"]
[Thu Sep 17 15:12:53.063478 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxX1ecL08BTTQixEnpD1wAAAAQ"]
[Thu Sep 17 15:12:53.063597 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxX1ecL08BTTQixEnpD1wAAAAQ"]
[Thu Sep 17 15:12:53.083291 2026] [security2:error] [pid 971102:tid 971257] [client 57.141.14.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reddomconstruction.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDzQAAABc"]
[Thu Sep 17 15:12:53.125995 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/nest/.env"] [unique_id "aqxX1ecL08BTTQixEnpD2wAAACE"]
[Thu Sep 17 15:12:53.360690 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.194.17:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpversion.php"] [unique_id "aqxX1ecL08BTTQixEnpD5gAAAF0"]
[Thu Sep 17 15:12:53.365346 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/react/.env"] [unique_id "aqxX1ecL08BTTQixEnpD5wAAAGg"]
[Thu Sep 17 15:12:53.371629 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxX1ecL08BTTQixEnpD6AAAAFM"]
[Thu Sep 17 15:12:53.371802 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxX1ecL08BTTQixEnpD6AAAAFM"]
[Thu Sep 17 15:12:53.430084 2026] [security2:error] [pid 971102:tid 971332] [client 162.241.226.11:57976] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxX1ecL08BTTQixEnpD6QAAAGI"]
[Thu Sep 17 15:12:53.599260 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/vue/.env"] [unique_id "aqxX1ecL08BTTQixEnpD8AAAADA"]
[Thu Sep 17 15:12:53.663996 2026] [security2:error] [pid 971102:tid 971244] [client 143.244.57.120:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxX1ecL08BTTQixEnpD8gAAAAo"]
[Thu Sep 17 15:12:53.664122 2026] [security2:error] [pid 971102:tid 971244] [client 143.244.57.120:60420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxX1ecL08BTTQixEnpD8gAAAAo"]
[Thu Sep 17 15:12:53.831168 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/angular/.env"] [unique_id "aqxX1ecL08BTTQixEnpD9AAAADI"]
[Thu Sep 17 15:12:53.941552 2026] [security2:error] [pid 971102:tid 971242] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1ecL08BTTQixEnpD8wAACGE"], referer: http://www.makingreligionhealthy.com/wordpress/
[Thu Sep 17 15:12:53.978786 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxX1ecL08BTTQixEnpD_QAAAGY"]
[Thu Sep 17 15:12:53.978894 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:60436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxX1ecL08BTTQixEnpD_QAAAGY"]
[Thu Sep 17 15:12:54.042621 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/_phpinfo.php"] [unique_id "aqxX1ucL08BTTQixEnpD_wAAAD8"]
[Thu Sep 17 15:12:54.061433 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/svelte/.env"] [unique_id "aqxX1ucL08BTTQixEnpEAAAAAHo"]
[Thu Sep 17 15:12:54.259873 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxX1ucL08BTTQixEnpEDAAAAFk"]
[Thu Sep 17 15:12:54.259965 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxX1ucL08BTTQixEnpEDAAAAFk"]
[Thu Sep 17 15:12:54.296561 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/vite/.env"] [unique_id "aqxX1ucL08BTTQixEnpEDgAAAHY"]
[Thu Sep 17 15:12:54.314774 2026] [security2:error] [pid 971102:tid 971353] [client 156.192.234.52:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEDwAAAHc"]
[Thu Sep 17 15:12:54.316957 2026] [security2:error] [pid 971102:tid 971353] [client 156.192.234.52:51466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEDwAAAHc"]
[Thu Sep 17 15:12:54.381972 2026] [security2:error] [pid 971102:tid 971351] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1ucL08BTTQixEnpEAgAAdW8"], referer: https://www.makingreligionhealthy.com/wordpress/
[Thu Sep 17 15:12:54.408197 2026] [security2:error] [pid 971102:tid 971239] [client 43.173.178.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxX1ucL08BTTQixEnpECgAAAAU"]
[Thu Sep 17 15:12:54.533892 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "aqxX1ucL08BTTQixEnpEGAAAACY"]
[Thu Sep 17 15:12:54.540175 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxX1ucL08BTTQixEnpEGQAAAFc"]
[Thu Sep 17 15:12:54.540302 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxX1ucL08BTTQixEnpEGQAAAFc"]
[Thu Sep 17 15:12:54.695580 2026] [security2:error] [pid 971102:tid 971251] [client 205.169.39.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ulm.iln.mybluehost.me"] [uri "/~jminnerp/index.php"] [unique_id "aqxX0ucL08BTTQixEnpDcwAAABE"], referer: https://ulm.iln.mybluehost.me/website_8c974a43/
[Thu Sep 17 15:12:54.743362 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.194.17:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/old_phpinfo.php"] [unique_id "aqxX1ucL08BTTQixEnpEIwAAAEo"]
[Thu Sep 17 15:12:54.772442 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/backups/.env"] [unique_id "aqxX1ucL08BTTQixEnpEJQAAAGM"]
[Thu Sep 17 15:12:54.846930 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxX1ucL08BTTQixEnpEJwAAAFM"]
[Thu Sep 17 15:12:54.847069 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxX1ucL08BTTQixEnpEJwAAAFM"]
[Thu Sep 17 15:12:54.923872 2026] [security2:error] [pid 971102:tid 971267] [client 115.244.164.14:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEKgAAACE"]
[Thu Sep 17 15:12:54.923987 2026] [security2:error] [pid 971102:tid 971267] [client 115.244.164.14:56072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEKgAAACE"]
[Thu Sep 17 15:12:54.951746 2026] [security2:error] [pid 971102:tid 971361] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1ucL08BTTQixEnpEIAAAfww"], referer: http://www.makingreligionhealthy.com/backup/
[Thu Sep 17 15:12:55.002844 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "aqxX1-cL08BTTQixEnpEMQAAADA"]
[Thu Sep 17 15:12:55.065485 2026] [security2:error] [pid 971102:tid 971325] [client 185.55.149.49:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX1-cL08BTTQixEnpEMwAAAFs"]
[Thu Sep 17 15:12:55.065613 2026] [security2:error] [pid 971102:tid 971325] [client 185.55.149.49:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX1-cL08BTTQixEnpEMwAAAFs"]
[Thu Sep 17 15:12:55.125589 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxX1-cL08BTTQixEnpENgAAADI"]
[Thu Sep 17 15:12:55.233303 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/tmp/.env"] [unique_id "aqxX1-cL08BTTQixEnpEOwAAADQ"]
[Thu Sep 17 15:12:55.282438 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxX1-cL08BTTQixEnpEQAAAAEA"]
[Thu Sep 17 15:12:55.332639 2026] [security2:error] [pid 971102:tid 971299] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpENAAAQQU"], referer: https://www.makingreligionhealthy.com/backup/
[Thu Sep 17 15:12:55.425049 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/wp-includes/sodium_compat/src/"] [unique_id "aqxX1-cL08BTTQixEnpERQAAAE4"]
[Thu Sep 17 15:12:55.435925 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.194.17:41818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/server-info.php"] [unique_id "aqxX1-cL08BTTQixEnpERgAAAHQ"]
[Thu Sep 17 15:12:55.464518 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/temp/.env"] [unique_id "aqxX1-cL08BTTQixEnpESgAAAFk"]
[Thu Sep 17 15:12:55.479894 2026] [security2:error] [pid 971102:tid 971293] [client 43.165.198.224:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.198.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showtimeeventsvb.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxX1-cL08BTTQixEnpERwAAADs"]
[Thu Sep 17 15:12:55.697372 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/lab/.env"] [unique_id "aqxX1-cL08BTTQixEnpEWQAAAHM"]
[Thu Sep 17 15:12:55.836430 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpEUgAAAAw"]
[Thu Sep 17 15:12:55.836455 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpEUgAAAAw"]
[Thu Sep 17 15:12:55.913516 2026] [security2:error] [pid 971102:tid 971250] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpEVAAAEAg"], referer: http://www.makingreligionhealthy.com/blog/
[Thu Sep 17 15:12:55.927389 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cronlab/.env"] [unique_id "aqxX1-cL08BTTQixEnpEXgAAABU"]
[Thu Sep 17 15:12:55.974096 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxX1-cL08BTTQixEnpEYwAAABk"]
[Thu Sep 17 15:12:55.974208 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxX1-cL08BTTQixEnpEYwAAABk"]
[Thu Sep 17 15:12:56.117978 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/server-status.php"] [unique_id "aqxX2OcL08BTTQixEnpEZwAAAEM"]
[Thu Sep 17 15:12:56.165804 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "aqxX2OcL08BTTQixEnpEaAAAAGk"]
[Thu Sep 17 15:12:56.257834 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxX2OcL08BTTQixEnpEagAAAFU"]
[Thu Sep 17 15:12:56.257933 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxX2OcL08BTTQixEnpEagAAAFU"]
[Thu Sep 17 15:12:56.400777 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/en/.env"] [unique_id "aqxX2OcL08BTTQixEnpEcAAAAGg"]
[Thu Sep 17 15:12:56.541148 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:60478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxX2OcL08BTTQixEnpEdgAAAAI"]
[Thu Sep 17 15:12:56.619905 2026] [security2:error] [pid 971102:tid 971325] [client 5.189.145.112:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxX2OcL08BTTQixEnpEeQAAAFs"], referer: binance.com
[Thu Sep 17 15:12:56.690431 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/administrator/.env"] [unique_id "aqxX2OcL08BTTQixEnpEegAAABQ"]
[Thu Sep 17 15:12:56.736500 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxX2OcL08BTTQixEnpEfQAAACg"]
[Thu Sep 17 15:12:56.854850 2026] [security2:error] [pid 971102:tid 971244] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2OcL08BTTQixEnpEeAAACiY"], referer: http://www.makingreligionhealthy.com/wp/
[Thu Sep 17 15:12:56.874643 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxX2OcL08BTTQixEnpEgwAAADQ"]
[Thu Sep 17 15:12:56.874779 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:60478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxX2OcL08BTTQixEnpEgwAAADQ"]
[Thu Sep 17 15:12:56.920925 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/psnlink/.env"] [unique_id "aqxX2OcL08BTTQixEnpEhQAAAE8"]
[Thu Sep 17 15:12:57.014561 2026] [security2:error] [pid 971102:tid 971350] [client 43.156.79.172:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.79.156.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxX2OcL08BTTQixEnpEiQAAAHQ"]
[Thu Sep 17 15:12:57.155396 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxX2ecL08BTTQixEnpEjwAAAF8"]
[Thu Sep 17 15:12:57.155489 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxX2ecL08BTTQixEnpEjwAAAF8"]
[Thu Sep 17 15:12:57.155759 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/exapi/.env"] [unique_id "aqxX2ecL08BTTQixEnpEjgAAADs"]
[Thu Sep 17 15:12:57.228184 2026] [security2:error] [pid 971102:tid 971312] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2OcL08BTTQixEnpEiAAATjY"], referer: https://www.makingreligionhealthy.com/wp/
[Thu Sep 17 15:12:57.385616 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sitemaps/.env"] [unique_id "aqxX2ecL08BTTQixEnpElwAAAG8"]
[Thu Sep 17 15:12:57.423803 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.194.17:41836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxX2ecL08BTTQixEnpEmQAAACQ"]
[Thu Sep 17 15:12:57.445062 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:60494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxX2ecL08BTTQixEnpEmwAAAAY"]
[Thu Sep 17 15:12:57.445163 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:60494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxX2ecL08BTTQixEnpEmwAAAAY"]
[Thu Sep 17 15:12:57.671932 2026] [security2:error] [pid 971102:tid 971223] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxX2ecL08BTTQixEnpEowAALHY"]
[Thu Sep 17 15:12:57.683616 2026] [core:error] [pid 971102:tid 971265] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:57.683632 2026] [core:error] [pid 971102:tid 971265] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:57.726342 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxX2ecL08BTTQixEnpEpQAAACs"]
[Thu Sep 17 15:12:57.726463 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxX2ecL08BTTQixEnpEpQAAACs"]
[Thu Sep 17 15:12:57.738963 2026] [security2:error] [pid 971102:tid 971351] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2ecL08BTTQixEnpEngAAdSg"], referer: http://www.makingreligionhealthy.com/new/
[Thu Sep 17 15:12:57.950116 2026] [security2:error] [pid 971102:tid 971259] [client 104.28.198.244:22605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2ecL08BTTQixEnpEqQAAABk"]
[Thu Sep 17 15:12:58.025620 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxX2ucL08BTTQixEnpErgAAAHk"]
[Thu Sep 17 15:12:58.025768 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:60512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxX2ucL08BTTQixEnpErgAAAHk"]
[Thu Sep 17 15:12:58.104247 2026] [security2:error] [pid 971102:tid 971271] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2ecL08BTTQixEnpEqAAAJS0"], referer: https://www.makingreligionhealthy.com/new/
[Thu Sep 17 15:12:58.105374 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.194.17:45248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxX2ucL08BTTQixEnpEsAAAAG0"]
[Thu Sep 17 15:12:58.139883 2026] [security2:error] [pid 971102:tid 971259] [client 104.28.198.244:22605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2ecL08BTTQixEnpEqQAAABk"]
[Thu Sep 17 15:12:58.311429 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:60516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxX2ucL08BTTQixEnpEuwAAADE"]
[Thu Sep 17 15:12:58.428291 2026] [core:error] [pid 971102:tid 971334] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:58.428312 2026] [core:error] [pid 971102:tid 971334] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:58.470606 2026] [authz_core:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/theme-compat/error_log
[Thu Sep 17 15:12:58.475861 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxX2ucL08BTTQixEnpEwwAAAEA"]
[Thu Sep 17 15:12:58.649965 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxX2ucL08BTTQixEnpEzQAAAFk"]
[Thu Sep 17 15:12:58.791224 2026] [security2:error] [pid 971102:tid 971293] [client 52.167.144.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wheresmymap.com"] [uri "/index.php"] [unique_id "aqxX2ucL08BTTQixEnpEywAAADs"]
[Thu Sep 17 15:12:58.801894 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxX2ucL08BTTQixEnpE1AAAAEU"]
[Thu Sep 17 15:12:58.806729 2026] [authz_core:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/widgets/error_log
[Thu Sep 17 15:12:58.811331 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxX2ucL08BTTQixEnpE0wAAAG8"]
[Thu Sep 17 15:12:58.954159 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX2ucL08BTTQixEnpE2AAAACk"]
[Thu Sep 17 15:12:58.954272 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:60516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX2ucL08BTTQixEnpE2AAAACk"]
[Thu Sep 17 15:12:58.985054 2026] [authz_core:error] [pid 971102:tid 971330] [client 20.244.34.24:63142] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:59.124212 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/logs/.env"] [unique_id "aqxX2-cL08BTTQixEnpE4AAAAAY"]
[Thu Sep 17 15:12:59.264319 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX2-cL08BTTQixEnpE5wAAAAk"]
[Thu Sep 17 15:12:59.291654 2026] [security2:error] [pid 971102:tid 971246] [client 114.198.138.124:57341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE6QAAAAw"]
[Thu Sep 17 15:12:59.291776 2026] [security2:error] [pid 971102:tid 971246] [client 114.198.138.124:57341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE6QAAAAw"]
[Thu Sep 17 15:12:59.354908 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cache/.env"] [unique_id "aqxX2-cL08BTTQixEnpE6gAAABM"]
[Thu Sep 17 15:12:59.491624 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX2-cL08BTTQixEnpE7QAAAAQ"]
[Thu Sep 17 15:12:59.495287 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:45268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxX2-cL08BTTQixEnpE8gAAAEM"]
[Thu Sep 17 15:12:59.584159 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "aqxX2-cL08BTTQixEnpE9QAAAFs"]
[Thu Sep 17 15:12:59.586475 2026] [security2:error] [pid 971102:tid 971291] [client 43.166.245.120:48260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.245.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "groverpdx.net"] [uri "/wp-login.php"] [unique_id "aqxX2-cL08BTTQixEnpE8wAAADk"], referer: https://groverpdx.net/
[Thu Sep 17 15:12:59.631183 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxX2-cL08BTTQixEnpE9gAAAG4"]
[Thu Sep 17 15:12:59.677723 2026] [security2:error] [pid 971102:tid 971140] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxX2-cL08BTTQixEnpE9wAALiQ"]
[Thu Sep 17 15:12:59.815306 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "aqxX2-cL08BTTQixEnpE-wAAAHg"]
[Thu Sep 17 15:12:59.856746 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE_AAAAGg"]
[Thu Sep 17 15:12:59.856849 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE_AAAAGg"]
[Thu Sep 17 15:13:00.043436 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/email/.env"] [unique_id "aqxX3OcL08BTTQixEnpFAQAAACg"]
[Thu Sep 17 15:13:00.043733 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxX2-cL08BTTQixEnpE-QAAAEo"]
[Thu Sep 17 15:13:00.175166 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:45278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxX3OcL08BTTQixEnpFAgAAAGY"]
[Thu Sep 17 15:13:00.225141 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxX3OcL08BTTQixEnpFBgAAAF8"]
[Thu Sep 17 15:13:00.282583 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/smtp/.env"] [unique_id "aqxX3OcL08BTTQixEnpFBwAAAC0"]
[Thu Sep 17 15:13:00.418706 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxX3OcL08BTTQixEnpFCgAAAFk"]
[Thu Sep 17 15:13:00.516557 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailing/.env"] [unique_id "aqxX3OcL08BTTQixEnpFDwAAAHw"]
[Thu Sep 17 15:13:00.567999 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/wp-admin/css/colors/"] [unique_id "aqxX3OcL08BTTQixEnpFEAAAADM"]
[Thu Sep 17 15:13:00.709056 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3OcL08BTTQixEnpFGAAAAFY"]
[Thu Sep 17 15:13:00.709166 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:56606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3OcL08BTTQixEnpFGAAAAFY"]
[Thu Sep 17 15:13:00.751188 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/notifications/.env"] [unique_id "aqxX3OcL08BTTQixEnpFGgAAAEc"]
[Thu Sep 17 15:13:00.864401 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.194.17:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxX3OcL08BTTQixEnpFHwAAAF0"]
[Thu Sep 17 15:13:00.916568 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3OcL08BTTQixEnpFFwAAABg"]
[Thu Sep 17 15:13:00.916591 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3OcL08BTTQixEnpFFwAAABg"]
[Thu Sep 17 15:13:00.984949 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/notify/.env"] [unique_id "aqxX3OcL08BTTQixEnpFIQAAAAY"]
[Thu Sep 17 15:13:01.089025 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxX3ecL08BTTQixEnpFJQAAACs"]
[Thu Sep 17 15:13:01.216993 2026] [security2:error] [pid 971102:tid 971268] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sender/.env"] [unique_id "aqxX3ecL08BTTQixEnpFLQAAACI"]
[Thu Sep 17 15:13:01.423092 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxX3ecL08BTTQixEnpFMAAAAFU"]
[Thu Sep 17 15:13:01.448460 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/campaign/.env"] [unique_id "aqxX3ecL08BTTQixEnpFMwAAAFI"]
[Thu Sep 17 15:13:01.535149 2026] [security2:error] [pid 971102:tid 971261] [client 45.169.98.18:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3ecL08BTTQixEnpFNwAAABs"]
[Thu Sep 17 15:13:01.535311 2026] [security2:error] [pid 971102:tid 971261] [client 45.169.98.18:60782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3ecL08BTTQixEnpFNwAAABs"]
[Thu Sep 17 15:13:01.554109 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxX3ecL08BTTQixEnpFOAAAABM"]
[Thu Sep 17 15:13:01.564657 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/wp-admin/css/colors/"] [unique_id "aqxX3ecL08BTTQixEnpFOgAAAAQ"]
[Thu Sep 17 15:13:01.680582 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/newsletter/.env"] [unique_id "aqxX3ecL08BTTQixEnpFPAAAADk"]
[Thu Sep 17 15:13:01.919246 2026] [security2:error] [pid 971102:tid 971244] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/ses/.env"] [unique_id "aqxX3ecL08BTTQixEnpFRQAAAAo"]
[Thu Sep 17 15:13:01.922111 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ecL08BTTQixEnpFQAAAADU"]
[Thu Sep 17 15:13:01.922131 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ecL08BTTQixEnpFQAAAADU"]
[Thu Sep 17 15:13:02.069704 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX3ucL08BTTQixEnpFSQAAAHI"]
[Thu Sep 17 15:13:02.154028 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sendgrid/.env"] [unique_id "aqxX3ucL08BTTQixEnpFSwAAAE0"]
[Thu Sep 17 15:13:02.249947 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.194.17:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php.old"] [unique_id "aqxX3ucL08BTTQixEnpFUQAAAEo"]
[Thu Sep 17 15:13:02.271597 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX3ucL08BTTQixEnpFTwAAAEA"]
[Thu Sep 17 15:13:02.391806 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sparkpost/.env"] [unique_id "aqxX3ucL08BTTQixEnpFVQAAAEw"]
[Thu Sep 17 15:13:02.419180 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/wp-admin/css/colors/"] [unique_id "aqxX3ucL08BTTQixEnpFVgAAAD0"]
[Thu Sep 17 15:13:02.600679 2026] [security2:error] [pid 971102:tid 971347] [client 5.189.145.112:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxX3ucL08BTTQixEnpFXAAAAHE"], referer: binance.com
[Thu Sep 17 15:13:02.628780 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/postmark/.env"] [unique_id "aqxX3ucL08BTTQixEnpFXgAAACo"]
[Thu Sep 17 15:13:02.757023 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ucL08BTTQixEnpFWwAAAEU"]
[Thu Sep 17 15:13:02.757054 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ucL08BTTQixEnpFWwAAAEU"]
[Thu Sep 17 15:13:02.862192 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailgun/.env"] [unique_id "aqxX3ucL08BTTQixEnpFYwAAAF4"]
[Thu Sep 17 15:13:02.900838 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxX3ucL08BTTQixEnpFZgAAAGA"]
[Thu Sep 17 15:13:02.949132 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:45328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php~"] [unique_id "aqxX3ucL08BTTQixEnpFZwAAAD8"]
[Thu Sep 17 15:13:03.091779 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxX3-cL08BTTQixEnpFagAAADo"]
[Thu Sep 17 15:13:03.093727 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mandrill/.env"] [unique_id "aqxX3-cL08BTTQixEnpFbAAAAEE"]
[Thu Sep 17 15:13:03.240113 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/wp-admin/css/colors/"] [unique_id "aqxX3-cL08BTTQixEnpFcQAAAGU"]
[Thu Sep 17 15:13:03.336370 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailjet/.env"] [unique_id "aqxX3-cL08BTTQixEnpFcwAAACY"]
[Thu Sep 17 15:13:03.570009 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3-cL08BTTQixEnpFdQAAAHo"]
[Thu Sep 17 15:13:03.570038 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3-cL08BTTQixEnpFdQAAAHo"]
[Thu Sep 17 15:13:03.572472 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/brevo/.env"] [unique_id "aqxX3-cL08BTTQixEnpFegAAAB8"]
[Thu Sep 17 15:13:03.642924 2026] [security2:error] [pid 971102:tid 971268] [client 34.166.194.17:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/info.php.bak"] [unique_id "aqxX3-cL08BTTQixEnpFfAAAACI"]
[Thu Sep 17 15:13:03.715254 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxX3-cL08BTTQixEnpFfQAAAFI"]
[Thu Sep 17 15:13:03.808901 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/transactional/.env"] [unique_id "aqxX3-cL08BTTQixEnpFgQAAAAQ"]
[Thu Sep 17 15:13:03.919349 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxX3-cL08BTTQixEnpFhQAAAGk"]
[Thu Sep 17 15:13:03.963112 2026] [security2:error] [pid 971102:tid 971325] [client 4.240.114.86:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxX3-cL08BTTQixEnpFigAAAFs"], referer: binance.com
[Thu Sep 17 15:13:04.043273 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/bulk/.env"] [unique_id "aqxX4OcL08BTTQixEnpFjAAAABY"]
[Thu Sep 17 15:13:04.062879 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/wp-admin/css/colors/"] [unique_id "aqxX4OcL08BTTQixEnpFjQAAAB4"]
[Thu Sep 17 15:13:04.282029 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/aws/.env"] [unique_id "aqxX4OcL08BTTQixEnpFkgAAAHg"]
[Thu Sep 17 15:13:04.334605 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.194.17:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php.save"] [unique_id "aqxX4OcL08BTTQixEnpFlAAAAEg"]
[Thu Sep 17 15:13:04.429725 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4OcL08BTTQixEnpFkAAAABo"]
[Thu Sep 17 15:13:04.429758 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4OcL08BTTQixEnpFkAAAABo"]
[Thu Sep 17 15:13:04.521769 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/azure/.env"] [unique_id "aqxX4OcL08BTTQixEnpFlwAAAE0"]
[Thu Sep 17 15:13:04.574961 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxX4OcL08BTTQixEnpFngAAADA"]
[Thu Sep 17 15:13:04.756020 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/gcp/.env"] [unique_id "aqxX4OcL08BTTQixEnpFpAAAAAM"]
[Thu Sep 17 15:13:04.771953 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxX4OcL08BTTQixEnpFogAAAEw"]
[Thu Sep 17 15:13:04.916899 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/wp-admin/css/colors/"] [unique_id "aqxX4OcL08BTTQixEnpFpgAAAAc"]
[Thu Sep 17 15:13:04.949230 2026] [security2:error] [pid 971102:tid 971298] [client 156.192.234.52:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4OcL08BTTQixEnpFpwAAAEA"]
[Thu Sep 17 15:13:04.949814 2026] [security2:error] [pid 971102:tid 971298] [client 156.192.234.52:52078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4OcL08BTTQixEnpFpwAAAEA"]
[Thu Sep 17 15:13:04.993168 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cloud/.env"] [unique_id "aqxX4OcL08BTTQixEnpFqAAAAG0"]
[Thu Sep 17 15:13:05.019857 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.194.17:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxX4ecL08BTTQixEnpFqwAAAF8"]
[Thu Sep 17 15:13:05.236745 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/infrastructure/.env"] [unique_id "aqxX4ecL08BTTQixEnpFsgAAAEU"]
[Thu Sep 17 15:13:05.261624 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFrgAAACo"]
[Thu Sep 17 15:13:05.261642 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFrgAAACo"]
[Thu Sep 17 15:13:05.405990 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxX4ecL08BTTQixEnpFuAAAAD8"]
[Thu Sep 17 15:13:05.470062 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "aqxX4ecL08BTTQixEnpFvwAAACM"]
[Thu Sep 17 15:13:05.506395 2026] [security2:error] [pid 971102:tid 971353] [client 115.244.164.14:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFwQAAAHc"]
[Thu Sep 17 15:13:05.506537 2026] [security2:error] [pid 971102:tid 971353] [client 115.244.164.14:56732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFwQAAAHc"]
[Thu Sep 17 15:13:05.615546 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxX4ecL08BTTQixEnpFxAAAACc"]
[Thu Sep 17 15:13:05.703160 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/k8s/.env"] [unique_id "aqxX4ecL08BTTQixEnpFxQAAADs"]
[Thu Sep 17 15:13:05.706717 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.194.17:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxX4ecL08BTTQixEnpFxgAAAEk"]
[Thu Sep 17 15:13:05.760537 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/wp-admin/css/colors/"] [unique_id "aqxX4ecL08BTTQixEnpFxwAAAHk"]
[Thu Sep 17 15:13:05.803899 2026] [security2:error] [pid 971102:tid 971335] [client 185.55.149.49:65220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFyQAAAGU"]
[Thu Sep 17 15:13:05.804005 2026] [security2:error] [pid 971102:tid 971335] [client 185.55.149.49:65220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFyQAAAGU"]
[Thu Sep 17 15:13:05.935022 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/kubernetes/.env"] [unique_id "aqxX4ecL08BTTQixEnpFywAAAHA"]
[Thu Sep 17 15:13:06.114581 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFygAAAA8"]
[Thu Sep 17 15:13:06.114607 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFygAAAA8"]
[Thu Sep 17 15:13:06.171734 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/terraform/.env"] [unique_id "aqxX4ucL08BTTQixEnpF0QAAABY"]
[Thu Sep 17 15:13:06.282831 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxX4ucL08BTTQixEnpF1gAAAA4"]
[Thu Sep 17 15:13:06.392321 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.194.17:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxX4ucL08BTTQixEnpF1wAAAH8"]
[Thu Sep 17 15:13:06.405301 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/ansible/.env"] [unique_id "aqxX4ucL08BTTQixEnpF2AAAAAA"]
[Thu Sep 17 15:13:06.638232 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.git/.env"] [unique_id "aqxX4ucL08BTTQixEnpF3QAAAEg"]
[Thu Sep 17 15:13:06.815121 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxX4ucL08BTTQixEnpF4AAAAHg"]
[Thu Sep 17 15:13:06.871771 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/ci/.env"] [unique_id "aqxX4ucL08BTTQixEnpF4wAAAHU"]
[Thu Sep 17 15:13:06.970955 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/wp-admin/css/colors/"] [unique_id "aqxX4ucL08BTTQixEnpF5AAAAC8"]
[Thu Sep 17 15:13:07.047747 2026] [security2:error] [pid 971102:tid 971311] [client 216.73.216.134:40683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.caitlinannemack.com"] [uri "/shop.php/sitemap624.xml"] [unique_id "aqxX4-cL08BTTQixEnpF6AAAAE0"]
[Thu Sep 17 15:13:07.084429 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.194.17:45370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxX4-cL08BTTQixEnpF6gAAABo"]
[Thu Sep 17 15:13:07.106165 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cd/.env"] [unique_id "aqxX4-cL08BTTQixEnpF6wAAAEo"]
[Thu Sep 17 15:13:07.323755 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpF7AAAADA"]
[Thu Sep 17 15:13:07.323784 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpF7AAAADA"]
[Thu Sep 17 15:13:07.339742 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/jenkins/.env"] [unique_id "aqxX4-cL08BTTQixEnpF8QAAAAM"]
[Thu Sep 17 15:13:07.536317 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:23000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4-cL08BTTQixEnpF9wAAACg"]
[Thu Sep 17 15:13:07.536464 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:23000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4-cL08BTTQixEnpF9wAAACg"]
[Thu Sep 17 15:13:07.575343 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/gitlab/.env"] [unique_id "aqxX4-cL08BTTQixEnpF-AAAAE4"]
[Thu Sep 17 15:13:07.607182 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/images/slider/"] [unique_id "aqxX4-cL08BTTQixEnpF_AAAADM"]
[Thu Sep 17 15:13:07.771041 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.194.17:40696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxX4-cL08BTTQixEnpGAgAAAHY"]
[Thu Sep 17 15:13:07.809294 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/github/.env"] [unique_id "aqxX4-cL08BTTQixEnpGAwAAAAU"]
[Thu Sep 17 15:13:07.962519 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpGAQAAAGo"]
[Thu Sep 17 15:13:07.962542 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpGAQAAAGo"]
[Thu Sep 17 15:13:08.041758 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/actions/.env"] [unique_id "aqxX5OcL08BTTQixEnpGCgAAAC0"]
[Thu Sep 17 15:13:08.055388 2026] [autoindex:error] [pid 971102:tid 971313] [client 194.163.128.162:59977] AH01276: Cannot serve directory /home1/commopo9/public_html/thezoeline/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:13:08.110411 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxX5OcL08BTTQixEnpGCwAAACU"]
[Thu Sep 17 15:13:08.280423 2026] [security2:error] [pid 971102:tid 971314] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/circleci/.env"] [unique_id "aqxX5OcL08BTTQixEnpGEQAAAFA"]
[Thu Sep 17 15:13:08.461708 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGEAAAAB8"]
[Thu Sep 17 15:13:08.461738 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGEAAAAB8"]
[Thu Sep 17 15:13:08.469473 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:40710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/www/phpinfo.php"] [unique_id "aqxX5OcL08BTTQixEnpGFgAAAH0"]
[Thu Sep 17 15:13:08.538462 2026] [security2:error] [pid 971102:tid 971267] [client 134.185.85.61:62746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "luxelivinglv.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxX5OcL08BTTQixEnpGFwAAACE"]
[Thu Sep 17 15:13:08.586387 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/travis/.env"] [unique_id "aqxX5OcL08BTTQixEnpGGAAAADw"]
[Thu Sep 17 15:13:08.636938 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/sites/default/files/"] [unique_id "aqxX5OcL08BTTQixEnpGGQAAAGM"]
[Thu Sep 17 15:13:08.928070 2026] [security2:error] [pid 971102:tid 971283] [client 134.185.85.61:55851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "luxelivinglv.com"] [uri "/media/system/js/core.js"] [unique_id "aqxX5OcL08BTTQixEnpGIAAAADE"]
[Thu Sep 17 15:13:08.961872 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/buildkite/.env"] [unique_id "aqxX5OcL08BTTQixEnpGIgAAAAA"]
[Thu Sep 17 15:13:08.976149 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGHgAAAA4"]
[Thu Sep 17 15:13:08.976172 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGHgAAAA4"]
[Thu Sep 17 15:13:09.088329 2026] [security2:error] [pid 971102:tid 971255] [client 169.58.197.253:57273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxX5ecL08BTTQixEnpGKAAAABU"], referer: binance.com
[Thu Sep 17 15:13:09.120883 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxX5ecL08BTTQixEnpGKQAAAH4"]
[Thu Sep 17 15:13:09.147467 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.194.17:40720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxX5ecL08BTTQixEnpGKgAAABQ"]
[Thu Sep 17 15:13:09.306742 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mysql/.env"] [unique_id "aqxX5ecL08BTTQixEnpGMAAAAAs"]
[Thu Sep 17 15:13:09.467475 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGLgAAAB4"]
[Thu Sep 17 15:13:09.467492 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGLgAAAB4"]
[Thu Sep 17 15:13:09.573953 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/postgres/.env"] [unique_id "aqxX5ecL08BTTQixEnpGNQAAABw"]
[Thu Sep 17 15:13:09.619845 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxX5ecL08BTTQixEnpGNgAAAGw"]
[Thu Sep 17 15:13:09.848928 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.194.17:40736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxX5ecL08BTTQixEnpGOQAAAEo"]
[Thu Sep 17 15:13:09.889274 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mongodb/.env"] [unique_id "aqxX5ecL08BTTQixEnpGPAAAADA"]
[Thu Sep 17 15:13:09.916979 2026] [security2:error] [pid 971102:tid 971341] [client 114.198.138.124:57967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ecL08BTTQixEnpGPgAAAGs"]
[Thu Sep 17 15:13:09.917074 2026] [security2:error] [pid 971102:tid 971341] [client 114.198.138.124:57967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ecL08BTTQixEnpGPgAAAGs"]
[Thu Sep 17 15:13:09.962301 2026] [security2:error] [pid 971102:tid 971235] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGOAAAAAE"]
[Thu Sep 17 15:13:09.962324 2026] [security2:error] [pid 971102:tid 971235] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGOAAAAAE"]
[Thu Sep 17 15:13:10.106795 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/components/"] [unique_id "aqxX5ucL08BTTQixEnpGQwAAAE4"]
[Thu Sep 17 15:13:10.221366 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/redis/.env"] [unique_id "aqxX5ucL08BTTQixEnpGSAAAAEU"]
[Thu Sep 17 15:13:10.466205 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGSgAAAHE"]
[Thu Sep 17 15:13:10.466231 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGSgAAAHE"]
[Thu Sep 17 15:13:10.478363 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/elasticsearch/.env"] [unique_id "aqxX5ucL08BTTQixEnpGTwAAACc"]
[Thu Sep 17 15:13:10.543065 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.194.17:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/site/phpinfo.php"] [unique_id "aqxX5ucL08BTTQixEnpGUQAAABg"]
[Thu Sep 17 15:13:10.616846 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/uploads/images/"] [unique_id "aqxX5ucL08BTTQixEnpGUgAAAHY"]
[Thu Sep 17 15:13:10.750077 2026] [security2:error] [pid 971102:tid 971357] [client 154.190.208.131:41874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ucL08BTTQixEnpGWQAAAHs"]
[Thu Sep 17 15:13:10.750166 2026] [security2:error] [pid 971102:tid 971357] [client 154.190.208.131:41874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ucL08BTTQixEnpGWQAAAHs"]
[Thu Sep 17 15:13:10.768506 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/rabbitmq/.env"] [unique_id "aqxX5ucL08BTTQixEnpGWwAAAEE"]
[Thu Sep 17 15:13:10.823907 2026] [security2:error] [pid 971102:tid 971295] [client 216.144.225.2:51479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "techsol360.com"] [uri "/.env"] [unique_id "aqxX5ucL08BTTQixEnpGXAAAAD0"]
[Thu Sep 17 15:13:10.891427 2026] [security2:error] [pid 971102:tid 971277] [client 5.189.145.112:50111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxX5ucL08BTTQixEnpGXQAAACs"], referer: binance.com
[Thu Sep 17 15:13:10.983804 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGWgAAAHc"]
[Thu Sep 17 15:13:10.983842 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGWgAAAHc"]
[Thu Sep 17 15:13:11.065402 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/kafka/.env"] [unique_id "aqxX5-cL08BTTQixEnpGYwAAACE"]
[Thu Sep 17 15:13:11.076623 2026] [security2:error] [pid 971102:tid 971294] [client 216.144.225.2:58151] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "techsol360.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "aqxX5-cL08BTTQixEnpGZAAAADw"]
[Thu Sep 17 15:13:11.129959 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxX5-cL08BTTQixEnpGZQAAAAQ"]
[Thu Sep 17 15:13:11.234254 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.194.17:40744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxX5-cL08BTTQixEnpGaQAAAB8"]
[Thu Sep 17 15:13:11.298957 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/queue/.env"] [unique_id "aqxX5-cL08BTTQixEnpGbAAAAGk"]
[Thu Sep 17 15:13:11.467614 2026] [security2:error] [pid 971102:tid 971335] [client 54.152.77.108:34096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rocketboxcreative.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGbwAAZRA"]
[Thu Sep 17 15:13:11.491352 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGawAAABs"]
[Thu Sep 17 15:13:11.491375 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGawAAABs"]
[Thu Sep 17 15:13:11.585766 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/worker/.env"] [unique_id "aqxX5-cL08BTTQixEnpGeAAAAAI"]
[Thu Sep 17 15:13:11.652376 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/fonts/"] [unique_id "aqxX5-cL08BTTQixEnpGfAAAAHg"]
[Thu Sep 17 15:13:11.723127 2026] [security2:error] [pid 971102:tid 971118] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxX5-cL08BTTQixEnpGfgAAJQ4"]
[Thu Sep 17 15:13:11.808628 2026] [security2:error] [pid 971102:tid 971248] [client 186.105.232.15:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5-cL08BTTQixEnpGgAAAAA4"]
[Thu Sep 17 15:13:11.808769 2026] [security2:error] [pid 971102:tid 971248] [client 186.105.232.15:57202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5-cL08BTTQixEnpGgAAAAA4"]
[Thu Sep 17 15:13:11.849632 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/job/.env"] [unique_id "aqxX5-cL08BTTQixEnpGgQAAADQ"]
[Thu Sep 17 15:13:11.929327 2026] [security2:error] [pid 971102:tid 971260] [client 111.225.149.191:28940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/"] [unique_id "aqxX5-cL08BTTQixEnpGggAAABo"]
[Thu Sep 17 15:13:11.937219 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.194.17:40760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxX5-cL08BTTQixEnpGgwAAABw"]
[Thu Sep 17 15:13:11.995821 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGfwAAAHI"]
[Thu Sep 17 15:13:11.995841 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGfwAAAHI"]
[Thu Sep 17 15:13:12.003395 2026] [security2:error] [pid 971102:tid 971324] [client 45.169.98.18:61336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6OcL08BTTQixEnpGhwAAAFo"]
[Thu Sep 17 15:13:12.004461 2026] [security2:error] [pid 971102:tid 971324] [client 45.169.98.18:61336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6OcL08BTTQixEnpGhwAAAFo"]
[Thu Sep 17 15:13:12.122312 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "aqxX6OcL08BTTQixEnpGiQAAAEw"]
[Thu Sep 17 15:13:12.144771 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxX6OcL08BTTQixEnpGigAAAEI"]
[Thu Sep 17 15:13:12.340872 2026] [authz_core:error] [pid 971102:tid 971325] [client 20.244.34.24:57076] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:13:12.358831 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/qa/.env"] [unique_id "aqxX6OcL08BTTQixEnpGlwAAAAg"]
[Thu Sep 17 15:13:12.529035 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6OcL08BTTQixEnpGkQAAAF8"]
[Thu Sep 17 15:13:12.529058 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6OcL08BTTQixEnpGkQAAAF8"]
[Thu Sep 17 15:13:12.592451 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/preview/.env"] [unique_id "aqxX6OcL08BTTQixEnpGnwAAADs"]
[Thu Sep 17 15:13:12.635129 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.194.17:40762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxX6OcL08BTTQixEnpGoAAAAG4"]
[Thu Sep 17 15:13:12.674803 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxX6OcL08BTTQixEnpGoQAAAF0"]
[Thu Sep 17 15:13:12.823573 2026] [security2:error] [pid 971102:tid 971246] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/beta/.env"] [unique_id "aqxX6OcL08BTTQixEnpGqAAAAAw"]
[Thu Sep 17 15:13:12.879540 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxX6OcL08BTTQixEnpGpwAAAE8"]
[Thu Sep 17 15:13:13.022988 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/"] [unique_id "aqxX6ecL08BTTQixEnpGsAAAACs"]
[Thu Sep 17 15:13:13.056282 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/uat/.env"] [unique_id "aqxX6ecL08BTTQixEnpGswAAABA"]
[Thu Sep 17 15:13:13.256533 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/"] [unique_id "aqxX6ecL08BTTQixEnpGtAAAAFY"]
[Thu Sep 17 15:13:13.288382 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/stage/.env"] [unique_id "aqxX6ecL08BTTQixEnpGuQAAAA8"]
[Thu Sep 17 15:13:13.312105 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.194.17:40766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/core/phpinfo.php"] [unique_id "aqxX6ecL08BTTQixEnpGugAAAHc"]
[Thu Sep 17 15:13:13.402729 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/wp-content/plugins/contact-form-7/"] [unique_id "aqxX6ecL08BTTQixEnpGuwAAACw"]
[Thu Sep 17 15:13:13.518535 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "aqxX6ecL08BTTQixEnpGvgAAACk"]
[Thu Sep 17 15:13:13.757329 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ecL08BTTQixEnpGwQAAABk"]
[Thu Sep 17 15:13:13.757356 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ecL08BTTQixEnpGwQAAABk"]
[Thu Sep 17 15:13:13.759082 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "aqxX6ecL08BTTQixEnpGxQAAAEg"]
[Thu Sep 17 15:13:13.918705 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/admin.php"] [unique_id "aqxX6ecL08BTTQixEnpGxgAAAA0"]
[Thu Sep 17 15:13:13.918827 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/admin.php"] [unique_id "aqxX6ecL08BTTQixEnpGxgAAAA0"]
[Thu Sep 17 15:13:13.987793 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/config/app/.env"] [unique_id "aqxX6ecL08BTTQixEnpGyQAAAHg"]
[Thu Sep 17 15:13:13.995246 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxX6ecL08BTTQixEnpGywAAABM"]
[Thu Sep 17 15:13:14.198904 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:46800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/edit-contact-form.php"] [unique_id "aqxX6ucL08BTTQixEnpGzQAAAB4"]
[Thu Sep 17 15:13:14.199002 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:46800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/edit-contact-form.php"] [unique_id "aqxX6ucL08BTTQixEnpGzQAAAB4"]
[Thu Sep 17 15:13:14.237360 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.130.148:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxX6ucL08BTTQixEnpGzgAAAFc"]
[Thu Sep 17 15:13:14.474534 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:46810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/"] [unique_id "aqxX6ucL08BTTQixEnpG3AAAAFs"]
[Thu Sep 17 15:13:14.705968 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/"] [unique_id "aqxX6ucL08BTTQixEnpG3wAAAAc"]
[Thu Sep 17 15:13:14.723451 2026] [security2:error] [pid 971102:tid 971127] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxX6ucL08BTTQixEnpG4gAAFhc"]
[Thu Sep 17 15:13:14.848131 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:46810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/wp-content/plugins/contact-form-7/admin/"] [unique_id "aqxX6ucL08BTTQixEnpG4wAAAG4"]
[Thu Sep 17 15:13:14.916993 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.130.148:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxX6ucL08BTTQixEnpG5QAAABg"]
[Thu Sep 17 15:13:15.199942 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ucL08BTTQixEnpG6gAAAGo"]
[Thu Sep 17 15:13:15.199979 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ucL08BTTQixEnpG6gAAAGo"]
[Thu Sep 17 15:13:15.329940 2026] [security2:error] [pid 971102:tid 971307] [client 34.122.149.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxX6-cL08BTTQixEnpG8AAAAEk"]
[Thu Sep 17 15:13:15.337390 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:46810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/admin-functions.php"] [unique_id "aqxX6-cL08BTTQixEnpG9wAAAEE"]
[Thu Sep 17 15:13:15.337523 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:46810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/admin-functions.php"] [unique_id "aqxX6-cL08BTTQixEnpG9wAAAEE"]
[Thu Sep 17 15:13:15.510123 2026] [security2:error] [pid 971102:tid 971246] [client 156.192.234.52:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6-cL08BTTQixEnpG_wAAAAw"]
[Thu Sep 17 15:13:15.510342 2026] [security2:error] [pid 971102:tid 971246] [client 156.192.234.52:52698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6-cL08BTTQixEnpG_wAAAAw"]
[Thu Sep 17 15:13:15.614979 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/class-contact-forms-list-table.php"] [unique_id "aqxX6-cL08BTTQixEnpHBAAAADY"]
[Thu Sep 17 15:13:15.615089 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:46820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/class-contact-forms-list-table.php"] [unique_id "aqxX6-cL08BTTQixEnpHBAAAADY"]
[Thu Sep 17 15:13:15.615370 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.130.148:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxX6-cL08BTTQixEnpHBQAAAH0"]
[Thu Sep 17 15:13:15.906161 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:46836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/config-validator.php"] [unique_id "aqxX6-cL08BTTQixEnpHDQAAAA4"]
[Thu Sep 17 15:13:15.906261 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:46836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/config-validator.php"] [unique_id "aqxX6-cL08BTTQixEnpHDQAAAA4"]
[Thu Sep 17 15:13:16.030320 2026] [security2:error] [pid 971102:tid 971354] [client 115.244.164.14:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHEgAAAHg"]
[Thu Sep 17 15:13:16.030415 2026] [security2:error] [pid 971102:tid 971354] [client 115.244.164.14:57386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHEgAAAHg"]
[Thu Sep 17 15:13:16.188990 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:46848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/css/"] [unique_id "aqxX7OcL08BTTQixEnpHFgAAAFo"]
[Thu Sep 17 15:13:16.314121 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.130.148:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/i.php"] [unique_id "aqxX7OcL08BTTQixEnpHGgAAAHI"]
[Thu Sep 17 15:13:16.371798 2026] [security2:error] [pid 971102:tid 971350] [client 169.58.197.253:57735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxX7OcL08BTTQixEnpHHQAAAHQ"], referer: binance.com
[Thu Sep 17 15:13:16.377267 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/css/"] [unique_id "aqxX7OcL08BTTQixEnpHHAAAAEA"]
[Thu Sep 17 15:13:16.477738 2026] [security2:error] [pid 971102:tid 971244] [client 185.55.149.49:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHIgAAAAo"]
[Thu Sep 17 15:13:16.477851 2026] [security2:error] [pid 971102:tid 971244] [client 185.55.149.49:49805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHIgAAAAo"]
[Thu Sep 17 15:13:16.521038 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:46848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/css/wp-content/plugins/contact-form-7/admin/includes/"] [unique_id "aqxX7OcL08BTTQixEnpHIwAAAHw"]
[Thu Sep 17 15:13:16.561565 2026] [security2:error] [pid 971102:tid 971322] [client 216.73.216.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.casualchessclub.com"] [uri "/index.php"] [unique_id "aqxX6ucL08BTTQixEnpG3gAAAFg"]
[Thu Sep 17 15:13:16.859616 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7OcL08BTTQixEnpHJwAAAF0"]
[Thu Sep 17 15:13:16.859642 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7OcL08BTTQixEnpHJwAAAF0"]
[Thu Sep 17 15:13:17.001674 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/editor.php"] [unique_id "aqxX7ecL08BTTQixEnpHMgAAACs"]
[Thu Sep 17 15:13:17.001789 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:46848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/editor.php"] [unique_id "aqxX7ecL08BTTQixEnpHMgAAACs"]
[Thu Sep 17 15:13:17.004611 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.130.148:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxX7ecL08BTTQixEnpHMwAAAGc"]
[Thu Sep 17 15:13:17.282113 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/help-tabs.php"] [unique_id "aqxX7ecL08BTTQixEnpHOQAAAFI"]
[Thu Sep 17 15:13:17.282231 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:46858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/help-tabs.php"] [unique_id "aqxX7ecL08BTTQixEnpHOQAAAFI"]
[Thu Sep 17 15:13:17.466283 2026] [security2:error] [pid 971102:tid 971149] [remote 47.128.29.159:36708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "techsol360.com"] [uri "/robots.txt"] [unique_id "aqxX7ecL08BTTQixEnpHPgAAYy0"]
[Thu Sep 17 15:13:17.536911 2026] [security2:error] [pid 971102:tid 971246] [client 4.240.114.86:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxX7ecL08BTTQixEnpHQAAAAAw"], referer: binance.com
[Thu Sep 17 15:13:17.608938 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:46860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/js/"] [unique_id "aqxX7ecL08BTTQixEnpHQwAAADY"]
[Thu Sep 17 15:13:17.755349 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.130.148:35426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxX7ecL08BTTQixEnpHRgAAAHA"]
[Thu Sep 17 15:13:17.780863 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/js/index.js"] [unique_id "aqxX7ecL08BTTQixEnpHRwAAAEs"]
[Thu Sep 17 15:13:17.875645 2026] [security2:error] [pid 971102:tid 971257] [client 5.189.145.112:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxX7ecL08BTTQixEnpHTAAAABc"], referer: binance.com
[Thu Sep 17 15:13:17.933568 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/tag-generator.php"] [unique_id "aqxX7ecL08BTTQixEnpHTQAAABM"]
[Thu Sep 17 15:13:17.933719 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:46860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/tag-generator.php"] [unique_id "aqxX7ecL08BTTQixEnpHTQAAABM"]
[Thu Sep 17 15:13:18.187568 2026] [security2:error] [pid 971102:tid 971307] [client 169.58.197.253:57813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ppfc.net"] [uri "/index.php"] [unique_id "aqxX7ecL08BTTQixEnpHNwAAAEk"], referer: binance.com
[Thu Sep 17 15:13:18.259619 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:46872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/welcome-panel.php"] [unique_id "aqxX7ucL08BTTQixEnpHVgAAABw"]
[Thu Sep 17 15:13:18.259763 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:46872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/welcome-panel.php"] [unique_id "aqxX7ucL08BTTQixEnpHVgAAABw"]
[Thu Sep 17 15:13:18.447973 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.130.148:35434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/test.php"] [unique_id "aqxX7ucL08BTTQixEnpHWwAAAFc"]
[Thu Sep 17 15:13:18.790524 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/assets/"] [unique_id "aqxX7ucL08BTTQixEnpHZAAAAHw"]
[Thu Sep 17 15:13:18.957599 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/assets/"] [unique_id "aqxX7ucL08BTTQixEnpHaAAAAF8"]
[Thu Sep 17 15:13:19.102842 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/assets/wp-content/plugins/contact-form-7/"] [unique_id "aqxX7-cL08BTTQixEnpHbgAAACo"]
[Thu Sep 17 15:13:19.222438 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:19.222456 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:19.502996 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7-cL08BTTQixEnpHcgAAAGY"]
[Thu Sep 17 15:13:19.503018 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7-cL08BTTQixEnpHcgAAAGY"]
[Thu Sep 17 15:13:19.655755 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX7-cL08BTTQixEnpHhAAAAEc"]
[Thu Sep 17 15:13:19.752775 2026] [security2:error] [pid 971102:tid 971333] [client 4.240.114.86:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxX7-cL08BTTQixEnpHiQAAAGM"], referer: binance.com
[Thu Sep 17 15:13:19.874741 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX7-cL08BTTQixEnpHiwAAAH0"]
[Thu Sep 17 15:13:19.922244 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:35444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/p.php"] [unique_id "aqxX7-cL08BTTQixEnpHjQAAAA8"]
[Thu Sep 17 15:13:20.020711 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/wp-content/plugins/contact-form-7/"] [unique_id "aqxX8OcL08BTTQixEnpHlgAAAAQ"]
[Thu Sep 17 15:13:20.382451 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8OcL08BTTQixEnpHmgAAAAs"]
[Thu Sep 17 15:13:20.382478 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8OcL08BTTQixEnpHmgAAAAs"]
[Thu Sep 17 15:13:20.528166 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/block-editor/"] [unique_id "aqxX8OcL08BTTQixEnpHqQAAAEQ"]
[Thu Sep 17 15:13:20.680738 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/block-editor/index.js"] [unique_id "aqxX8OcL08BTTQixEnpHqgAAAE4"]
[Thu Sep 17 15:13:20.731602 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.130.148:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxX8OcL08BTTQixEnpHrAAAAHI"]
[Thu Sep 17 15:13:20.755421 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/uploads/"] [unique_id "aqxX8OcL08BTTQixEnpHrwAAADA"]
[Thu Sep 17 15:13:20.803380 2026] [security2:error] [pid 971102:tid 971308] [client 114.198.138.124:58605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8OcL08BTTQixEnpHsQAAAEo"]
[Thu Sep 17 15:13:20.803514 2026] [security2:error] [pid 971102:tid 971308] [client 114.198.138.124:58605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8OcL08BTTQixEnpHsQAAAEo"]
[Thu Sep 17 15:13:20.826641 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:46884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/capabilities.php"] [unique_id "aqxX8OcL08BTTQixEnpHsgAAABY"]
[Thu Sep 17 15:13:20.826768 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/capabilities.php"] [unique_id "aqxX8OcL08BTTQixEnpHsgAAABY"]
[Thu Sep 17 15:13:21.103277 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:37694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/"] [unique_id "aqxX8ecL08BTTQixEnpHuAAAAC8"]
[Thu Sep 17 15:13:21.266603 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/"] [unique_id "aqxX8ecL08BTTQixEnpHvAAAAGY"]
[Thu Sep 17 15:13:21.268788 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:42479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ecL08BTTQixEnpHuwAAAAg"]
[Thu Sep 17 15:13:21.268867 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:42479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ecL08BTTQixEnpHuwAAAAg"]
[Thu Sep 17 15:13:21.419623 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:37694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX8ecL08BTTQixEnpHwAAAAEc"]
[Thu Sep 17 15:13:21.433618 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.130.148:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxX8ecL08BTTQixEnpHxAAAACM"]
[Thu Sep 17 15:13:21.581050 2026] [core:error] [pid 971102:tid 971299] [client 74.7.228.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:21.581073 2026] [core:error] [pid 971102:tid 971299] [client 74.7.228.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:21.581198 2026] [security2:error] [pid 971102:tid 971299] [client 74.7.228.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "test.jcktax.com"] [uri "/home4/jcktaxco/public_html/index.php"] [unique_id "aqxX8ecL08BTTQixEnpHygAAAEE"]
[Thu Sep 17 15:13:21.589375 2026] [security2:error] [pid 971102:tid 971303] [client 74.7.228.18:56118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "test.jcktax.com"] [uri "/robots.txt"] [unique_id "aqxX8ecL08BTTQixEnpHxgAARTk"]
[Thu Sep 17 15:13:21.735911 2026] [autoindex:error] [pid 971102:tid 971243] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:21.736444 2026] [security2:error] [pid 971102:tid 971243] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/cgi-sys/403.html"] [unique_id "aqxX8ecL08BTTQixEnpHzQAAAAk"]
[Thu Sep 17 15:13:21.748526 2026] [security2:error] [pid 971102:tid 971291] [client 180.102.110.140:34788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.amecoegypt.com"] [uri "/"] [unique_id "aqxX8ecL08BTTQixEnpH0AAAADk"]
[Thu Sep 17 15:13:21.748610 2026] [security2:error] [pid 971102:tid 971291] [client 180.102.110.140:34788] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.amecoegypt.com"] [uri "/"] [unique_id "aqxX8ecL08BTTQixEnpH0AAAADk"]
[Thu Sep 17 15:13:21.770141 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8ecL08BTTQixEnpHyQAAAHc"]
[Thu Sep 17 15:13:21.770170 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8ecL08BTTQixEnpHyQAAAHc"]
[Thu Sep 17 15:13:21.909653 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:37694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/actions.php"] [unique_id "aqxX8ecL08BTTQixEnpH0wAAAEg"]
[Thu Sep 17 15:13:21.909783 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:37694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/actions.php"] [unique_id "aqxX8ecL08BTTQixEnpH0wAAAEg"]
[Thu Sep 17 15:13:22.063887 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/"] [unique_id "aqxX8ucL08BTTQixEnpH2QAAAE0"]
[Thu Sep 17 15:13:22.121184 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.130.148:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxX8ucL08BTTQixEnpH2gAAAGQ"]
[Thu Sep 17 15:13:22.191152 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:37698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/additional-settings.php"] [unique_id "aqxX8ucL08BTTQixEnpH3AAAAGg"]
[Thu Sep 17 15:13:22.191280 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:37698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/additional-settings.php"] [unique_id "aqxX8ucL08BTTQixEnpH3AAAAGg"]
[Thu Sep 17 15:13:22.317543 2026] [autoindex:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:22.318185 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/"] [unique_id "aqxX8ucL08BTTQixEnpH4AAAAHY"]
[Thu Sep 17 15:13:22.474735 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/form.php"] [unique_id "aqxX8ucL08BTTQixEnpH5gAAADM"]
[Thu Sep 17 15:13:22.474828 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:37706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/form.php"] [unique_id "aqxX8ucL08BTTQixEnpH5gAAADM"]
[Thu Sep 17 15:13:22.476239 2026] [security2:error] [pid 971102:tid 971240] [client 45.169.98.18:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH6AAAAAY"]
[Thu Sep 17 15:13:22.476337 2026] [security2:error] [pid 971102:tid 971240] [client 45.169.98.18:61992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH6AAAAAY"]
[Thu Sep 17 15:13:22.523331 2026] [security2:error] [pid 971102:tid 971268] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/css/"] [unique_id "aqxX8ucL08BTTQixEnpH6gAAACI"]
[Thu Sep 17 15:13:22.728495 2026] [autoindex:error] [pid 971102:tid 971251] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:22.729039 2026] [security2:error] [pid 971102:tid 971251] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/css/"] [unique_id "aqxX8ucL08BTTQixEnpH7gAAABE"]
[Thu Sep 17 15:13:22.776780 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/mail.php"] [unique_id "aqxX8ucL08BTTQixEnpH8gAAAHw"]
[Thu Sep 17 15:13:22.776895 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/mail.php"] [unique_id "aqxX8ucL08BTTQixEnpH8gAAAHw"]
[Thu Sep 17 15:13:22.806393 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.130.148:35484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxX8ucL08BTTQixEnpH9AAAAA0"]
[Thu Sep 17 15:13:22.894841 2026] [security2:error] [pid 971102:tid 971317] [client 186.105.232.15:57803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH9wAAAFM"]
[Thu Sep 17 15:13:22.894982 2026] [security2:error] [pid 971102:tid 971317] [client 186.105.232.15:57803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH9wAAAFM"]
[Thu Sep 17 15:13:22.943615 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/ID3/"] [unique_id "aqxX8ucL08BTTQixEnpH-QAAAEo"]
[Thu Sep 17 15:13:23.069813 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/messages.php"] [unique_id "aqxX8-cL08BTTQixEnpH_QAAAHU"]
[Thu Sep 17 15:13:23.069932 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:37722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/messages.php"] [unique_id "aqxX8-cL08BTTQixEnpH_QAAAHU"]
[Thu Sep 17 15:13:23.134036 2026] [autoindex:error] [pid 971102:tid 971280] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:23.134860 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/ID3/"] [unique_id "aqxX8-cL08BTTQixEnpH_wAAAC4"]
[Thu Sep 17 15:13:23.259829 2026] [security2:error] [pid 971102:tid 971281] [client 169.58.197.253:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxX8-cL08BTTQixEnpIAgAAAC8"], referer: binance.com
[Thu Sep 17 15:13:23.362191 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/IXR/"] [unique_id "aqxX8-cL08BTTQixEnpIBgAAAAg"]
[Thu Sep 17 15:13:23.365083 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:37734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/validator.php"] [unique_id "aqxX8-cL08BTTQixEnpIBwAAACg"]
[Thu Sep 17 15:13:23.365206 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:37734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/validator.php"] [unique_id "aqxX8-cL08BTTQixEnpIBwAAACg"]
[Thu Sep 17 15:13:23.384601 2026] [security2:error] [pid 971102:tid 971304] [client 4.240.114.86:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxX8-cL08BTTQixEnpICAAAAEY"], referer: binance.com
[Thu Sep 17 15:13:23.498227 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.130.148:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxX8-cL08BTTQixEnpIDgAAABg"]
[Thu Sep 17 15:13:23.541521 2026] [autoindex:error] [pid 971102:tid 971270] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:23.542122 2026] [security2:error] [pid 971102:tid 971270] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/IXR/"] [unique_id "aqxX8-cL08BTTQixEnpIEAAAACQ"]
[Thu Sep 17 15:13:23.583270 2026] [security2:error] [pid 971102:tid 971326] [client 204.14.249.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxX8-cL08BTTQixEnpICwAAAFw"], referer: https://instagram.com/
[Thu Sep 17 15:13:23.739185 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Requests/"] [unique_id "aqxX8-cL08BTTQixEnpIEwAAAD0"]
[Thu Sep 17 15:13:23.767936 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:37744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-functions.php"] [unique_id "aqxX8-cL08BTTQixEnpIFgAAAFI"]
[Thu Sep 17 15:13:23.768059 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:37744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-functions.php"] [unique_id "aqxX8-cL08BTTQixEnpIFgAAAFI"]
[Thu Sep 17 15:13:23.911225 2026] [security2:error] [pid 971102:tid 971330] [client 169.58.197.253:58254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ppfc.net"] [uri "/index.php"] [unique_id "aqxX8-cL08BTTQixEnpIFwAAAGA"], referer: binance.com
[Thu Sep 17 15:13:23.948176 2026] [autoindex:error] [pid 971102:tid 971238] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:23.949326 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Requests/"] [unique_id "aqxX8-cL08BTTQixEnpIGwAAAAQ"]
[Thu Sep 17 15:13:24.062678 2026] [cgid:error] [pid 971102:tid 971211] [remote 104.28.40.132:50191] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:13:24.066119 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:37756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-template.php"] [unique_id "aqxX9OcL08BTTQixEnpIIQAAACk"]
[Thu Sep 17 15:13:24.066229 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:37756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-template.php"] [unique_id "aqxX9OcL08BTTQixEnpIIQAAACk"]
[Thu Sep 17 15:13:24.180778 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.130.148:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxX9OcL08BTTQixEnpIIgAAAC0"]
[Thu Sep 17 15:13:24.208344 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxX9OcL08BTTQixEnpIIwAAACE"]
[Thu Sep 17 15:13:24.364194 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:37772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form.php"] [unique_id "aqxX9OcL08BTTQixEnpIKQAAAAs"]
[Thu Sep 17 15:13:24.364304 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:37772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form.php"] [unique_id "aqxX9OcL08BTTQixEnpIKQAAAAs"]
[Thu Sep 17 15:13:24.457656 2026] [autoindex:error] [pid 971102:tid 971240] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:24.458158 2026] [security2:error] [pid 971102:tid 971240] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxX9OcL08BTTQixEnpILQAAAAY"]
[Thu Sep 17 15:13:24.646714 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/controller.php"] [unique_id "aqxX9OcL08BTTQixEnpIMwAAABU"]
[Thu Sep 17 15:13:24.646824 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:37786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/controller.php"] [unique_id "aqxX9OcL08BTTQixEnpIMwAAABU"]
[Thu Sep 17 15:13:24.680682 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/"] [unique_id "aqxX9OcL08BTTQixEnpINAAAAEw"]
[Thu Sep 17 15:13:24.864650 2026] [autoindex:error] [pid 971102:tid 971256] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:24.865185 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/"] [unique_id "aqxX9OcL08BTTQixEnpIOwAAABY"]
[Thu Sep 17 15:13:24.896397 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.130.148:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxX9OcL08BTTQixEnpIPAAAAB4"]
[Thu Sep 17 15:13:24.971931 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:37796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/"] [unique_id "aqxX9OcL08BTTQixEnpIQQAAADA"]
[Thu Sep 17 15:13:25.075122 2026] [security2:error] [pid 971102:tid 971348] [client 5.189.145.112:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxX9ecL08BTTQixEnpIQwAAAHI"], referer: binance.com
[Thu Sep 17 15:13:25.133279 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/"] [unique_id "aqxX9ecL08BTTQixEnpIRQAAAHo"]
[Thu Sep 17 15:13:25.163309 2026] [security2:error] [pid 971102:tid 971300] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxX9ecL08BTTQixEnpIRwAAAEI"]
[Thu Sep 17 15:13:25.254649 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.221.252:42016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxX9ecL08BTTQixEnpISgAAAFo"]
[Thu Sep 17 15:13:25.278406 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:37796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX9ecL08BTTQixEnpISwAAAGY"]
[Thu Sep 17 15:13:25.410814 2026] [security2:error] [pid 971102:tid 971269] [client 192.178.6.4:38469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxX9ecL08BTTQixEnpITgAAACM"]
[Thu Sep 17 15:13:25.606086 2026] [core:error] [pid 971102:tid 971243] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:25.606106 2026] [core:error] [pid 971102:tid 971243] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:25.654367 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpIUQAAAAw"]
[Thu Sep 17 15:13:25.654400 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpIUQAAAAw"]
[Thu Sep 17 15:13:25.798406 2026] [security2:error] [pid 971102:tid 971257] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpITAAAAAg"]
[Thu Sep 17 15:13:25.798430 2026] [security2:error] [pid 971102:tid 971257] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpITAAAAAg"]
[Thu Sep 17 15:13:25.825497 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/file.php"] [unique_id "aqxX9ecL08BTTQixEnpIZQAAAC0"]
[Thu Sep 17 15:13:25.825604 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:37796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/file.php"] [unique_id "aqxX9ecL08BTTQixEnpIZQAAAC0"]
[Thu Sep 17 15:13:25.877622 2026] [authz_core:error] [pid 971102:tid 971258] [client 20.244.34.24:54639] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:13:25.937077 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.221.252:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/info.php"] [unique_id "aqxX9ecL08BTTQixEnpIaQAAACk"]
[Thu Sep 17 15:13:26.054772 2026] [security2:error] [pid 971102:tid 971283] [client 156.192.234.52:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIbQAAADE"]
[Thu Sep 17 15:13:26.060120 2026] [security2:error] [pid 971102:tid 971283] [client 156.192.234.52:53294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIbQAAADE"]
[Thu Sep 17 15:13:26.113336 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/filesystem.php"] [unique_id "aqxX9ucL08BTTQixEnpIbgAAABA"]
[Thu Sep 17 15:13:26.113482 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:37800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/filesystem.php"] [unique_id "aqxX9ucL08BTTQixEnpIbgAAABA"]
[Thu Sep 17 15:13:26.194423 2026] [security2:error] [pid 971102:tid 971259] [client 162.241.226.11:15670] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxX9ucL08BTTQixEnpIbwAAABk"]
[Thu Sep 17 15:13:26.295734 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:37206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxX9ucL08BTTQixEnpIcAAAADs"]
[Thu Sep 17 15:13:26.333458 2026] [security2:error] [pid 971102:tid 971317] [client 157.230.228.220:59451] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ocdpeers.seandaviddeezyn.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX9ucL08BTTQixEnpIcwAAAFM"]
[Thu Sep 17 15:13:26.353631 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxX9ucL08BTTQixEnpIdQAAAH4"]
[Thu Sep 17 15:13:26.420165 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:37804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tag.php"] [unique_id "aqxX9ucL08BTTQixEnpIdwAAADU"]
[Thu Sep 17 15:13:26.420316 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:37804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tag.php"] [unique_id "aqxX9ucL08BTTQixEnpIdwAAADU"]
[Thu Sep 17 15:13:26.479271 2026] [security2:error] [pid 971102:tid 971244] [client 157.230.228.220:59453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ocdpeers.seandaviddeezyn.com"] [uri "/"] [unique_id "aqxX9ucL08BTTQixEnpIegAAAAo"]
[Thu Sep 17 15:13:26.576680 2026] [security2:error] [pid 971102:tid 971321] [client 115.244.164.14:58040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIfAAAAFc"]
[Thu Sep 17 15:13:26.576812 2026] [security2:error] [pid 971102:tid 971321] [client 115.244.164.14:58040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIfAAAAFc"]
[Thu Sep 17 15:13:26.635557 2026] [security2:error] [pid 971102:tid 971343] [client 157.230.228.220:59454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ocdpeers.seandaviddeezyn.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX9ucL08BTTQixEnpIfQAAAG0"]
[Thu Sep 17 15:13:26.639199 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.221.252:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/php.php"] [unique_id "aqxX9ucL08BTTQixEnpIfgAAABM"]
[Thu Sep 17 15:13:26.712758 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tags-manager.php"] [unique_id "aqxX9ucL08BTTQixEnpIgwAAAEI"]
[Thu Sep 17 15:13:26.712856 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:37816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tags-manager.php"] [unique_id "aqxX9ucL08BTTQixEnpIgwAAAEI"]
[Thu Sep 17 15:13:26.995782 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.130.148:37210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxX9ucL08BTTQixEnpIigAAAF8"]
[Thu Sep 17 15:13:26.997126 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/formatting.php"] [unique_id "aqxX9ucL08BTTQixEnpIiwAAAD4"]
[Thu Sep 17 15:13:26.997224 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/formatting.php"] [unique_id "aqxX9ucL08BTTQixEnpIiwAAAD4"]
[Thu Sep 17 15:13:27.014320 2026] [security2:error] [pid 971102:tid 971304] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ucL08BTTQixEnpIhwAAAEY"]
[Thu Sep 17 15:13:27.014348 2026] [security2:error] [pid 971102:tid 971304] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ucL08BTTQixEnpIhwAAAEY"]
[Thu Sep 17 15:13:27.229192 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:59539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX9-cL08BTTQixEnpIjwAAAAk"]
[Thu Sep 17 15:13:27.229306 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:59539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX9-cL08BTTQixEnpIjwAAAAk"]
[Thu Sep 17 15:13:27.284031 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/functions.php"] [unique_id "aqxX9-cL08BTTQixEnpIkgAAAA4"]
[Thu Sep 17 15:13:27.284146 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/functions.php"] [unique_id "aqxX9-cL08BTTQixEnpIkgAAAA4"]
[Thu Sep 17 15:13:27.324858 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.221.252:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/i.php"] [unique_id "aqxX9-cL08BTTQixEnpIlAAAACg"]
[Thu Sep 17 15:13:27.458749 2026] [security2:error] [pid 971102:tid 971355] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxX9-cL08BTTQixEnpIlwAAAHk"]
[Thu Sep 17 15:13:27.562000 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/html-formatter.php"] [unique_id "aqxX9-cL08BTTQixEnpImQAAAD8"]
[Thu Sep 17 15:13:27.562152 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:37830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/html-formatter.php"] [unique_id "aqxX9-cL08BTTQixEnpImQAAAD8"]
[Thu Sep 17 15:13:27.724211 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.130.148:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxX9-cL08BTTQixEnpImwAAAAQ"]
[Thu Sep 17 15:13:27.805025 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9-cL08BTTQixEnpImgAAAC0"]
[Thu Sep 17 15:13:27.805052 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9-cL08BTTQixEnpImgAAAC0"]
[Thu Sep 17 15:13:27.838213 2026] [security2:error] [pid 971102:tid 971298] [client 167.99.159.16:33358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpIVwAAAEA"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:27.863440 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/integration.php"] [unique_id "aqxX9-cL08BTTQixEnpIoAAAABk"]
[Thu Sep 17 15:13:27.863532 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/integration.php"] [unique_id "aqxX9-cL08BTTQixEnpIoAAAABk"]
[Thu Sep 17 15:13:28.025840 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.221.252:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxX-OcL08BTTQixEnpIpAAAAHY"]
[Thu Sep 17 15:13:28.166521 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:37856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/js/"] [unique_id "aqxX-OcL08BTTQixEnpIpQAAABQ"]
[Thu Sep 17 15:13:28.250967 2026] [security2:error] [pid 971102:tid 971255] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxX-OcL08BTTQixEnpIpwAAABU"]
[Thu Sep 17 15:13:28.332097 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/js/index.js"] [unique_id "aqxX-OcL08BTTQixEnpIqwAAAG8"]
[Thu Sep 17 15:13:28.414434 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:37232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxX-OcL08BTTQixEnpIrAAAAAU"]
[Thu Sep 17 15:13:28.429506 2026] [autoindex:error] [pid 971102:tid 971312] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:28.430058 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxX-OcL08BTTQixEnpIrQAAAE4"]
[Thu Sep 17 15:13:28.490625 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/l10n.php"] [unique_id "aqxX-OcL08BTTQixEnpIsAAAABE"]
[Thu Sep 17 15:13:28.490755 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:37856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/l10n.php"] [unique_id "aqxX-OcL08BTTQixEnpIsAAAABE"]
[Thu Sep 17 15:13:28.729915 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxX-OcL08BTTQixEnpItAAAADU"]
[Thu Sep 17 15:13:28.730193 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.221.252:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxX-OcL08BTTQixEnpItQAAAGc"]
[Thu Sep 17 15:13:28.756874 2026] [security2:error] [pid 971102:tid 971358] [client 104.28.198.244:22706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX-OcL08BTTQixEnpItgAAAHw"]
[Thu Sep 17 15:13:28.757038 2026] [security2:error] [pid 971102:tid 971358] [client 104.28.198.244:22706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX-OcL08BTTQixEnpItgAAAHw"]
[Thu Sep 17 15:13:28.786271 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:37870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail-tag.php"] [unique_id "aqxX-OcL08BTTQixEnpIuQAAAE8"]
[Thu Sep 17 15:13:28.786369 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:37870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail-tag.php"] [unique_id "aqxX-OcL08BTTQixEnpIuQAAAE8"]
[Thu Sep 17 15:13:29.018644 2026] [autoindex:error] [pid 971102:tid 971272] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:29.019162 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxX-ecL08BTTQixEnpIvQAAACY"]
[Thu Sep 17 15:13:29.131990 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.130.148:37244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxX-ecL08BTTQixEnpIwAAAAB4"]
[Thu Sep 17 15:13:29.133008 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:37872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail.php"] [unique_id "aqxX-ecL08BTTQixEnpIwQAAAHI"]
[Thu Sep 17 15:13:29.133093 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:37872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail.php"] [unique_id "aqxX-ecL08BTTQixEnpIwQAAAHI"]
[Thu Sep 17 15:13:29.240476 2026] [security2:error] [pid 971102:tid 971323] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/blocks/"] [unique_id "aqxX-ecL08BTTQixEnpIwgAAAFk"]
[Thu Sep 17 15:13:29.243956 2026] [security2:error] [pid 971102:tid 971341] [client 167.99.159.16:33366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX-ecL08BTTQixEnpIvwAAAGs"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:29.423307 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:37880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pipe.php"] [unique_id "aqxX-ecL08BTTQixEnpIxgAAAFg"]
[Thu Sep 17 15:13:29.423454 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:37880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pipe.php"] [unique_id "aqxX-ecL08BTTQixEnpIxgAAAFg"]
[Thu Sep 17 15:13:29.424266 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.221.252:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/test.php"] [unique_id "aqxX-ecL08BTTQixEnpIyAAAAAM"]
[Thu Sep 17 15:13:29.435653 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxX-ecL08BTTQixEnpIxwAAAAA"]
[Thu Sep 17 15:13:29.638647 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/certificates/"] [unique_id "aqxX-ecL08BTTQixEnpIzwAAAGM"]
[Thu Sep 17 15:13:29.714274 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pocket-holder.php"] [unique_id "aqxX-ecL08BTTQixEnpI0AAAAA4"]
[Thu Sep 17 15:13:29.714382 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pocket-holder.php"] [unique_id "aqxX-ecL08BTTQixEnpI0AAAAA4"]
[Thu Sep 17 15:13:29.781984 2026] [security2:error] [pid 971102:tid 971273] [client 20.244.34.24:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX-ecL08BTTQixEnpI0wAAACc"], referer: binance.com
[Thu Sep 17 15:13:29.834904 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.130.148:37246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxX-ecL08BTTQixEnpI1AAAADo"]
[Thu Sep 17 15:13:29.868751 2026] [autoindex:error] [pid 971102:tid 971274] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:29.869256 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/certificates/"] [unique_id "aqxX-ecL08BTTQixEnpI1QAAACg"]
[Thu Sep 17 15:13:30.003770 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/rest-api.php"] [unique_id "aqxX-ucL08BTTQixEnpI2wAAAHs"]
[Thu Sep 17 15:13:30.003878 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:35440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/rest-api.php"] [unique_id "aqxX-ucL08BTTQixEnpI2wAAAHs"]
[Thu Sep 17 15:13:30.138596 2026] [security2:error] [pid 971102:tid 971265] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/customize/"] [unique_id "aqxX-ucL08BTTQixEnpI3QAAAB8"]
[Thu Sep 17 15:13:30.295960 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:35454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/shortcodes.php"] [unique_id "aqxX-ucL08BTTQixEnpI4gAAAH8"]
[Thu Sep 17 15:13:30.296071 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:35454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/shortcodes.php"] [unique_id "aqxX-ucL08BTTQixEnpI4gAAAH8"]
[Thu Sep 17 15:13:30.351278 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.221.252:35624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/p.php"] [unique_id "aqxX-ucL08BTTQixEnpI5AAAABw"]
[Thu Sep 17 15:13:30.363008 2026] [autoindex:error] [pid 971102:tid 971250] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:30.363610 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/customize/"] [unique_id "aqxX-ucL08BTTQixEnpI4wAAABA"]
[Thu Sep 17 15:13:30.576525 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/special-mail-tags.php"] [unique_id "aqxX-ucL08BTTQixEnpI6wAAAGw"]
[Thu Sep 17 15:13:30.576649 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:35458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/special-mail-tags.php"] [unique_id "aqxX-ucL08BTTQixEnpI6wAAAGw"]
[Thu Sep 17 15:13:30.605736 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:30.605757 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:30.636279 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/fonts/"] [unique_id "aqxX-ucL08BTTQixEnpI7QAAAGg"]
[Thu Sep 17 15:13:30.842761 2026] [autoindex:error] [pid 971102:tid 971317] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:30.843271 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/fonts/"] [unique_id "aqxX-ucL08BTTQixEnpI8QAAAFM"]
[Thu Sep 17 15:13:30.862006 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/submission.php"] [unique_id "aqxX-ucL08BTTQixEnpI8gAAAH4"]
[Thu Sep 17 15:13:30.862124 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:35474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/submission.php"] [unique_id "aqxX-ucL08BTTQixEnpI8gAAAH4"]
[Thu Sep 17 15:13:31.038740 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.221.252:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxX--cL08BTTQixEnpI9gAAAHA"]
[Thu Sep 17 15:13:31.045971 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/images/"] [unique_id "aqxX--cL08BTTQixEnpI9wAAAAo"]
[Thu Sep 17 15:13:31.085779 2026] [autoindex:error] [pid 971102:tid 971271] [client 106.63.26.22:6955] AH01276: Cannot serve directory /home1/vxmhuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:31.151051 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/"] [unique_id "aqxX--cL08BTTQixEnpI-QAAAFE"]
[Thu Sep 17 15:13:31.169248 2026] [security2:error] [pid 971102:tid 971313] [client 169.58.197.253:58755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxX--cL08BTTQixEnpI-gAAAE8"], referer: binance.com
[Thu Sep 17 15:13:31.319131 2026] [autoindex:error] [pid 971102:tid 971348] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:31.319764 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/images/"] [unique_id "aqxX--cL08BTTQixEnpI_QAAAHI"]
[Thu Sep 17 15:13:31.329851 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/"] [unique_id "aqxX--cL08BTTQixEnpI_AAAACY"]
[Thu Sep 17 15:13:31.428395 2026] [core:error] [pid 971102:tid 971260] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:31.428415 2026] [core:error] [pid 971102:tid 971260] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:31.475038 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX--cL08BTTQixEnpJCgAAAAA"]
[Thu Sep 17 15:13:31.550997 2026] [autoindex:error] [pid 971102:tid 971330] [client 85.204.70.116:60250] AH01276: Cannot serve directory /home1/zainridg/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:31.551989 2026] [security2:error] [pid 971102:tid 971330] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/.well-known/"] [unique_id "aqxX--cL08BTTQixEnpJCwAAAGA"]
[Thu Sep 17 15:13:31.715943 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.221.252:35640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxX--cL08BTTQixEnpJEAAAABY"]
[Thu Sep 17 15:13:31.770026 2026] [security2:error] [pid 971102:tid 971286] [client 154.190.208.131:41737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJEgAAADQ"]
[Thu Sep 17 15:13:31.770147 2026] [security2:error] [pid 971102:tid 971286] [client 154.190.208.131:41737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJEgAAADQ"]
[Thu Sep 17 15:13:31.820126 2026] [security2:error] [pid 971102:tid 971273] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/ALFA_DATA/"] [unique_id "aqxX--cL08BTTQixEnpJFQAAACc"]
[Thu Sep 17 15:13:31.852641 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX--cL08BTTQixEnpJDgAAAGM"]
[Thu Sep 17 15:13:31.852671 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX--cL08BTTQixEnpJDgAAAGM"]
[Thu Sep 17 15:13:31.863284 2026] [security2:error] [pid 971102:tid 971351] [client 114.198.138.124:59231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJFgAAAHU"]
[Thu Sep 17 15:13:31.863600 2026] [security2:error] [pid 971102:tid 971351] [client 114.198.138.124:59231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJFgAAAHU"]
[Thu Sep 17 15:13:32.001646 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/js/"] [unique_id "aqxX_OcL08BTTQixEnpJGQAAAE0"]
[Thu Sep 17 15:13:32.144688 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.130.148:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxX_OcL08BTTQixEnpJHAAAAHs"]
[Thu Sep 17 15:13:32.157216 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/js/index.js"] [unique_id "aqxX_OcL08BTTQixEnpJHQAAACo"]
[Thu Sep 17 15:13:32.170041 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJGwAAAEc"]
[Thu Sep 17 15:13:32.170066 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJGwAAAEc"]
[Thu Sep 17 15:13:32.301982 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/"] [unique_id "aqxX_OcL08BTTQixEnpJIAAAADw"]
[Thu Sep 17 15:13:32.427251 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.221.252:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxX_OcL08BTTQixEnpJIgAAAGk"]
[Thu Sep 17 15:13:32.474290 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/"] [unique_id "aqxX_OcL08BTTQixEnpJIwAAABw"]
[Thu Sep 17 15:13:32.535224 2026] [security2:error] [pid 971102:tid 971309] [client 5.189.145.112:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxX_OcL08BTTQixEnpJKAAAAEs"], referer: binance.com
[Thu Sep 17 15:13:32.623040 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/wp-content/plugins/contact-form-7/includes/swv/"] [unique_id "aqxX_OcL08BTTQixEnpJKQAAAEI"]
[Thu Sep 17 15:13:32.637619 2026] [security2:error] [pid 971102:tid 971302] [client 181.91.87.22:19225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJJwAAAEQ"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:32.851024 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.130.148:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxX_OcL08BTTQixEnpJLQAAAAs"]
[Thu Sep 17 15:13:32.979766 2026] [security2:error] [pid 971102:tid 971320] [client 45.169.98.18:62740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_OcL08BTTQixEnpJMAAAAFY"]
[Thu Sep 17 15:13:32.979870 2026] [security2:error] [pid 971102:tid 971320] [client 45.169.98.18:62740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_OcL08BTTQixEnpJMAAAAFY"]
[Thu Sep 17 15:13:32.997219 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJLAAAAEM"]
[Thu Sep 17 15:13:32.997243 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJLAAAAEM"]
[Thu Sep 17 15:13:33.023999 2026] [security2:error] [pid 971102:tid 971291] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/.well-knownold/"] [unique_id "aqxX_ecL08BTTQixEnpJMQAAADk"]
[Thu Sep 17 15:13:33.118026 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.221.252:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxX_ecL08BTTQixEnpJMwAAAG8"]
[Thu Sep 17 15:13:33.141463 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/abstract-rules.php"] [unique_id "aqxX_ecL08BTTQixEnpJNAAAAFM"]
[Thu Sep 17 15:13:33.141575 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/abstract-rules.php"] [unique_id "aqxX_ecL08BTTQixEnpJNAAAAFM"]
[Thu Sep 17 15:13:33.403940 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJNQAAAEE"]
[Thu Sep 17 15:13:33.403970 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJNQAAAEE"]
[Thu Sep 17 15:13:33.430761 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/"] [unique_id "aqxX_ecL08BTTQixEnpJOQAAAFE"]
[Thu Sep 17 15:13:33.477030 2026] [security2:error] [pid 971102:tid 971271] [client 74.7.175.174:42126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gmx.zga.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxX_ecL08BTTQixEnpJPAAAACU"]
[Thu Sep 17 15:13:33.552985 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.130.148:37284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxX_ecL08BTTQixEnpJPwAAAHw"]
[Thu Sep 17 15:13:33.603648 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/"] [unique_id "aqxX_ecL08BTTQixEnpJQAAAAB4"]
[Thu Sep 17 15:13:33.747496 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/wp-content/plugins/contact-form-7/includes/swv/php/"] [unique_id "aqxX_ecL08BTTQixEnpJQgAAAFo"]
[Thu Sep 17 15:13:33.807304 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.221.252:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxX_ecL08BTTQixEnpJQwAAAHg"]
[Thu Sep 17 15:13:33.808371 2026] [security2:error] [pid 971102:tid 971237] [client 4.240.114.86:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxX_ecL08BTTQixEnpJRAAAAAM"], referer: binance.com
[Thu Sep 17 15:13:33.866079 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.116:60250] AH01276: Cannot serve directory /home1/zainridg/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:33.866570 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxX_ecL08BTTQixEnpJRQAAACA"]
[Thu Sep 17 15:13:33.933169 2026] [security2:error] [pid 971102:tid 971343] [client 186.105.232.15:58403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_ecL08BTTQixEnpJSQAAAG0"]
[Thu Sep 17 15:13:33.933277 2026] [security2:error] [pid 971102:tid 971343] [client 186.105.232.15:58403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_ecL08BTTQixEnpJSQAAAG0"]
[Thu Sep 17 15:13:34.090404 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJRgAAAGA"]
[Thu Sep 17 15:13:34.090428 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJRgAAAGA"]
[Thu Sep 17 15:13:34.128108 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/cgi-bin/"] [unique_id "aqxX_ucL08BTTQixEnpJTwAAABY"]
[Thu Sep 17 15:13:34.233884 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/all.php"] [unique_id "aqxX_ucL08BTTQixEnpJUgAAAF8"]
[Thu Sep 17 15:13:34.233986 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/all.php"] [unique_id "aqxX_ucL08BTTQixEnpJUgAAAF8"]
[Thu Sep 17 15:13:34.256760 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.130.148:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxX_ucL08BTTQixEnpJUwAAAFg"]
[Thu Sep 17 15:13:34.340670 2026] [cgid:error] [pid 971102:tid 971281] [client 85.204.70.116:40012] AH01265: stderr from /home1/zainridg/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:13:34.341181 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/cgi-bin/"] [unique_id "aqxX_ucL08BTTQixEnpJVgAAAC8"]
[Thu Sep 17 15:13:34.518007 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.221.252:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxX_ucL08BTTQixEnpJXgAAADo"]
[Thu Sep 17 15:13:34.524866 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/any.php"] [unique_id "aqxX_ucL08BTTQixEnpJXwAAAE0"]
[Thu Sep 17 15:13:34.524992 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:35490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/any.php"] [unique_id "aqxX_ucL08BTTQixEnpJXwAAAE0"]
[Thu Sep 17 15:13:34.539483 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/index/"] [unique_id "aqxX_ucL08BTTQixEnpJYAAAABg"]
[Thu Sep 17 15:13:34.819346 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:35492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/date.php"] [unique_id "aqxX_ucL08BTTQixEnpJZQAAABc"]
[Thu Sep 17 15:13:34.819452 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:35492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/date.php"] [unique_id "aqxX_ucL08BTTQixEnpJZQAAABc"]
[Thu Sep 17 15:13:34.979079 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.130.148:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxX_ucL08BTTQixEnpJaQAAAH0"]
[Thu Sep 17 15:13:35.113292 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/dayofweek.php"] [unique_id "aqxX_-cL08BTTQixEnpJawAAAEQ"]
[Thu Sep 17 15:13:35.113405 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:35496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/dayofweek.php"] [unique_id "aqxX_-cL08BTTQixEnpJawAAAEQ"]
[Thu Sep 17 15:13:35.216813 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.221.252:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxX_-cL08BTTQixEnpJbAAAAEs"]
[Thu Sep 17 15:13:35.404134 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/email.php"] [unique_id "aqxX_-cL08BTTQixEnpJbgAAABA"]
[Thu Sep 17 15:13:35.404305 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:35512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/email.php"] [unique_id "aqxX_-cL08BTTQixEnpJbgAAABA"]
[Thu Sep 17 15:13:35.538970 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_-cL08BTTQixEnpJbQAAADg"]
[Thu Sep 17 15:13:35.538993 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_-cL08BTTQixEnpJbQAAADg"]
[Thu Sep 17 15:13:35.626826 2026] [security2:error] [pid 971102:tid 971284] [client 179.36.194.118:60394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX_-cL08BTTQixEnpJcwAAADI"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:35.683669 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.130.148:45602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxX_-cL08BTTQixEnpJdgAAAAY"]
[Thu Sep 17 15:13:35.693318 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/enum.php"] [unique_id "aqxX_-cL08BTTQixEnpJdwAAAGU"]
[Thu Sep 17 15:13:35.693429 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/enum.php"] [unique_id "aqxX_-cL08BTTQixEnpJdwAAAGU"]
[Thu Sep 17 15:13:35.982350 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/file.php"] [unique_id "aqxX_-cL08BTTQixEnpJfAAAAHA"]
[Thu Sep 17 15:13:35.982468 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:35520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/file.php"] [unique_id "aqxX_-cL08BTTQixEnpJfAAAAHA"]
[Thu Sep 17 15:13:36.159566 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.221.252:36886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxYAOcL08BTTQixEnpJgAAAAFs"]
[Thu Sep 17 15:13:36.247673 2026] [security2:error] [pid 971102:tid 971327] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/id/"] [unique_id "aqxYAOcL08BTTQixEnpJgQAAAF0"]
[Thu Sep 17 15:13:36.273521 2026] [security2:error] [pid 971102:tid 971267] [client 143.244.57.120:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxdate.php"] [unique_id "aqxYAOcL08BTTQixEnpJggAAACE"]
[Thu Sep 17 15:13:36.273618 2026] [security2:error] [pid 971102:tid 971267] [client 143.244.57.120:35528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxdate.php"] [unique_id "aqxYAOcL08BTTQixEnpJggAAACE"]
[Thu Sep 17 15:13:36.388171 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:45610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYAOcL08BTTQixEnpJhwAAAA8"]
[Thu Sep 17 15:13:36.571483 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxfilesize.php"] [unique_id "aqxYAOcL08BTTQixEnpJjAAAAEU"]
[Thu Sep 17 15:13:36.571605 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:35542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxfilesize.php"] [unique_id "aqxYAOcL08BTTQixEnpJjAAAAEU"]
[Thu Sep 17 15:13:36.572258 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAOcL08BTTQixEnpJiAAAABo"]
[Thu Sep 17 15:13:36.572276 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAOcL08BTTQixEnpJiAAAABo"]
[Thu Sep 17 15:13:36.592185 2026] [security2:error] [pid 971102:tid 971324] [client 185.191.171.11:22742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tab-funkenwerk.com"] [uri "/index.html"] [unique_id "aqxYAOcL08BTTQixEnpJjQAAAFo"]
[Thu Sep 17 15:13:36.592331 2026] [security2:error] [pid 971102:tid 971324] [client 185.191.171.11:22742] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tab-funkenwerk.com"] [uri "/index.html"] [unique_id "aqxYAOcL08BTTQixEnpJjQAAAFo"]
[Thu Sep 17 15:13:36.655172 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:53885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAOcL08BTTQixEnpJjgAAAFA"]
[Thu Sep 17 15:13:36.655700 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:53885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAOcL08BTTQixEnpJjgAAAFA"]
[Thu Sep 17 15:13:36.858550 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.221.252:36902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxYAOcL08BTTQixEnpJlQAAACA"]
[Thu Sep 17 15:13:36.864356 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:35548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxitems.php"] [unique_id "aqxYAOcL08BTTQixEnpJlgAAAEY"]
[Thu Sep 17 15:13:36.864471 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:35548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxitems.php"] [unique_id "aqxYAOcL08BTTQixEnpJlgAAAEY"]
[Thu Sep 17 15:13:37.093919 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.130.148:45620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYAecL08BTTQixEnpJnAAAAD0"]
[Thu Sep 17 15:13:37.141768 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/www/"] [unique_id "aqxYAecL08BTTQixEnpJnQAAACg"]
[Thu Sep 17 15:13:37.154305 2026] [security2:error] [pid 971102:tid 971241] [client 115.244.164.14:58701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJngAAAAc"]
[Thu Sep 17 15:13:37.154487 2026] [security2:error] [pid 971102:tid 971241] [client 115.244.164.14:58701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJngAAAAc"]
[Thu Sep 17 15:13:37.155678 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxlength.php"] [unique_id "aqxYAecL08BTTQixEnpJnwAAAF4"]
[Thu Sep 17 15:13:37.155766 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxlength.php"] [unique_id "aqxYAecL08BTTQixEnpJnwAAAF4"]
[Thu Sep 17 15:13:37.455830 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:35568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxnumber.php"] [unique_id "aqxYAecL08BTTQixEnpJpwAAAGk"]
[Thu Sep 17 15:13:37.455939 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:35568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxnumber.php"] [unique_id "aqxYAecL08BTTQixEnpJpwAAAGk"]
[Thu Sep 17 15:13:37.497005 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAecL08BTTQixEnpJoAAAAEc"]
[Thu Sep 17 15:13:37.497033 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAecL08BTTQixEnpJoAAAAEc"]
[Thu Sep 17 15:13:37.522983 2026] [access_compat:error] [pid 971102:tid 971288] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/category
[Thu Sep 17 15:13:37.543987 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.221.252:36914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxYAecL08BTTQixEnpJrQAAAHs"]
[Thu Sep 17 15:13:37.544138 2026] [security2:error] [pid 971102:tid 971351] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bridge2lifeteenhomes.org"] [uri "/index.php"] [unique_id "aqxX_ucL08BTTQixEnpJVwAAAHU"]
[Thu Sep 17 15:13:37.546297 2026] [security2:error] [pid 971102:tid 971349] [client 74.7.228.63:37840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bridge2lifeteenhomes.org"] [uri "/robots.txt"] [unique_id "aqxX_ucL08BTTQixEnpJUAAAcwM"]
[Thu Sep 17 15:13:37.743063 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/mindate.php"] [unique_id "aqxYAecL08BTTQixEnpJrwAAAFI"]
[Thu Sep 17 15:13:37.743197 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:35570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/mindate.php"] [unique_id "aqxYAecL08BTTQixEnpJrwAAAFI"]
[Thu Sep 17 15:13:37.784910 2026] [security2:error] [pid 971102:tid 971277] [client 34.166.130.148:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYAecL08BTTQixEnpJsAAAACs"]
[Thu Sep 17 15:13:37.903967 2026] [security2:error] [pid 971102:tid 971127] [remote 45.157.54.43:10760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtQAAcRc"]
[Thu Sep 17 15:13:37.904214 2026] [security2:error] [pid 971102:tid 971347] [client 45.157.54.43:10760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtQAAcRc"]
[Thu Sep 17 15:13:37.931101 2026] [security2:error] [pid 971102:tid 971275] [client 185.55.149.49:60237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtgAAACk"]
[Thu Sep 17 15:13:37.931218 2026] [security2:error] [pid 971102:tid 971275] [client 185.55.149.49:60237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtgAAACk"]
[Thu Sep 17 15:13:37.951498 2026] [security2:error] [pid 971102:tid 971356] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/web/"] [unique_id "aqxYAecL08BTTQixEnpJuQAAAHo"]
[Thu Sep 17 15:13:38.038688 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minfilesize.php"] [unique_id "aqxYAucL08BTTQixEnpJuwAAACc"]
[Thu Sep 17 15:13:38.038851 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:35582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minfilesize.php"] [unique_id "aqxYAucL08BTTQixEnpJuwAAACc"]
[Thu Sep 17 15:13:38.110437 2026] [security2:error] [pid 971102:tid 971315] [client 147.182.136.147:57301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxYAucL08BTTQixEnpJvAAAAFE"]
[Thu Sep 17 15:13:38.223362 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.221.252:36920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxYAucL08BTTQixEnpJvgAAAGc"]
[Thu Sep 17 15:13:38.260345 2026] [security2:error] [pid 971102:tid 971350] [client 147.182.136.147:57321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/"] [unique_id "aqxYAucL08BTTQixEnpJvwAAAHQ"]
[Thu Sep 17 15:13:38.317032 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:35592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minitems.php"] [unique_id "aqxYAucL08BTTQixEnpJwwAAADc"]
[Thu Sep 17 15:13:38.317140 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:35592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minitems.php"] [unique_id "aqxYAucL08BTTQixEnpJwwAAADc"]
[Thu Sep 17 15:13:38.407352 2026] [security2:error] [pid 971102:tid 971260] [client 147.182.136.147:57328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxYAucL08BTTQixEnpJxQAAABo"]
[Thu Sep 17 15:13:38.485337 2026] [security2:error] [pid 971102:tid 971129] [remote 45.157.54.43:11542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAucL08BTTQixEnpJyQAAChk"]
[Thu Sep 17 15:13:38.485518 2026] [security2:error] [pid 971102:tid 971244] [client 45.157.54.43:11542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAucL08BTTQixEnpJyQAAChk"]
[Thu Sep 17 15:13:38.488620 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:45646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYAucL08BTTQixEnpJygAAADs"]
[Thu Sep 17 15:13:38.587243 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAucL08BTTQixEnpJxgAAAFo"]
[Thu Sep 17 15:13:38.587272 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAucL08BTTQixEnpJxgAAAFo"]
[Thu Sep 17 15:13:38.610132 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:35600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minlength.php"] [unique_id "aqxYAucL08BTTQixEnpJzQAAAC0"]
[Thu Sep 17 15:13:38.610255 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:35600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minlength.php"] [unique_id "aqxYAucL08BTTQixEnpJzQAAAC0"]
[Thu Sep 17 15:13:38.904775 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minnumber.php"] [unique_id "aqxYAucL08BTTQixEnpJ0wAAAF4"]
[Thu Sep 17 15:13:38.904907 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minnumber.php"] [unique_id "aqxYAucL08BTTQixEnpJ0wAAAF4"]
[Thu Sep 17 15:13:38.904979 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.221.252:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxYAucL08BTTQixEnpJ1AAAAFk"]
[Thu Sep 17 15:13:38.943061 2026] [security2:error] [pid 971102:tid 971292] [client 5.189.145.112:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxYAucL08BTTQixEnpJ1QAAADo"], referer: binance.com
[Thu Sep 17 15:13:38.990554 2026] [security2:error] [pid 971102:tid 971326] [client 210.222.43.21:57826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYAucL08BTTQixEnpJ0AAAAFw"], referer: http://talent-in-borders.com/Www
[Thu Sep 17 15:13:39.143455 2026] [security2:error] [pid 971102:tid 971322] [client 4.240.114.86:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxYA-cL08BTTQixEnpJ2wAAAFg"], referer: binance.com
[Thu Sep 17 15:13:39.193181 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:35618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/number.php"] [unique_id "aqxYA-cL08BTTQixEnpJ3gAAAEc"]
[Thu Sep 17 15:13:39.193277 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:35618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/number.php"] [unique_id "aqxYA-cL08BTTQixEnpJ3gAAAEc"]
[Thu Sep 17 15:13:39.198905 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.130.148:45654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYA-cL08BTTQixEnpJ3wAAAC4"]
[Thu Sep 17 15:13:39.296221 2026] [security2:error] [pid 971102:tid 971229] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYA-cL08BTTQixEnpJ4wAABHw"]
[Thu Sep 17 15:13:39.474809 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:35620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/required.php"] [unique_id "aqxYA-cL08BTTQixEnpJ7AAAAEI"]
[Thu Sep 17 15:13:39.474933 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:35620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/required.php"] [unique_id "aqxYA-cL08BTTQixEnpJ7AAAAEI"]
[Thu Sep 17 15:13:39.515982 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/uploads/"] [unique_id "aqxYA-cL08BTTQixEnpJ7QAAAEQ"]
[Thu Sep 17 15:13:39.598058 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.221.252:36938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8AAAADQ"]
[Thu Sep 17 15:13:39.756825 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/requiredfile.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8wAAAGU"]
[Thu Sep 17 15:13:39.756927 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/requiredfile.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8wAAAGU"]
[Thu Sep 17 15:13:39.893894 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:45658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYA-cL08BTTQixEnpJ-wAAAFI"]
[Thu Sep 17 15:13:39.894155 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8gAAAAs"]
[Thu Sep 17 15:13:39.894173 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8gAAAAs"]
[Thu Sep 17 15:13:40.089988 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:49000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/stepnumber.php"] [unique_id "aqxYBOcL08BTTQixEnpJ_wAAAE4"]
[Thu Sep 17 15:13:40.090111 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:49000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/stepnumber.php"] [unique_id "aqxYBOcL08BTTQixEnpJ_wAAAE4"]
[Thu Sep 17 15:13:40.356910 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/upload/"] [unique_id "aqxYBOcL08BTTQixEnpKAwAAABM"]
[Thu Sep 17 15:13:40.382477 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:49008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/tel.php"] [unique_id "aqxYBOcL08BTTQixEnpKBAAAAB4"]
[Thu Sep 17 15:13:40.382642 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:49008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/tel.php"] [unique_id "aqxYBOcL08BTTQixEnpKBAAAAB4"]
[Thu Sep 17 15:13:40.593881 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.130.148:45660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYBOcL08BTTQixEnpKDAAAAEw"]
[Thu Sep 17 15:13:40.673810 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/time.php"] [unique_id "aqxYBOcL08BTTQixEnpKDQAAAAA"]
[Thu Sep 17 15:13:40.673950 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:49020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/time.php"] [unique_id "aqxYBOcL08BTTQixEnpKDQAAAAA"]
[Thu Sep 17 15:13:40.691109 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBOcL08BTTQixEnpKCQAAABo"]
[Thu Sep 17 15:13:40.691136 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBOcL08BTTQixEnpKCQAAABo"]
[Thu Sep 17 15:13:40.760016 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.221.252:36952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYBOcL08BTTQixEnpKDgAAAG0"]
[Thu Sep 17 15:13:40.851768 2026] [security2:error] [pid 971102:tid 971321] [client 93.92.20.248:45325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxYBOcL08BTTQixEnpKEQAAAFc"]
[Thu Sep 17 15:13:40.957762 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/url.php"] [unique_id "aqxYBOcL08BTTQixEnpKFQAAAHg"]
[Thu Sep 17 15:13:40.957908 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:49028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/url.php"] [unique_id "aqxYBOcL08BTTQixEnpKFQAAAHg"]
[Thu Sep 17 15:13:41.107903 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/uploads/"] [unique_id "aqxYBecL08BTTQixEnpKGgAAAD0"]
[Thu Sep 17 15:13:41.260795 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/schema-holder.php"] [unique_id "aqxYBecL08BTTQixEnpKGwAAADo"]
[Thu Sep 17 15:13:41.260906 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:49044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/schema-holder.php"] [unique_id "aqxYBecL08BTTQixEnpKGwAAADo"]
[Thu Sep 17 15:13:41.281818 2026] [security2:error] [pid 971102:tid 971265] [client 169.58.197.253:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxYBecL08BTTQixEnpKHAAAAB8"], referer: binance.com
[Thu Sep 17 15:13:41.294646 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:45666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYBecL08BTTQixEnpKHQAAAA8"]
[Thu Sep 17 15:13:41.463945 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.221.252:36958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxYBecL08BTTQixEnpKJgAAAFk"]
[Thu Sep 17 15:13:41.469876 2026] [security2:error] [pid 971102:tid 971250] [client 5.69.109.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ6QAAABA"]
[Thu Sep 17 15:13:41.470481 2026] [security2:error] [pid 971102:tid 971240] [client 153.132.77.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYAecL08BTTQixEnpJtAAAAAY"]
[Thu Sep 17 15:13:41.500043 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBecL08BTTQixEnpKHgAAAAE"]
[Thu Sep 17 15:13:41.500072 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBecL08BTTQixEnpKHgAAAAE"]
[Thu Sep 17 15:13:41.502204 2026] [security2:error] [pid 971102:tid 971353] [client 95.70.165.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYAOcL08BTTQixEnpJlwAAAHc"]
[Thu Sep 17 15:13:41.504878 2026] [security2:error] [pid 971102:tid 971355] [client 130.193.230.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ6AAAAHk"]
[Thu Sep 17 15:13:41.571611 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:49046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/script-loader.php"] [unique_id "aqxYBecL08BTTQixEnpKKgAAADQ"]
[Thu Sep 17 15:13:41.571751 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:49046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/script-loader.php"] [unique_id "aqxYBecL08BTTQixEnpKKgAAADQ"]
[Thu Sep 17 15:13:41.851263 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:49052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/swv.php"] [unique_id "aqxYBecL08BTTQixEnpKLgAAAG8"]
[Thu Sep 17 15:13:41.851384 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:49052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/swv.php"] [unique_id "aqxYBecL08BTTQixEnpKLgAAAG8"]
[Thu Sep 17 15:13:41.956524 2026] [security2:error] [pid 971102:tid 971319] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Admin/uploads/"] [unique_id "aqxYBecL08BTTQixEnpKMwAAAFU"]
[Thu Sep 17 15:13:41.964245 2026] [access_compat:error] [pid 971102:tid 971287] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/ancient-jewels-the-mayan-legacy
[Thu Sep 17 15:13:41.987117 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.130.148:45670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYBecL08BTTQixEnpKOQAAAGU"]
[Thu Sep 17 15:13:42.171842 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/upgrade.php"] [unique_id "aqxYBucL08BTTQixEnpKQAAAABo"]
[Thu Sep 17 15:13:42.171989 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:49068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/upgrade.php"] [unique_id "aqxYBucL08BTTQixEnpKQAAAABo"]
[Thu Sep 17 15:13:42.177426 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.221.252:36962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYBucL08BTTQixEnpKQQAAACU"]
[Thu Sep 17 15:13:42.288680 2026] [security2:error] [pid 971102:tid 971124] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYBucL08BTTQixEnpKQwAACxQ"]
[Thu Sep 17 15:13:42.308869 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKPgAAAD4"]
[Thu Sep 17 15:13:42.308906 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKPgAAAD4"]
[Thu Sep 17 15:13:42.325414 2026] [security2:error] [pid 971102:tid 971282] [client 154.190.208.131:42343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKRAAAADA"]
[Thu Sep 17 15:13:42.325537 2026] [security2:error] [pid 971102:tid 971282] [client 154.190.208.131:42343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKRAAAADA"]
[Thu Sep 17 15:13:42.508734 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation-functions.php"] [unique_id "aqxYBucL08BTTQixEnpKSQAAAEY"]
[Thu Sep 17 15:13:42.508887 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:49084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation-functions.php"] [unique_id "aqxYBucL08BTTQixEnpKSQAAAEY"]
[Thu Sep 17 15:13:42.664109 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/"] [unique_id "aqxYBucL08BTTQixEnpKTAAAABs"]
[Thu Sep 17 15:13:42.709408 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.130.148:45684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYBucL08BTTQixEnpKTQAAAGs"]
[Thu Sep 17 15:13:42.793751 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation.php"] [unique_id "aqxYBucL08BTTQixEnpKTgAAAHw"]
[Thu Sep 17 15:13:42.793872 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:49086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation.php"] [unique_id "aqxYBucL08BTTQixEnpKTgAAAHw"]
[Thu Sep 17 15:13:42.806955 2026] [security2:error] [pid 971102:tid 971344] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKSwAAbgs"], referer: http://missglitterteaches.com/new/
[Thu Sep 17 15:13:42.862657 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.221.252:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYBucL08BTTQixEnpKUgAAAEE"]
[Thu Sep 17 15:13:42.923955 2026] [security2:error] [pid 971102:tid 971248] [client 114.198.138.124:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKVQAAAA4"]
[Thu Sep 17 15:13:42.924173 2026] [security2:error] [pid 971102:tid 971248] [client 114.198.138.124:58162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKVQAAAA4"]
[Thu Sep 17 15:13:42.996875 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKUwAAAHY"]
[Thu Sep 17 15:13:42.996903 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKUwAAAHY"]
[Thu Sep 17 15:13:43.092387 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:49090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/languages/"] [unique_id "aqxYB-cL08BTTQixEnpKWgAAAD8"]
[Thu Sep 17 15:13:43.246628 2026] [security2:error] [pid 971102:tid 971359] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKWAAAfSw"], referer: http://missglitterteaches.com/wordpress/
[Thu Sep 17 15:13:43.308237 2026] [security2:error] [pid 971102:tid 971306] [client 4.240.114.86:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/party.php"] [unique_id "aqxYB-cL08BTTQixEnpKXwAAAEg"], referer: binance.com
[Thu Sep 17 15:13:43.422261 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.130.148:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYB-cL08BTTQixEnpKYwAAAHc"]
[Thu Sep 17 15:13:43.472455 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:63364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYB-cL08BTTQixEnpKZQAAADg"]
[Thu Sep 17 15:13:43.472562 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:63364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYB-cL08BTTQixEnpKZQAAADg"]
[Thu Sep 17 15:13:43.553679 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.221.252:36972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYB-cL08BTTQixEnpKagAAADQ"]
[Thu Sep 17 15:13:43.583977 2026] [security2:error] [pid 971102:tid 971288] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKYgAANis"], referer: http://missglitterteaches.com/wp/
[Thu Sep 17 15:13:43.641206 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/languages/"] [unique_id "aqxYB-cL08BTTQixEnpKbAAAABg"]
[Thu Sep 17 15:13:43.788526 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:49090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/languages/wp-content/plugins/contact-form-7/"] [unique_id "aqxYB-cL08BTTQixEnpKcAAAAB4"]
[Thu Sep 17 15:13:44.005896 2026] [security2:error] [pid 971102:tid 971346] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKbgAAcA0"], referer: http://missglitterteaches.com/old/
[Thu Sep 17 15:13:44.126900 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.130.148:47218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYCOcL08BTTQixEnpKegAAACM"]
[Thu Sep 17 15:13:44.195370 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKdQAAAC8"]
[Thu Sep 17 15:13:44.195407 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKdQAAAC8"]
[Thu Sep 17 15:13:44.244387 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.221.252:40192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYCOcL08BTTQixEnpKfQAAACY"]
[Thu Sep 17 15:13:44.378637 2026] [security2:error] [pid 971102:tid 971234] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYCOcL08BTTQixEnpKewAAABU"], referer: http://missglitterteaches.com/blog/
[Thu Sep 17 15:13:44.523201 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/load.php"] [unique_id "aqxYCOcL08BTTQixEnpKhwAAAF8"]
[Thu Sep 17 15:13:44.523310 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:49090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/load.php"] [unique_id "aqxYCOcL08BTTQixEnpKhwAAAF8"]
[Thu Sep 17 15:13:44.722972 2026] [security2:error] [pid 971102:tid 971282] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYCOcL08BTTQixEnpKhgAAMEA"], referer: http://missglitterteaches.com/backup/
[Thu Sep 17 15:13:44.821294 2026] [security2:error] [pid 971102:tid 971360] [client 186.105.232.15:58994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYCOcL08BTTQixEnpKiAAAAH4"]
[Thu Sep 17 15:13:44.821402 2026] [security2:error] [pid 971102:tid 971360] [client 186.105.232.15:58994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYCOcL08BTTQixEnpKiAAAAH4"]
[Thu Sep 17 15:13:44.839314 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:47230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYCOcL08BTTQixEnpKjQAAAGI"]
[Thu Sep 17 15:13:44.856678 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:49106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYCOcL08BTTQixEnpKjgAAAAs"]
[Thu Sep 17 15:13:44.939512 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.221.252:40194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYCOcL08BTTQixEnpKkQAAAF4"]
[Thu Sep 17 15:13:45.062134 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYCOcL08BTTQixEnpKlAAAAGs"]
[Thu Sep 17 15:13:45.202507 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:49106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/wp-content/plugins/contact-form-7/"] [unique_id "aqxYCecL08BTTQixEnpKlgAAAEE"]
[Thu Sep 17 15:13:45.531289 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.130.148:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYCecL08BTTQixEnpKrAAAABE"]
[Thu Sep 17 15:13:45.595472 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCecL08BTTQixEnpKpgAAAHU"]
[Thu Sep 17 15:13:45.595492 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCecL08BTTQixEnpKpgAAAHU"]
[Thu Sep 17 15:13:45.623455 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.221.252:40208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYCecL08BTTQixEnpKrgAAAHk"]
[Thu Sep 17 15:13:45.740978 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/acceptance.php"] [unique_id "aqxYCecL08BTTQixEnpKsAAAACs"]
[Thu Sep 17 15:13:45.741094 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:49106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/acceptance.php"] [unique_id "aqxYCecL08BTTQixEnpKsAAAACs"]
[Thu Sep 17 15:13:45.965857 2026] [security2:error] [pid 971102:tid 971246] [client 17.166.154.156:56940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYCecL08BTTQixEnpKsQAADEk"]
[Thu Sep 17 15:13:46.027921 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:49112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/"] [unique_id "aqxYCucL08BTTQixEnpKvgAAAEs"]
[Thu Sep 17 15:13:46.133918 2026] [security2:error] [pid 971102:tid 971284] [client 5.189.145.112:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxYCucL08BTTQixEnpKwAAAADI"], referer: binance.com
[Thu Sep 17 15:13:46.184594 2026] [security2:error] [pid 971102:tid 971179] [remote 128.1.120.151:41188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "mavenme.com"] [uri "/"] [unique_id "aqxYCucL08BTTQixEnpKxQAABEs"]
[Thu Sep 17 15:13:46.188503 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/"] [unique_id "aqxYCucL08BTTQixEnpKwgAAAHA"]
[Thu Sep 17 15:13:46.206771 2026] [core:error] [pid 971102:tid 971314] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:46.206786 2026] [core:error] [pid 971102:tid 971314] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:46.245311 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:47248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYCucL08BTTQixEnpKxwAAACE"]
[Thu Sep 17 15:13:46.321245 2026] [security2:error] [pid 971102:tid 971285] [client 34.166.221.252:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYCucL08BTTQixEnpKyAAAADM"]
[Thu Sep 17 15:13:46.330038 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:49112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYCucL08BTTQixEnpKyQAAACU"]
[Thu Sep 17 15:13:46.685186 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCucL08BTTQixEnpKzgAAAFc"]
[Thu Sep 17 15:13:46.685213 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCucL08BTTQixEnpKzgAAAFc"]
[Thu Sep 17 15:13:46.838642 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/akismet.php"] [unique_id "aqxYCucL08BTTQixEnpK5QAAAFs"]
[Thu Sep 17 15:13:46.838772 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:49112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/akismet.php"] [unique_id "aqxYCucL08BTTQixEnpK5QAAAFs"]
[Thu Sep 17 15:13:46.932036 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.130.148:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYCucL08BTTQixEnpK6AAAAEk"]
[Thu Sep 17 15:13:47.011476 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.221.252:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYC-cL08BTTQixEnpK7QAAAF4"]
[Thu Sep 17 15:13:47.115704 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/service.php"] [unique_id "aqxYC-cL08BTTQixEnpK8AAAABk"]
[Thu Sep 17 15:13:47.115824 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:49126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/service.php"] [unique_id "aqxYC-cL08BTTQixEnpK8AAAABk"]
[Thu Sep 17 15:13:47.235465 2026] [security2:error] [pid 971102:tid 971324] [client 156.192.234.52:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpK8gAAAFo"]
[Thu Sep 17 15:13:47.236120 2026] [security2:error] [pid 971102:tid 971324] [client 156.192.234.52:54513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpK8gAAAFo"]
[Thu Sep 17 15:13:47.395714 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/checkbox.php"] [unique_id "aqxYC-cL08BTTQixEnpK9gAAAC4"]
[Thu Sep 17 15:13:47.395830 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:49136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/checkbox.php"] [unique_id "aqxYC-cL08BTTQixEnpK9gAAAC4"]
[Thu Sep 17 15:13:47.615945 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.130.148:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYC-cL08BTTQixEnpK_QAAABA"]
[Thu Sep 17 15:13:47.684525 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:49142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/"] [unique_id "aqxYC-cL08BTTQixEnpLAQAAAHA"]
[Thu Sep 17 15:13:47.699801 2026] [security2:error] [pid 971102:tid 971306] [client 115.244.164.14:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpLAgAAAEg"]
[Thu Sep 17 15:13:47.699916 2026] [security2:error] [pid 971102:tid 971306] [client 115.244.164.14:59356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpLAgAAAEg"]
[Thu Sep 17 15:13:47.704410 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.221.252:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYC-cL08BTTQixEnpLAwAAAHo"]
[Thu Sep 17 15:13:47.873591 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/"] [unique_id "aqxYC-cL08BTTQixEnpLBwAAADM"]
[Thu Sep 17 15:13:48.017087 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:49142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYDOcL08BTTQixEnpLDAAAAAA"]
[Thu Sep 17 15:13:48.319545 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.130.148:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYDOcL08BTTQixEnpLEwAAACo"]
[Thu Sep 17 15:13:48.386194 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYDOcL08BTTQixEnpLDQAAAF8"]
[Thu Sep 17 15:13:48.386216 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYDOcL08BTTQixEnpLDQAAAF8"]
[Thu Sep 17 15:13:48.388735 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.221.252:40246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYDOcL08BTTQixEnpLFgAAAEU"]
[Thu Sep 17 15:13:48.482457 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:36168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zainridgecondo.org"] [uri "/wp-admin/index.php"] [unique_id "aqxYCOcL08BTTQixEnpKfAAAAEo"]
[Thu Sep 17 15:13:48.536652 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/constant-contact.php"] [unique_id "aqxYDOcL08BTTQixEnpLHAAAAAM"]
[Thu Sep 17 15:13:48.536829 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:49142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/constant-contact.php"] [unique_id "aqxYDOcL08BTTQixEnpLHAAAAAM"]
[Thu Sep 17 15:13:48.647033 2026] [security2:error] [pid 971102:tid 971295] [client 185.55.149.49:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYDOcL08BTTQixEnpLHwAAAD0"]
[Thu Sep 17 15:13:48.647162 2026] [security2:error] [pid 971102:tid 971295] [client 185.55.149.49:63956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYDOcL08BTTQixEnpLHwAAAD0"]
[Thu Sep 17 15:13:48.703459 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:36168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYDOcL08BTTQixEnpLIAAAAAc"]
[Thu Sep 17 15:13:48.703633 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:36168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYDOcL08BTTQixEnpLIAAAAAc"]
[Thu Sep 17 15:13:48.832975 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:49152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/count.php"] [unique_id "aqxYDOcL08BTTQixEnpLIQAAAGk"]
[Thu Sep 17 15:13:48.833109 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:49152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/count.php"] [unique_id "aqxYDOcL08BTTQixEnpLIQAAAGk"]
[Thu Sep 17 15:13:49.013149 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.130.148:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYDecL08BTTQixEnpLJAAAAFw"]
[Thu Sep 17 15:13:49.095450 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.221.252:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYDecL08BTTQixEnpLJwAAAAk"]
[Thu Sep 17 15:13:49.134046 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/date.php"] [unique_id "aqxYDecL08BTTQixEnpLKAAAADE"]
[Thu Sep 17 15:13:49.134175 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:49158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/date.php"] [unique_id "aqxYDecL08BTTQixEnpLKAAAADE"]
[Thu Sep 17 15:13:49.148939 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/images/"] [unique_id "aqxYDecL08BTTQixEnpLKQAAAE8"]
[Thu Sep 17 15:13:49.308141 2026] [security2:error] [pid 971102:tid 971207] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYDecL08BTTQixEnpLKgAALmY"]
[Thu Sep 17 15:13:49.410516 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/disallowed-list.php"] [unique_id "aqxYDecL08BTTQixEnpLKwAAAHY"]
[Thu Sep 17 15:13:49.410626 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:49172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/disallowed-list.php"] [unique_id "aqxYDecL08BTTQixEnpLKwAAAHY"]
[Thu Sep 17 15:13:49.440888 2026] [security2:error] [pid 971102:tid 971249] [client 71.164.83.186:55130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "copichristianschool.org"] [uri "/.env"] [unique_id "aqxYDecL08BTTQixEnpLLgAAAA8"]
[Thu Sep 17 15:13:49.699746 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:49174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/doi-helper.php"] [unique_id "aqxYDecL08BTTQixEnpLMAAAABc"]
[Thu Sep 17 15:13:49.699873 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:49174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/doi-helper.php"] [unique_id "aqxYDecL08BTTQixEnpLMAAAABc"]
[Thu Sep 17 15:13:49.726251 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47292] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:49.726270 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47292] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:49.808930 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.221.252:40262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYDecL08BTTQixEnpLMwAAAH0"]
[Thu Sep 17 15:13:49.810413 2026] [security2:error] [pid 971102:tid 971222] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYDecL08BTTQixEnpLNAAAf3U"]
[Thu Sep 17 15:13:49.824078 2026] [security2:error] [pid 971102:tid 971262] [client 71.164.83.186:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "copichurch.org"] [uri "/.env"] [unique_id "aqxYDecL08BTTQixEnpLNQAAABw"]
[Thu Sep 17 15:13:49.990637 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/file.php"] [unique_id "aqxYDecL08BTTQixEnpLOQAAAFA"]
[Thu Sep 17 15:13:49.990759 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:34208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/file.php"] [unique_id "aqxYDecL08BTTQixEnpLOQAAAFA"]
[Thu Sep 17 15:13:50.021550 2026] [fcgid:warn] [pid 971102:tid 971278] (70014)End of file found: [client 152.32.158.219:48908] mod_fcgid: can't get data from http client
[Thu Sep 17 15:13:50.078895 2026] [security2:error] [pid 971102:tid 971351] [client 162.241.226.11:50624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.snowhillstokes.org"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxYDucL08BTTQixEnpLPAAAAHU"]
[Thu Sep 17 15:13:50.202229 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYDecL08BTTQixEnpLMgAAAGU"]
[Thu Sep 17 15:13:50.202257 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYDecL08BTTQixEnpLMgAAAGU"]
[Thu Sep 17 15:13:50.279050 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:34218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/flamingo.php"] [unique_id "aqxYDucL08BTTQixEnpLPgAAADM"]
[Thu Sep 17 15:13:50.279167 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:34218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/flamingo.php"] [unique_id "aqxYDucL08BTTQixEnpLPgAAADM"]
[Thu Sep 17 15:13:50.434356 2026] [core:error] [pid 971102:tid 971287] [client 34.166.130.148:47294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:50.434377 2026] [core:error] [pid 971102:tid 971287] [client 34.166.130.148:47294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:50.492472 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.221.252:40270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYDucL08BTTQixEnpLRgAAAAg"]
[Thu Sep 17 15:13:50.564461 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/hidden.php"] [unique_id "aqxYDucL08BTTQixEnpLRwAAABU"]
[Thu Sep 17 15:13:50.564571 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:34220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/hidden.php"] [unique_id "aqxYDucL08BTTQixEnpLRwAAABU"]
[Thu Sep 17 15:13:50.845121 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/listo.php"] [unique_id "aqxYDucL08BTTQixEnpLUAAAADA"]
[Thu Sep 17 15:13:50.845237 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/listo.php"] [unique_id "aqxYDucL08BTTQixEnpLUAAAADA"]
[Thu Sep 17 15:13:50.915200 2026] [security2:error] [pid 971102:tid 971265] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/assets/"] [unique_id "aqxYDucL08BTTQixEnpLUwAAAB8"]
[Thu Sep 17 15:13:50.980934 2026] [security2:error] [pid 971102:tid 971268] [client 104.28.198.244:22841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYDucL08BTTQixEnpLVgAAACI"]
[Thu Sep 17 15:13:50.981067 2026] [security2:error] [pid 971102:tid 971268] [client 104.28.198.244:22841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYDucL08BTTQixEnpLVgAAACI"]
[Thu Sep 17 15:13:51.120586 2026] [core:error] [pid 971102:tid 971237] [client 34.166.130.148:47300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.120606 2026] [core:error] [pid 971102:tid 971237] [client 34.166.130.148:47300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.122791 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/number.php"] [unique_id "aqxYD-cL08BTTQixEnpLWwAAAF4"]
[Thu Sep 17 15:13:51.122886 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:34236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/number.php"] [unique_id "aqxYD-cL08BTTQixEnpLWwAAAF4"]
[Thu Sep 17 15:13:51.207241 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.221.252:40280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYD-cL08BTTQixEnpLXAAAAGA"]
[Thu Sep 17 15:13:51.413262 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/quiz.php"] [unique_id "aqxYD-cL08BTTQixEnpLXgAAAA0"]
[Thu Sep 17 15:13:51.413356 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:34246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/quiz.php"] [unique_id "aqxYD-cL08BTTQixEnpLXgAAAA0"]
[Thu Sep 17 15:13:51.415835 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLWQAAAA4"]
[Thu Sep 17 15:13:51.415862 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLWQAAAA4"]
[Thu Sep 17 15:13:51.708043 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/really-simple-captcha.php"] [unique_id "aqxYD-cL08BTTQixEnpLYwAAACY"]
[Thu Sep 17 15:13:51.708152 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:34262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/really-simple-captcha.php"] [unique_id "aqxYD-cL08BTTQixEnpLYwAAACY"]
[Thu Sep 17 15:13:51.727505 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxYD-cL08BTTQixEnpLZQAAACA"]
[Thu Sep 17 15:13:51.757485 2026] [security2:error] [pid 971102:tid 971235] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLYgAAATo"]
[Thu Sep 17 15:13:51.837317 2026] [core:error] [pid 971102:tid 971312] [client 34.166.130.148:47302] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.837344 2026] [core:error] [pid 971102:tid 971312] [client 34.166.130.148:47302] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.888251 2026] [security2:error] [pid 971102:tid 971277] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLZwAAKw4"]
[Thu Sep 17 15:13:51.920805 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.221.252:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYD-cL08BTTQixEnpLawAAAGs"]
[Thu Sep 17 15:13:51.987099 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:34266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/recaptcha/"] [unique_id "aqxYD-cL08BTTQixEnpLbwAAABA"]
[Thu Sep 17 15:13:52.097784 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLbgAAADg"]
[Thu Sep 17 15:13:52.097811 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLbgAAADg"]
[Thu Sep 17 15:13:52.147574 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/recaptcha/index.js"] [unique_id "aqxYEOcL08BTTQixEnpLcwAAAH8"]
[Thu Sep 17 15:13:52.152497 2026] [security2:error] [pid 971102:tid 971288] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLcgAANhY"]
[Thu Sep 17 15:13:52.284446 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/reflection.php"] [unique_id "aqxYEOcL08BTTQixEnpLdgAAADw"]
[Thu Sep 17 15:13:52.284567 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/reflection.php"] [unique_id "aqxYEOcL08BTTQixEnpLdgAAADw"]
[Thu Sep 17 15:13:52.364528 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/upload/image/"] [unique_id "aqxYEOcL08BTTQixEnpLdwAAAFA"]
[Thu Sep 17 15:13:52.504477 2026] [security2:error] [pid 971102:tid 971347] [client 173.252.69.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcktax.com"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLewAAAHE"]
[Thu Sep 17 15:13:52.533719 2026] [core:error] [pid 971102:tid 971264] [client 34.166.130.148:47306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:52.533738 2026] [core:error] [pid 971102:tid 971264] [client 34.166.130.148:47306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:52.562590 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/response.php"] [unique_id "aqxYEOcL08BTTQixEnpLgwAAAAg"]
[Thu Sep 17 15:13:52.562738 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:34282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/response.php"] [unique_id "aqxYEOcL08BTTQixEnpLgwAAAAg"]
[Thu Sep 17 15:13:52.619037 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.221.252:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYEOcL08BTTQixEnpLhAAAAHU"]
[Thu Sep 17 15:13:52.679447 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLgAAAADM"]
[Thu Sep 17 15:13:52.679480 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLgAAAADM"]
[Thu Sep 17 15:13:52.768025 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:58829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLhgAAAGQ"]
[Thu Sep 17 15:13:52.768130 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:58829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLhgAAAGQ"]
[Thu Sep 17 15:13:52.833672 2026] [security2:error] [pid 971102:tid 971274] [client 154.190.208.131:41604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLjAAAACg"]
[Thu Sep 17 15:13:52.835815 2026] [security2:error] [pid 971102:tid 971274] [client 154.190.208.131:41604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLjAAAACg"]
[Thu Sep 17 15:13:52.850008 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/assets/images/"] [unique_id "aqxYEOcL08BTTQixEnpLkAAAAAc"]
[Thu Sep 17 15:13:52.860272 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/select.php"] [unique_id "aqxYEOcL08BTTQixEnpLkgAAAGk"]
[Thu Sep 17 15:13:52.860359 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/select.php"] [unique_id "aqxYEOcL08BTTQixEnpLkgAAAGk"]
[Thu Sep 17 15:13:53.150276 2026] [security2:error] [pid 971102:tid 971247] [client 162.241.226.11:11226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.snowhillstokes.org"] [uri "/wp-cron.php"] [unique_id "aqxYEecL08BTTQixEnpLmgAAAA0"]
[Thu Sep 17 15:13:53.179489 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:34294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/"] [unique_id "aqxYEecL08BTTQixEnpLnAAAAHw"]
[Thu Sep 17 15:13:53.234682 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:47312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.234718 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:47312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.303521 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.221.252:40314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYEecL08BTTQixEnpLngAAAHg"]
[Thu Sep 17 15:13:53.320937 2026] [security2:error] [pid 971102:tid 971127] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxYEecL08BTTQixEnpLnwAAJRc"]
[Thu Sep 17 15:13:53.346212 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/"] [unique_id "aqxYEecL08BTTQixEnpLoAAAACA"]
[Thu Sep 17 15:13:53.484858 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:34294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYEecL08BTTQixEnpLqAAAADk"]
[Thu Sep 17 15:13:53.582911 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLoQAAAAE"]
[Thu Sep 17 15:13:53.582937 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLoQAAAAE"]
[Thu Sep 17 15:13:53.759239 2026] [security2:error] [pid 971102:tid 971288] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Public/"] [unique_id "aqxYEecL08BTTQixEnpLrAAAADY"]
[Thu Sep 17 15:13:53.833928 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLqQAAABA"]
[Thu Sep 17 15:13:53.833961 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLqQAAABA"]
[Thu Sep 17 15:13:53.921148 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.921169 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.957075 2026] [security2:error] [pid 971102:tid 971359] [client 45.169.98.18:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEecL08BTTQixEnpLsQAAAH0"]
[Thu Sep 17 15:13:53.957285 2026] [security2:error] [pid 971102:tid 971359] [client 45.169.98.18:63915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEecL08BTTQixEnpLsQAAAH0"]
[Thu Sep 17 15:13:53.975484 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:34294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/contact-form-properties.php"] [unique_id "aqxYEecL08BTTQixEnpLtQAAAHY"]
[Thu Sep 17 15:13:53.975617 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:34294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/contact-form-properties.php"] [unique_id "aqxYEecL08BTTQixEnpLtQAAAHY"]
[Thu Sep 17 15:13:53.991666 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.221.252:40324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYEecL08BTTQixEnpLtgAAADw"]
[Thu Sep 17 15:13:54.088645 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLsgAAAEg"]
[Thu Sep 17 15:13:54.088689 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLsgAAAEg"]
[Thu Sep 17 15:13:54.209772 2026] [security2:error] [pid 971102:tid 971264] [client 5.189.145.112:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxYEucL08BTTQixEnpLuwAAAB4"], referer: binance.com
[Thu Sep 17 15:13:54.255492 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:34308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/doi.php"] [unique_id "aqxYEucL08BTTQixEnpLvAAAAHM"]
[Thu Sep 17 15:13:54.255613 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:34308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/doi.php"] [unique_id "aqxYEucL08BTTQixEnpLvAAAAHM"]
[Thu Sep 17 15:13:54.338958 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/vendor/"] [unique_id "aqxYEucL08BTTQixEnpLvQAAAEU"]
[Thu Sep 17 15:13:54.532264 2026] [security2:error] [pid 971102:tid 971318] [client 162.241.226.11:11232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.snowhillstokes.org"] [uri "/wp-cron.php"] [unique_id "aqxYEucL08BTTQixEnpLwgAAAFQ"]
[Thu Sep 17 15:13:54.532507 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:34320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/sendinblue.php"] [unique_id "aqxYEucL08BTTQixEnpLwwAAAGI"]
[Thu Sep 17 15:13:54.532587 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:34320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/sendinblue.php"] [unique_id "aqxYEucL08BTTQixEnpLwwAAAGI"]
[Thu Sep 17 15:13:54.632124 2026] [core:error] [pid 971102:tid 971296] [client 34.166.130.148:47692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:54.632148 2026] [core:error] [pid 971102:tid 971296] [client 34.166.130.148:47692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:54.690125 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.221.252:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYEucL08BTTQixEnpLyAAAACo"]
[Thu Sep 17 15:13:54.708492 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEucL08BTTQixEnpLwQAAAGw"]
[Thu Sep 17 15:13:54.708524 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEucL08BTTQixEnpLwQAAAGw"]
[Thu Sep 17 15:13:54.816230 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/service.php"] [unique_id "aqxYEucL08BTTQixEnpLywAAADA"]
[Thu Sep 17 15:13:54.816355 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/service.php"] [unique_id "aqxYEucL08BTTQixEnpLywAAADA"]
[Thu Sep 17 15:13:54.915283 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/local/"] [unique_id "aqxYEucL08BTTQixEnpL0AAAAC0"]
[Thu Sep 17 15:13:55.102634 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:34342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/stripe/"] [unique_id "aqxYE-cL08BTTQixEnpL1wAAAAs"]
[Thu Sep 17 15:13:55.258894 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/stripe/index.js"] [unique_id "aqxYE-cL08BTTQixEnpL2QAAAAk"]
[Thu Sep 17 15:13:55.281197 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL2AAAAGM"]
[Thu Sep 17 15:13:55.281228 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL2AAAAGM"]
[Thu Sep 17 15:13:55.339855 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:47694] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:55.339875 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:47694] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:55.384016 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.221.252:46200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYE-cL08BTTQixEnpL3gAAAA0"]
[Thu Sep 17 15:13:55.396752 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:34342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/submit.php"] [unique_id "aqxYE-cL08BTTQixEnpL3wAAAEI"]
[Thu Sep 17 15:13:55.396859 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:34342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/submit.php"] [unique_id "aqxYE-cL08BTTQixEnpL3wAAAEI"]
[Thu Sep 17 15:13:55.505168 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/modules/"] [unique_id "aqxYE-cL08BTTQixEnpL5QAAAAo"]
[Thu Sep 17 15:13:55.691611 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/text.php"] [unique_id "aqxYE-cL08BTTQixEnpL6QAAABc"]
[Thu Sep 17 15:13:55.691782 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:34344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/text.php"] [unique_id "aqxYE-cL08BTTQixEnpL6QAAABc"]
[Thu Sep 17 15:13:55.798797 2026] [security2:error] [pid 971102:tid 971313] [client 40.77.167.71:35608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL5gAATyg"]
[Thu Sep 17 15:13:55.806880 2026] [security2:error] [pid 971102:tid 971270] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL5wAAACQ"]
[Thu Sep 17 15:13:55.806905 2026] [security2:error] [pid 971102:tid 971270] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL5wAAACQ"]
[Thu Sep 17 15:13:55.978983 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:34360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/textarea.php"] [unique_id "aqxYE-cL08BTTQixEnpL8AAAAFM"]
[Thu Sep 17 15:13:55.979079 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:34360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/textarea.php"] [unique_id "aqxYE-cL08BTTQixEnpL8AAAAFM"]
[Thu Sep 17 15:13:56.027376 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Site/"] [unique_id "aqxYFOcL08BTTQixEnpL8gAAACE"]
[Thu Sep 17 15:13:56.049845 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:47702] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.049862 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:47702] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.083726 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.221.252:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYFOcL08BTTQixEnpL9QAAAH0"]
[Thu Sep 17 15:13:56.167811 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFOcL08BTTQixEnpL9gAAAH8"]
[Thu Sep 17 15:13:56.169688 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:59598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFOcL08BTTQixEnpL9gAAAH8"]
[Thu Sep 17 15:13:56.272108 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:34368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/"] [unique_id "aqxYFOcL08BTTQixEnpL-AAAAAg"]
[Thu Sep 17 15:13:56.382083 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpL9wAAAC8"]
[Thu Sep 17 15:13:56.382111 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpL9wAAAC8"]
[Thu Sep 17 15:13:56.430688 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/"] [unique_id "aqxYFOcL08BTTQixEnpL-QAAAFE"]
[Thu Sep 17 15:13:56.581385 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:34368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYFOcL08BTTQixEnpL_gAAADM"]
[Thu Sep 17 15:13:56.604517 2026] [security2:error] [pid 971102:tid 971246] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/system/"] [unique_id "aqxYFOcL08BTTQixEnpL_wAAAAw"]
[Thu Sep 17 15:13:56.659817 2026] [security2:error] [pid 971102:tid 971322] [client 104.234.19.145:62019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/000.php"] [unique_id "aqxYFOcL08BTTQixEnpMAAAAAFg"]
[Thu Sep 17 15:13:56.746198 2026] [core:error] [pid 971102:tid 971351] [client 34.166.130.148:47706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.746221 2026] [core:error] [pid 971102:tid 971351] [client 34.166.130.148:47706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.768070 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.221.252:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYFOcL08BTTQixEnpMBAAAAD0"]
[Thu Sep 17 15:13:56.926054 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMAgAAAHs"]
[Thu Sep 17 15:13:56.926079 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMAgAAAHs"]
[Thu Sep 17 15:13:56.972419 2026] [security2:error] [pid 971102:tid 971286] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMBQAAADQ"]
[Thu Sep 17 15:13:56.972446 2026] [security2:error] [pid 971102:tid 971286] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMBQAAADQ"]
[Thu Sep 17 15:13:57.070853 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:34368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/service.php"] [unique_id "aqxYFecL08BTTQixEnpMDQAAAFc"]
[Thu Sep 17 15:13:57.070955 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:34368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/service.php"] [unique_id "aqxYFecL08BTTQixEnpMDQAAAFc"]
[Thu Sep 17 15:13:57.159564 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/template/"] [unique_id "aqxYFecL08BTTQixEnpMDwAAAGY"]
[Thu Sep 17 15:13:57.244624 2026] [security2:error] [pid 971102:tid 971132] [remote 216.73.217.142:21738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxYFecL08BTTQixEnpMEgAAVBw"]
[Thu Sep 17 15:13:57.365501 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/turnstile.php"] [unique_id "aqxYFecL08BTTQixEnpMFgAAAGg"]
[Thu Sep 17 15:13:57.365620 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:34374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/turnstile.php"] [unique_id "aqxYFecL08BTTQixEnpMFgAAAGg"]
[Thu Sep 17 15:13:57.453638 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.221.252:46244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYFecL08BTTQixEnpMGAAAAB8"]
[Thu Sep 17 15:13:57.459225 2026] [core:error] [pid 971102:tid 971282] [client 34.166.130.148:47720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:57.459240 2026] [core:error] [pid 971102:tid 971282] [client 34.166.130.148:47720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:57.496927 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMFAAAAAM"]
[Thu Sep 17 15:13:57.496952 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMFAAAAAM"]
[Thu Sep 17 15:13:57.652722 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/shop/"] [unique_id "aqxYFecL08BTTQixEnpMHwAAABQ"]
[Thu Sep 17 15:13:57.654840 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/uninstall.php"] [unique_id "aqxYFecL08BTTQixEnpMIAAAAGk"]
[Thu Sep 17 15:13:57.654936 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/uninstall.php"] [unique_id "aqxYFecL08BTTQixEnpMIAAAAGk"]
[Thu Sep 17 15:13:57.880954 2026] [security2:error] [pid 971102:tid 971333] [client 156.192.234.52:55117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFecL08BTTQixEnpMLgAAAGM"]
[Thu Sep 17 15:13:57.881093 2026] [security2:error] [pid 971102:tid 971333] [client 156.192.234.52:55117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFecL08BTTQixEnpMLgAAAGM"]
[Thu Sep 17 15:13:57.937368 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:34396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/wp-contact-form-7.php"] [unique_id "aqxYFecL08BTTQixEnpMLwAAABg"]
[Thu Sep 17 15:13:57.937538 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:34396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/wp-contact-form-7.php"] [unique_id "aqxYFecL08BTTQixEnpMLwAAABg"]
[Thu Sep 17 15:13:57.997266 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMKQAAAGs"]
[Thu Sep 17 15:13:57.997292 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMKQAAAGs"]
[Thu Sep 17 15:13:58.010012 2026] [security2:error] [pid 971102:tid 971239] [client 193.36.224.116:36435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/about.php"] [unique_id "aqxYFucL08BTTQixEnpMNQAAAAU"]
[Thu Sep 17 15:13:58.148134 2026] [core:error] [pid 971102:tid 971290] [client 34.166.130.148:47728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.148154 2026] [core:error] [pid 971102:tid 971290] [client 34.166.130.148:47728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.211904 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/files/"] [unique_id "aqxYFucL08BTTQixEnpMOwAAAAQ"]
[Thu Sep 17 15:13:58.213354 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wordpress/"] [unique_id "aqxYFucL08BTTQixEnpMPAAAAHE"]
[Thu Sep 17 15:13:58.265447 2026] [security2:error] [pid 971102:tid 971242] [client 104.234.19.147:29005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxYFucL08BTTQixEnpMPwAAAAg"]
[Thu Sep 17 15:13:58.327995 2026] [security2:error] [pid 971102:tid 971319] [client 115.244.164.14:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFucL08BTTQixEnpMQQAAAFU"]
[Thu Sep 17 15:13:58.328084 2026] [security2:error] [pid 971102:tid 971319] [client 115.244.164.14:60016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFucL08BTTQixEnpMQQAAAFU"]
[Thu Sep 17 15:13:58.400642 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wordpress/"] [unique_id "aqxYFucL08BTTQixEnpMRAAAAFg"]
[Thu Sep 17 15:13:58.447285 2026] [security2:error] [pid 971102:tid 971329] [client 162.241.226.11:16634] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxYFucL08BTTQixEnpMRgAAAF8"]
[Thu Sep 17 15:13:58.503453 2026] [security2:error] [pid 971102:tid 971287] [client 216.24.219.19:42493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxYFucL08BTTQixEnpMSgAAADU"]
[Thu Sep 17 15:13:58.557277 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/images/"] [unique_id "aqxYFucL08BTTQixEnpMSwAAAD4"]
[Thu Sep 17 15:13:58.589304 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMRwAAACw"]
[Thu Sep 17 15:13:58.589336 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMRwAAACw"]
[Thu Sep 17 15:13:58.754756 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/editor/"] [unique_id "aqxYFucL08BTTQixEnpMTwAAAEs"]
[Thu Sep 17 15:13:58.788033 2026] [security2:error] [pid 971102:tid 971330] [client 104.234.19.152:45283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxYFucL08BTTQixEnpMUAAAAGA"]
[Thu Sep 17 15:13:58.850569 2026] [core:error] [pid 971102:tid 971321] [client 34.166.130.148:47744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.850587 2026] [core:error] [pid 971102:tid 971321] [client 34.166.130.148:47744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.853836 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/images/"] [unique_id "aqxYFucL08BTTQixEnpMTgAAAFk"]
[Thu Sep 17 15:13:58.992300 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYFucL08BTTQixEnpMWQAAADE"]
[Thu Sep 17 15:13:59.071011 2026] [security2:error] [pid 971102:tid 971358] [client 193.36.224.149:60025] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxYF-cL08BTTQixEnpMWwAAAHw"]
[Thu Sep 17 15:13:59.085796 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMVgAAABk"]
[Thu Sep 17 15:13:59.085825 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMVgAAABk"]
[Thu Sep 17 15:13:59.255750 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/include/"] [unique_id "aqxYF-cL08BTTQixEnpMYAAAACk"]
[Thu Sep 17 15:13:59.345856 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMXQAAAAk"]
[Thu Sep 17 15:13:59.345888 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMXQAAAAk"]
[Thu Sep 17 15:13:59.395343 2026] [security2:error] [pid 971102:tid 971272] [client 193.36.224.148:65063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/bless.php"] [unique_id "aqxYF-cL08BTTQixEnpMYgAAACY"]
[Thu Sep 17 15:13:59.424220 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:52293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYF-cL08BTTQixEnpMZQAAAAM"]
[Thu Sep 17 15:13:59.424313 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:52293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYF-cL08BTTQixEnpMZQAAAAM"]
[Thu Sep 17 15:13:59.483553 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxYF-cL08BTTQixEnpMbAAAAFw"]
[Thu Sep 17 15:13:59.600754 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMZwAAAEo"]
[Thu Sep 17 15:13:59.600784 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMZwAAAEo"]
[Thu Sep 17 15:13:59.605133 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:59.605152 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:59.699030 2026] [security2:error] [pid 971102:tid 971317] [client 216.24.219.104:34591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/goods.php"] [unique_id "aqxYF-cL08BTTQixEnpMeAAAAFM"]
[Thu Sep 17 15:13:59.827648 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Assets/"] [unique_id "aqxYF-cL08BTTQixEnpMegAAAH8"]
[Thu Sep 17 15:13:59.837020 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMcwAAAHY"]
[Thu Sep 17 15:13:59.837042 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMcwAAAHY"]
[Thu Sep 17 15:14:00.017911 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/js/"] [unique_id "aqxYGOcL08BTTQixEnpMfwAAAFE"]
[Thu Sep 17 15:14:00.128035 2026] [security2:error] [pid 971102:tid 971249] [client 102.129.223.92:3765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.223.129.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vedur.app"] [uri "/wp-login.php"] [unique_id "aqxYGOcL08BTTQixEnpMgQAAAA8"], referer: http://vedur.app
[Thu Sep 17 15:14:00.179036 2026] [security2:error] [pid 971102:tid 971335] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgAAAAGU"]
[Thu Sep 17 15:14:00.179061 2026] [security2:error] [pid 971102:tid 971335] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgAAAAGU"]
[Thu Sep 17 15:14:00.350712 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgwAAAA0"]
[Thu Sep 17 15:14:00.350734 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgwAAAA0"]
[Thu Sep 17 15:14:00.361516 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/images/stories/"] [unique_id "aqxYGOcL08BTTQixEnpMiAAAAC0"]
[Thu Sep 17 15:14:00.489517 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYGOcL08BTTQixEnpMiwAAAHU"]
[Thu Sep 17 15:14:00.510269 2026] [security2:error] [pid 971102:tid 971289] [client 104.28.198.244:22805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYGOcL08BTTQixEnpMjQAAADc"]
[Thu Sep 17 15:14:00.510364 2026] [security2:error] [pid 971102:tid 971289] [client 104.28.198.244:22805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYGOcL08BTTQixEnpMjQAAADc"]
[Thu Sep 17 15:14:00.693080 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMjwAAABY"]
[Thu Sep 17 15:14:00.693104 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMjwAAABY"]
[Thu Sep 17 15:14:00.770308 2026] [authz_core:error] [pid 971102:tid 971282] [client 169.58.197.253:60574] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:14:00.889639 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMkgAAABk"]
[Thu Sep 17 15:14:00.889668 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMkgAAABk"]
[Thu Sep 17 15:14:00.909334 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/plugins/"] [unique_id "aqxYGOcL08BTTQixEnpMmAAAACA"]
[Thu Sep 17 15:14:00.980838 2026] [security2:error] [pid 971102:tid 971324] [client 216.24.219.20:32177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/blurbs.php"] [unique_id "aqxYGOcL08BTTQixEnpMnAAAAFo"]
[Thu Sep 17 15:14:01.028796 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYGecL08BTTQixEnpMnQAAAG4"]
[Thu Sep 17 15:14:01.267267 2026] [security2:error] [pid 971102:tid 971270] [client 104.234.19.143:51971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxYGecL08BTTQixEnpMpgAAACQ"]
[Thu Sep 17 15:14:01.287308 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMogAAAAo"]
[Thu Sep 17 15:14:01.287336 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMogAAAAo"]
[Thu Sep 17 15:14:01.430230 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMowAAAGM"]
[Thu Sep 17 15:14:01.430256 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMowAAAGM"]
[Thu Sep 17 15:14:01.451517 2026] [security2:error] [pid 971102:tid 971305] [client 47.79.200.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMoAAAAEc"], referer: https://www.google.com/
[Thu Sep 17 15:14:01.494911 2026] [core:error] [pid 971102:tid 971171] [remote 57.141.14.66:25080] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:01.494927 2026] [core:error] [pid 971102:tid 971171] [remote 57.141.14.66:25080] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:01.521202 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/php/"] [unique_id "aqxYGecL08BTTQixEnpMqwAAAGk"]
[Thu Sep 17 15:14:01.571296 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/meta/"] [unique_id "aqxYGecL08BTTQixEnpMrQAAAFM"]
[Thu Sep 17 15:14:01.762420 2026] [security2:error] [pid 971102:tid 971145] [remote 216.73.217.142:21738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxYGecL08BTTQixEnpMsQAAFyk"]
[Thu Sep 17 15:14:01.791981 2026] [security2:error] [pid 971102:tid 971359] [client 216.24.219.97:54485] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/abcd.php"] [unique_id "aqxYGecL08BTTQixEnpMtQAAAH0"]
[Thu Sep 17 15:14:01.793990 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/meta/"] [unique_id "aqxYGecL08BTTQixEnpMrwAAAAA"]
[Thu Sep 17 15:14:01.869061 2026] [security2:error] [pid 971102:tid 971306] [client 192.178.6.5:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYGecL08BTTQixEnpMtwAAAEg"]
[Thu Sep 17 15:14:01.886233 2026] [security2:error] [pid 971102:tid 971240] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMsAAAAAY"]
[Thu Sep 17 15:14:01.886258 2026] [security2:error] [pid 971102:tid 971240] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMsAAAAAY"]
[Thu Sep 17 15:14:01.934974 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/network/"] [unique_id "aqxYGecL08BTTQixEnpMuAAAAHE"]
[Thu Sep 17 15:14:02.055445 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/"] [unique_id "aqxYGucL08BTTQixEnpMvAAAABA"]
[Thu Sep 17 15:14:02.311893 2026] [autoindex:error] [pid 971102:tid 971299] [client 85.204.70.116:36182] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:02.312580 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/"] [unique_id "aqxYGucL08BTTQixEnpMvwAAAEE"]
[Thu Sep 17 15:14:02.352457 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxYGucL08BTTQixEnpMvQAAAFg"]
[Thu Sep 17 15:14:02.532742 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxYGucL08BTTQixEnpMxQAAACo"]
[Thu Sep 17 15:14:02.701260 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYGucL08BTTQixEnpMxwAAAFk"]
[Thu Sep 17 15:14:02.701406 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYGucL08BTTQixEnpMxwAAAFk"]
[Thu Sep 17 15:14:02.743062 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "aqxYGucL08BTTQixEnpMyAAAAHQ"]
[Thu Sep 17 15:14:02.846921 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/user/"] [unique_id "aqxYGucL08BTTQixEnpMzQAAAFc"]
[Thu Sep 17 15:14:02.924022 2026] [security2:error] [pid 971102:tid 971260] [client 216.24.219.38:30619] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxYGucL08BTTQixEnpMzwAAABo"]
[Thu Sep 17 15:14:02.958913 2026] [security2:error] [pid 971102:tid 971286] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/cache/"] [unique_id "aqxYGucL08BTTQixEnpM0QAAADQ"]
[Thu Sep 17 15:14:03.103093 2026] [security2:error] [pid 971102:tid 971266] [client 5.189.145.112:57924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxYG-cL08BTTQixEnpM1AAAACA"], referer: binance.com
[Thu Sep 17 15:14:03.400237 2026] [security2:error] [pid 971102:tid 971311] [client 193.36.224.116:28211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/dex.php"] [unique_id "aqxYG-cL08BTTQixEnpM1wAAAE0"]
[Thu Sep 17 15:14:03.480710 2026] [security2:error] [pid 971102:tid 971262] [client 114.198.138.124:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM3AAAABw"]
[Thu Sep 17 15:14:03.480844 2026] [security2:error] [pid 971102:tid 971262] [client 114.198.138.124:59483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM3AAAABw"]
[Thu Sep 17 15:14:03.539052 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:54580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxYG-cL08BTTQixEnpM1gAAACI"]
[Thu Sep 17 15:14:03.686242 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYG-cL08BTTQixEnpM4AAAAGk"]
[Thu Sep 17 15:14:03.686355 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:54580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYG-cL08BTTQixEnpM4AAAAGk"]
[Thu Sep 17 15:14:03.689822 2026] [security2:error] [pid 971102:tid 971255] [client 4.240.114.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxYGucL08BTTQixEnpMzAAAABU"], referer: binance.com
[Thu Sep 17 15:14:03.699875 2026] [security2:error] [pid 971102:tid 971288] [client 104.234.19.146:58973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxYG-cL08BTTQixEnpM4QAAADY"]
[Thu Sep 17 15:14:03.793907 2026] [security2:error] [pid 971102:tid 971272] [client 154.190.208.131:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM4gAAACY"]
[Thu Sep 17 15:14:03.794058 2026] [security2:error] [pid 971102:tid 971272] [client 154.190.208.131:42209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM4gAAACY"]
[Thu Sep 17 15:14:03.831306 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/"] [unique_id "aqxYG-cL08BTTQixEnpM4wAAAAA"]
[Thu Sep 17 15:14:03.966880 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYG-cL08BTTQixEnpM3QAAAAk"]
[Thu Sep 17 15:14:03.966910 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYG-cL08BTTQixEnpM3QAAAAk"]
[Thu Sep 17 15:14:04.014727 2026] [security2:error] [pid 971102:tid 971346] [client 216.24.219.35:31065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM5wAAAHA"]
[Thu Sep 17 15:14:04.274399 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM7QAAAHg"]
[Thu Sep 17 15:14:04.322025 2026] [security2:error] [pid 971102:tid 971264] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/maint/"] [unique_id "aqxYHOcL08BTTQixEnpM7gAAAB4"]
[Thu Sep 17 15:14:04.418335 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/"] [unique_id "aqxYHOcL08BTTQixEnpM8AAAAHM"]
[Thu Sep 17 15:14:04.421657 2026] [security2:error] [pid 971102:tid 971238] [client 45.169.98.18:64465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYHOcL08BTTQixEnpM8QAAAAQ"]
[Thu Sep 17 15:14:04.421754 2026] [security2:error] [pid 971102:tid 971238] [client 45.169.98.18:64465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYHOcL08BTTQixEnpM8QAAAAQ"]
[Thu Sep 17 15:14:04.500689 2026] [security2:error] [pid 971102:tid 971353] [client 216.24.219.103:55127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM9AAAAHc"]
[Thu Sep 17 15:14:04.557214 2026] [autoindex:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:04.557779 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/maint/"] [unique_id "aqxYHOcL08BTTQixEnpM9QAAAHY"]
[Thu Sep 17 15:14:04.569181 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM9wAAAEw"]
[Thu Sep 17 15:14:04.700324 2026] [security2:error] [pid 971102:tid 971304] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM-QAARlE"], referer: http://envisionfilmvideo.com/new/
[Thu Sep 17 15:14:04.707876 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/"] [unique_id "aqxYHOcL08BTTQixEnpM-gAAAEE"]
[Thu Sep 17 15:14:04.761623 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYHOcL08BTTQixEnpM-wAAADM"]
[Thu Sep 17 15:14:04.783337 2026] [security2:error] [pid 971102:tid 971343] [client 193.36.224.149:39357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM_QAAAG0"]
[Thu Sep 17 15:14:04.857260 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM_wAAAD4"]
[Thu Sep 17 15:14:04.872082 2026] [security2:error] [pid 971102:tid 971251] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM_gAAEUk"], referer: http://envisionfilmvideo.com/old/
[Thu Sep 17 15:14:04.953570 2026] [authz_core:error] [pid 971102:tid 971247] [client 85.204.70.116:45598] AH01630: client denied by server configuration: /home1/zainridg/public_html/wp-content/plugins/akismet/
[Thu Sep 17 15:14:04.954152 2026] [security2:error] [pid 971102:tid 971247] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYHOcL08BTTQixEnpNAwAAAA0"]
[Thu Sep 17 15:14:04.995360 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYHOcL08BTTQixEnpNBQAAACM"]
[Thu Sep 17 15:14:05.163340 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/assets/"] [unique_id "aqxYHecL08BTTQixEnpNCQAAAHQ"]
[Thu Sep 17 15:14:05.187086 2026] [security2:error] [pid 971102:tid 971283] [client 193.36.224.219:41563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/index.php"] [unique_id "aqxYHecL08BTTQixEnpNCgAAADE"]
[Thu Sep 17 15:14:05.206780 2026] [authz_core:error] [pid 971102:tid 971351] [client 143.244.57.120:54596] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-admin/includes/error_log
[Thu Sep 17 15:14:05.232446 2026] [security2:error] [pid 971102:tid 971358] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHecL08BTTQixEnpNCwAAfFo"], referer: http://envisionfilmvideo.com/backup/
[Thu Sep 17 15:14:05.275438 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYHecL08BTTQixEnpNCAAAAHU"]
[Thu Sep 17 15:14:05.342279 2026] [autoindex:error] [pid 971102:tid 971357] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:05.342773 2026] [security2:error] [pid 971102:tid 971357] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/assets/"] [unique_id "aqxYHecL08BTTQixEnpNEAAAAHs"]
[Thu Sep 17 15:14:05.402176 2026] [security2:error] [pid 971102:tid 971321] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHecL08BTTQixEnpNEQAAVyc"], referer: http://envisionfilmvideo.com/wp/
[Thu Sep 17 15:14:05.537022 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYHecL08BTTQixEnpNFQAAAGY"]
[Thu Sep 17 15:14:05.548565 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/privacy-tools.php"] [unique_id "aqxYHecL08BTTQixEnpNGAAAADw"]
[Thu Sep 17 15:14:05.548678 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/privacy-tools.php"] [unique_id "aqxYHecL08BTTQixEnpNGAAAADw"]
[Thu Sep 17 15:14:05.578439 2026] [security2:error] [pid 971102:tid 971286] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHecL08BTTQixEnpNFgAANGo"], referer: http://envisionfilmvideo.com/wordpress/
[Thu Sep 17 15:14:05.589512 2026] [security2:error] [pid 971102:tid 971254] [client 193.36.224.212:44169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxYHecL08BTTQixEnpNGQAAABQ"]
[Thu Sep 17 15:14:05.761608 2026] [autoindex:error] [pid 971102:tid 971344] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:05.762170 2026] [security2:error] [pid 971102:tid 971344] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYHecL08BTTQixEnpNGgAAAG4"]
[Thu Sep 17 15:14:05.814151 2026] [security2:error] [pid 971102:tid 971303] [client 216.24.219.102:41135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/file.php"] [unique_id "aqxYHecL08BTTQixEnpNGwAAAEU"]
[Thu Sep 17 15:14:05.879052 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:33804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/schema.php"] [unique_id "aqxYHecL08BTTQixEnpNHAAAAFA"]
[Thu Sep 17 15:14:05.879155 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:33804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/schema.php"] [unique_id "aqxYHecL08BTTQixEnpNHAAAAFA"]
[Thu Sep 17 15:14:05.958921 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYHecL08BTTQixEnpNHgAAAG8"]
[Thu Sep 17 15:14:06.074813 2026] [security2:error] [pid 971102:tid 971334] [client 193.36.224.167:36809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxYHucL08BTTQixEnpNIgAAAGQ"]
[Thu Sep 17 15:14:06.178612 2026] [autoindex:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:06.179093 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYHucL08BTTQixEnpNJQAAAGI"]
[Thu Sep 17 15:14:06.226676 2026] [security2:error] [pid 971102:tid 971239] [client 2.104.60.34:49732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "copiwestcoast.org"] [uri "/.env"] [unique_id "aqxYHucL08BTTQixEnpNKAAAAAU"]
[Thu Sep 17 15:14:06.303525 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:33808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/screen.php"] [unique_id "aqxYHucL08BTTQixEnpNKgAAACY"]
[Thu Sep 17 15:14:06.303627 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:33808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/screen.php"] [unique_id "aqxYHucL08BTTQixEnpNKgAAACY"]
[Thu Sep 17 15:14:06.306202 2026] [security2:error] [pid 971102:tid 971243] [client 193.36.224.146:41191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-mail.php"] [unique_id "aqxYHucL08BTTQixEnpNKwAAAAk"]
[Thu Sep 17 15:14:06.340888 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/html-api/"] [unique_id "aqxYHucL08BTTQixEnpNLAAAAAA"]
[Thu Sep 17 15:14:06.565344 2026] [autoindex:error] [pid 971102:tid 971346] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:06.565822 2026] [security2:error] [pid 971102:tid 971346] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/html-api/"] [unique_id "aqxYHucL08BTTQixEnpNMAAAAHA"]
[Thu Sep 17 15:14:06.572387 2026] [security2:error] [pid 971102:tid 971355] [client 104.234.19.147:64285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/ioxi-o.php"] [unique_id "aqxYHucL08BTTQixEnpNMQAAAHk"]
[Thu Sep 17 15:14:06.599793 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/theme-install.php"] [unique_id "aqxYHucL08BTTQixEnpNMgAAAEQ"]
[Thu Sep 17 15:14:06.599862 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:33814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/theme-install.php"] [unique_id "aqxYHucL08BTTQixEnpNMgAAAEQ"]
[Thu Sep 17 15:14:06.742077 2026] [security2:error] [pid 971102:tid 971264] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/js/"] [unique_id "aqxYHucL08BTTQixEnpNNQAAAB4"]
[Thu Sep 17 15:14:06.792881 2026] [security2:error] [pid 971102:tid 971292] [client 104.234.19.145:51101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxYHucL08BTTQixEnpNOQAAADo"]
[Thu Sep 17 15:14:06.819396 2026] [security2:error] [pid 971102:tid 971238] [client 4.240.114.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxYHucL08BTTQixEnpNOAAAAAQ"], referer: binance.com
[Thu Sep 17 15:14:06.893224 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:33830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/translation-install.php"] [unique_id "aqxYHucL08BTTQixEnpNPAAAAEM"]
[Thu Sep 17 15:14:06.893338 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:33830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/translation-install.php"] [unique_id "aqxYHucL08BTTQixEnpNPAAAAEM"]
[Thu Sep 17 15:14:06.949189 2026] [autoindex:error] [pid 971102:tid 971348] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:06.949681 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/js/"] [unique_id "aqxYHucL08BTTQixEnpNPQAAAHI"]
[Thu Sep 17 15:14:07.096501 2026] [security2:error] [pid 971102:tid 971287] [client 193.36.224.148:49651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/style.php"] [unique_id "aqxYH-cL08BTTQixEnpNRAAAADU"]
[Thu Sep 17 15:14:07.137885 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYH-cL08BTTQixEnpNRQAAAFE"]
[Thu Sep 17 15:14:07.174332 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:33834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/update-core.php"] [unique_id "aqxYH-cL08BTTQixEnpNRgAAAE4"]
[Thu Sep 17 15:14:07.174415 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:33834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/update-core.php"] [unique_id "aqxYH-cL08BTTQixEnpNRgAAAE4"]
[Thu Sep 17 15:14:07.344928 2026] [security2:error] [pid 971102:tid 971310] [client 186.105.232.15:60198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYH-cL08BTTQixEnpNSQAAAEw"]
[Thu Sep 17 15:14:07.345029 2026] [security2:error] [pid 971102:tid 971310] [client 186.105.232.15:60198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYH-cL08BTTQixEnpNSQAAAEw"]
[Thu Sep 17 15:14:07.348425 2026] [autoindex:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:07.349184 2026] [security2:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYH-cL08BTTQixEnpNSAAAACU"]
[Thu Sep 17 15:14:07.371739 2026] [security2:error] [pid 971102:tid 971278] [client 74.7.230.0:37532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.rwz.qhz.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "aqxYH-cL08BTTQixEnpNSgAAACw"]
[Thu Sep 17 15:14:07.468597 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:33842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/upgrade.php"] [unique_id "aqxYH-cL08BTTQixEnpNTAAAACo"]
[Thu Sep 17 15:14:07.468717 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:33842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/upgrade.php"] [unique_id "aqxYH-cL08BTTQixEnpNTAAAACo"]
[Thu Sep 17 15:14:07.489121 2026] [security2:error] [pid 971102:tid 971342] [client 104.234.19.151:34767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/style.php"] [unique_id "aqxYH-cL08BTTQixEnpNTgAAAGw"]
[Thu Sep 17 15:14:07.564869 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYH-cL08BTTQixEnpNUAAAAHw"]
[Thu Sep 17 15:14:07.729055 2026] [security2:error] [pid 971102:tid 971265] [client 193.36.224.226:39457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxYH-cL08BTTQixEnpNUgAAAB8"]
[Thu Sep 17 15:14:07.756989 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:33844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/"] [unique_id "aqxYH-cL08BTTQixEnpNVAAAAFI"]
[Thu Sep 17 15:14:07.764312 2026] [autoindex:error] [pid 971102:tid 971277] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:07.765025 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYH-cL08BTTQixEnpNUwAAACs"]
[Thu Sep 17 15:14:07.954134 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/pomo/"] [unique_id "aqxYH-cL08BTTQixEnpNVwAAABQ"]
[Thu Sep 17 15:14:08.132840 2026] [security2:error] [pid 971102:tid 971248] [client 128.242.183.58:18891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.churchinirving.org"] [uri "/index.php"] [unique_id "aqxYIOcL08BTTQixEnpNWAAAAA4"]
[Thu Sep 17 15:14:08.143455 2026] [autoindex:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:08.144024 2026] [security2:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/pomo/"] [unique_id "aqxYIOcL08BTTQixEnpNYAAAADc"]
[Thu Sep 17 15:14:08.191386 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYH-cL08BTTQixEnpNVgAAADw"]
[Thu Sep 17 15:14:08.332049 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYIOcL08BTTQixEnpNYwAAACI"]
[Thu Sep 17 15:14:08.332163 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYIOcL08BTTQixEnpNYwAAACI"]
[Thu Sep 17 15:14:08.332164 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/random_compat/"] [unique_id "aqxYIOcL08BTTQixEnpNYgAAABM"]
[Thu Sep 17 15:14:08.471906 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:33844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxYIOcL08BTTQixEnpNZQAAABc"]
[Thu Sep 17 15:14:08.479465 2026] [security2:error] [pid 971102:tid 971282] [client 156.192.234.52:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNZgAAADA"]
[Thu Sep 17 15:14:08.480880 2026] [security2:error] [pid 971102:tid 971282] [client 156.192.234.52:55732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNZgAAADA"]
[Thu Sep 17 15:14:08.583123 2026] [security2:error] [pid 971102:tid 971288] [client 193.36.224.108:60381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-editor.php"] [unique_id "aqxYIOcL08BTTQixEnpNawAAADY"]
[Thu Sep 17 15:14:08.719372 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYIOcL08BTTQixEnpNagAAAGI"]
[Thu Sep 17 15:14:08.719393 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYIOcL08BTTQixEnpNagAAAGI"]
[Thu Sep 17 15:14:08.828902 2026] [security2:error] [pid 971102:tid 971305] [client 115.244.164.14:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNbgAAAEc"]
[Thu Sep 17 15:14:08.828994 2026] [security2:error] [pid 971102:tid 971305] [client 115.244.164.14:60670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNbgAAAEc"]
[Thu Sep 17 15:14:08.915445 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:54602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxYIOcL08BTTQixEnpNbwAAAEg"]
[Thu Sep 17 15:14:08.950140 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYIOcL08BTTQixEnpNcQAAAHg"]
[Thu Sep 17 15:14:09.124196 2026] [autoindex:error] [pid 971102:tid 971347] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:09.124711 2026] [security2:error] [pid 971102:tid 971347] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYIecL08BTTQixEnpNdQAAAHE"]
[Thu Sep 17 15:14:09.315778 2026] [security2:error] [pid 971102:tid 971284] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYIecL08BTTQixEnpNeAAAADI"]
[Thu Sep 17 15:14:09.538371 2026] [autoindex:error] [pid 971102:tid 971287] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:09.538897 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYIecL08BTTQixEnpNqwAAADU"]
[Thu Sep 17 15:14:09.826716 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYIecL08BTTQixEnpN2gAAACw"]
[Thu Sep 17 15:14:10.024487 2026] [autoindex:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:10.024960 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYIucL08BTTQixEnpN8gAAAHw"]
[Thu Sep 17 15:14:10.076683 2026] [security2:error] [pid 971102:tid 971240] [client 185.55.149.49:52937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYIucL08BTTQixEnpN9AAAAAY"]
[Thu Sep 17 15:14:10.076794 2026] [security2:error] [pid 971102:tid 971240] [client 185.55.149.49:52937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYIucL08BTTQixEnpN9AAAAAY"]
[Thu Sep 17 15:14:10.241645 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYIucL08BTTQixEnpN9gAAACs"]
[Thu Sep 17 15:14:10.354148 2026] [security2:error] [pid 971102:tid 971350] [client 193.36.224.206:63797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/lufix.php"] [unique_id "aqxYIucL08BTTQixEnpN9wAAAHQ"]
[Thu Sep 17 15:14:10.432389 2026] [autoindex:error] [pid 971102:tid 971340] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:10.432895 2026] [security2:error] [pid 971102:tid 971340] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYIucL08BTTQixEnpN-AAAAGo"]
[Thu Sep 17 15:14:10.671224 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYIucL08BTTQixEnpN_AAAACA"]
[Thu Sep 17 15:14:10.692685 2026] [security2:error] [pid 971102:tid 971324] [client 193.36.224.182:62787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/txets.php"] [unique_id "aqxYIucL08BTTQixEnpN_QAAAFo"]
[Thu Sep 17 15:14:10.724837 2026] [security2:error] [pid 971102:tid 971248] [client 5.189.145.112:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxYIucL08BTTQixEnpN_gAAAA4"], referer: binance.com
[Thu Sep 17 15:14:10.844224 2026] [autoindex:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:10.844837 2026] [security2:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYIucL08BTTQixEnpOAQAAADc"]
[Thu Sep 17 15:14:10.962574 2026] [security2:error] [pid 971102:tid 971352] [client 5.178.15.127:2635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYIucL08BTTQixEnpN_wAAAHY"]
[Thu Sep 17 15:14:11.044860 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/widgets/"] [unique_id "aqxYI-cL08BTTQixEnpOCAAAAE0"]
[Thu Sep 17 15:14:11.056105 2026] [autoindex:error] [pid 971102:tid 971294] [client 212.156.70.154:15213] AH01276: Cannot serve directory /home1/hbnxuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:11.122168 2026] [security2:error] [pid 971102:tid 971256] [client 193.36.224.168:21363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxYI-cL08BTTQixEnpOCwAAABY"]
[Thu Sep 17 15:14:11.243767 2026] [autoindex:error] [pid 971102:tid 971253] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:11.244388 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/widgets/"] [unique_id "aqxYI-cL08BTTQixEnpODAAAABM"]
[Thu Sep 17 15:14:11.440368 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYI-cL08BTTQixEnpODwAAADA"]
[Thu Sep 17 15:14:11.679737 2026] [autoindex:error] [pid 971102:tid 971333] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:11.680465 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYI-cL08BTTQixEnpOEwAAAGM"]
[Thu Sep 17 15:14:11.850868 2026] [security2:error] [pid 971102:tid 971332] [client 193.36.224.152:40603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxYI-cL08BTTQixEnpOGQAAAGI"]
[Thu Sep 17 15:14:11.928592 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYI-cL08BTTQixEnpOGwAAAAA"]
[Thu Sep 17 15:14:12.182735 2026] [autoindex:error] [pid 971102:tid 971245] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:12.183203 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYJOcL08BTTQixEnpOHwAAAAs"]
[Thu Sep 17 15:14:12.337493 2026] [security2:error] [pid 971102:tid 971355] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/images/slider/"] [unique_id "aqxYJOcL08BTTQixEnpOIgAAAHk"]
[Thu Sep 17 15:14:12.753480 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJOcL08BTTQixEnpOJgAAAF8"]
[Thu Sep 17 15:14:12.753506 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJOcL08BTTQixEnpOJgAAAF8"]
[Thu Sep 17 15:14:12.959684 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxYJOcL08BTTQixEnpOKAAAABA"]
[Thu Sep 17 15:14:13.249542 2026] [security2:error] [pid 971102:tid 971310] [client 216.24.219.20:31219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxYJecL08BTTQixEnpOLQAAAEw"]
[Thu Sep 17 15:14:13.269042 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOLAAAAAg"]
[Thu Sep 17 15:14:13.269064 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOLAAAAAg"]
[Thu Sep 17 15:14:13.485087 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/sites/default/files/"] [unique_id "aqxYJecL08BTTQixEnpOMQAAAH4"]
[Thu Sep 17 15:14:13.796064 2026] [security2:error] [pid 971102:tid 971319] [client 104.234.19.148:31127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/goods.php"] [unique_id "aqxYJecL08BTTQixEnpONAAAAFU"]
[Thu Sep 17 15:14:13.864729 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOMwAAAHw"]
[Thu Sep 17 15:14:13.864753 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOMwAAAHw"]
[Thu Sep 17 15:14:13.940844 2026] [security2:error] [pid 971102:tid 971357] [client 20.244.34.24:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxYJecL08BTTQixEnpONQAAAHs"], referer: binance.com
[Thu Sep 17 15:14:14.045028 2026] [security2:error] [pid 971102:tid 971281] [client 114.198.138.124:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOOQAAAC8"]
[Thu Sep 17 15:14:14.045126 2026] [security2:error] [pid 971102:tid 971281] [client 114.198.138.124:60316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOOQAAAC8"]
[Thu Sep 17 15:14:14.052755 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxYJucL08BTTQixEnpOOgAAAHU"]
[Thu Sep 17 15:14:14.393574 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJucL08BTTQixEnpOOwAAAEs"]
[Thu Sep 17 15:14:14.393599 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJucL08BTTQixEnpOOwAAAEs"]
[Thu Sep 17 15:14:14.927288 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:65030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOPwAAADg"]
[Thu Sep 17 15:14:14.927436 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:65030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOPwAAADg"]
[Thu Sep 17 15:14:15.054846 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:41478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJ-cL08BTTQixEnpOQwAAAGg"]
[Thu Sep 17 15:14:15.063921 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:41478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJ-cL08BTTQixEnpOQwAAAGg"]
[Thu Sep 17 15:14:15.247326 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxYJ-cL08BTTQixEnpORAAAAEU"]
[Thu Sep 17 15:14:15.567502 2026] [security2:error] [pid 971102:tid 971348] [client 34.44.142.114:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOLgAAcm0"]
[Thu Sep 17 15:14:15.590640 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpORQAAAHY"]
[Thu Sep 17 15:14:15.590684 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpORQAAAHY"]
[Thu Sep 17 15:14:15.772075 2026] [security2:error] [pid 971102:tid 971345] [client 104.234.19.146:22735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/php8.php"] [unique_id "aqxYJ-cL08BTTQixEnpOTgAAAG8"]
[Thu Sep 17 15:14:15.786272 2026] [security2:error] [pid 971102:tid 971326] [client 34.44.142.114:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpOTAAAXGA"]
[Thu Sep 17 15:14:15.823276 2026] [security2:error] [pid 971102:tid 971273] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/components/"] [unique_id "aqxYJ-cL08BTTQixEnpOTwAAACc"]
[Thu Sep 17 15:14:16.091712 2026] [security2:error] [pid 971102:tid 971318] [client 34.44.142.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpOVAAAAFQ"]
[Thu Sep 17 15:14:16.174226 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOWAAAAD0"]
[Thu Sep 17 15:14:16.174247 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOWAAAAD0"]
[Thu Sep 17 15:14:16.341844 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/uploads/images/"] [unique_id "aqxYKOcL08BTTQixEnpOXAAAAEg"]
[Thu Sep 17 15:14:16.674560 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOYAAAABs"]
[Thu Sep 17 15:14:16.674584 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOYAAAABs"]
[Thu Sep 17 15:14:16.854253 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxYKOcL08BTTQixEnpOZgAAAAQ"]
[Thu Sep 17 15:14:17.017124 2026] [security2:error] [pid 971102:tid 971312] [client 5.189.145.112:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxYKecL08BTTQixEnpObAAAAE4"], referer: binance.com
[Thu Sep 17 15:14:17.052298 2026] [autoindex:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/plugins/classic-editor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:17.052816 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxYKecL08BTTQixEnpObgAAAH8"]
[Thu Sep 17 15:14:17.235256 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/fonts/"] [unique_id "aqxYKecL08BTTQixEnpObwAAAD4"]
[Thu Sep 17 15:14:17.564476 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOdAAAAAc"]
[Thu Sep 17 15:14:17.564496 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOdAAAAAc"]
[Thu Sep 17 15:14:17.745456 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxYKecL08BTTQixEnpOewAAACo"]
[Thu Sep 17 15:14:18.052076 2026] [authz_core:error] [pid 971102:tid 971323] [client 169.58.197.253:61646] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:14:18.082556 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOfQAAAC8"]
[Thu Sep 17 15:14:18.082581 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOfQAAAC8"]
[Thu Sep 17 15:14:18.263418 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxYKucL08BTTQixEnpOhQAAAEs"]
[Thu Sep 17 15:14:18.314150 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:60805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYKucL08BTTQixEnpOhgAAAHs"]
[Thu Sep 17 15:14:18.315205 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:60805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYKucL08BTTQixEnpOhgAAAHs"]
[Thu Sep 17 15:14:18.578707 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKucL08BTTQixEnpOiwAAAGg"]
[Thu Sep 17 15:14:18.578739 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKucL08BTTQixEnpOiwAAAGg"]
[Thu Sep 17 15:14:18.754032 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wordpress/"] [unique_id "aqxYKucL08BTTQixEnpOkAAAAE0"]
[Thu Sep 17 15:14:19.040294 2026] [security2:error] [pid 971102:tid 971294] [client 156.192.234.52:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmQAAADw"]
[Thu Sep 17 15:14:19.040878 2026] [security2:error] [pid 971102:tid 971294] [client 156.192.234.52:56353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmQAAADw"]
[Thu Sep 17 15:14:19.171767 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYK-cL08BTTQixEnpOmAAAABk"]
[Thu Sep 17 15:14:19.171792 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYK-cL08BTTQixEnpOmAAAABk"]
[Thu Sep 17 15:14:19.391234 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:61329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmgAAAGY"]
[Thu Sep 17 15:14:19.391331 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:61329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmgAAAGY"]
[Thu Sep 17 15:14:20.152242 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/images/"] [unique_id "aqxYLOcL08BTTQixEnpOqgAAAHg"]
[Thu Sep 17 15:14:20.384800 2026] [autoindex:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:20.385319 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/images/"] [unique_id "aqxYLOcL08BTTQixEnpOqwAAAH8"]
[Thu Sep 17 15:14:20.542573 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYLOcL08BTTQixEnpOrwAAAAE"]
[Thu Sep 17 15:14:20.602416 2026] [fcgid:warn] [pid 971102:tid 971335] (70014)End of file found: [client 167.94.146.56:40888] mod_fcgid: can't get data from http client
[Thu Sep 17 15:14:20.891835 2026] [security2:error] [pid 971102:tid 971284] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLOcL08BTTQixEnpOsQAAADI"]
[Thu Sep 17 15:14:20.891871 2026] [security2:error] [pid 971102:tid 971284] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLOcL08BTTQixEnpOsQAAADI"]
[Thu Sep 17 15:14:20.952896 2026] [security2:error] [pid 971102:tid 971296] [client 185.55.149.49:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYLOcL08BTTQixEnpOswAAAD4"]
[Thu Sep 17 15:14:20.953040 2026] [security2:error] [pid 971102:tid 971296] [client 185.55.149.49:51630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYLOcL08BTTQixEnpOswAAAD4"]
[Thu Sep 17 15:14:21.147510 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxYLecL08BTTQixEnpOtwAAADo"]
[Thu Sep 17 15:14:21.467825 2026] [security2:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOugAAACU"]
[Thu Sep 17 15:14:21.467849 2026] [security2:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOugAAACU"]
[Thu Sep 17 15:14:21.721277 2026] [security2:error] [pid 971102:tid 971343] [client 104.28.198.244:22700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYLecL08BTTQixEnpOxgAAAG0"]
[Thu Sep 17 15:14:21.721359 2026] [security2:error] [pid 971102:tid 971343] [client 104.28.198.244:22700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYLecL08BTTQixEnpOxgAAAG0"]
[Thu Sep 17 15:14:21.740063 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/js/"] [unique_id "aqxYLecL08BTTQixEnpOxwAAACs"]
[Thu Sep 17 15:14:21.756054 2026] [security2:error] [pid 971102:tid 971186] [remote 216.73.217.142:21738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYLecL08BTTQixEnpOyQAAD1I"]
[Thu Sep 17 15:14:22.068201 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOygAAABo"]
[Thu Sep 17 15:14:22.068227 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOygAAABo"]
[Thu Sep 17 15:14:22.336097 2026] [security2:error] [pid 971102:tid 971344] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYLucL08BTTQixEnpO0QAAAG4"]
[Thu Sep 17 15:14:22.540391 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/plugins/woocommerce/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:22.540925 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYLucL08BTTQixEnpO1wAAACA"]
[Thu Sep 17 15:14:22.748154 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYLucL08BTTQixEnpO2gAAAH0"]
[Thu Sep 17 15:14:23.019711 2026] [autoindex:error] [pid 971102:tid 971280] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/plugins/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:23.020186 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYL-cL08BTTQixEnpO3gAAAC4"]
[Thu Sep 17 15:14:23.190029 2026] [core:error] [pid 971102:tid 971333] [client 31.56.58.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:23.190046 2026] [core:error] [pid 971102:tid 971333] [client 31.56.58.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:23.216844 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/meta/"] [unique_id "aqxYL-cL08BTTQixEnpO5QAAAGs"]
[Thu Sep 17 15:14:23.564255 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO5gAAAEQ"]
[Thu Sep 17 15:14:23.564278 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO5gAAAEQ"]
[Thu Sep 17 15:14:23.738930 2026] [security2:error] [pid 971102:tid 971307] [client 35.198.113.100:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO6QAASWU"]
[Thu Sep 17 15:14:23.741881 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/network/"] [unique_id "aqxYL-cL08BTTQixEnpO7gAAAAE"]
[Thu Sep 17 15:14:24.081944 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/network/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO8AAAAEE"]
[Thu Sep 17 15:14:24.135175 2026] [security2:error] [pid 971102:tid 971258] [client 37.231.33.242:62867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYMOcL08BTTQixEnpO8wAAGAw"]
[Thu Sep 17 15:14:24.242973 2026] [security2:error] [pid 971102:tid 971245] [client 5.189.145.112:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxYMOcL08BTTQixEnpO-wAAAAs"], referer: binance.com
[Thu Sep 17 15:14:24.316748 2026] [security2:error] [pid 971102:tid 971251] [client 134.185.85.61:49430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "tengushee.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYMOcL08BTTQixEnpO_AAAABE"]
[Thu Sep 17 15:14:24.685682 2026] [security2:error] [pid 971102:tid 971276] [client 114.198.138.124:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMOcL08BTTQixEnpPAgAAACo"]
[Thu Sep 17 15:14:24.685775 2026] [security2:error] [pid 971102:tid 971276] [client 114.198.138.124:63121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMOcL08BTTQixEnpPAgAAACo"]
[Thu Sep 17 15:14:24.717596 2026] [security2:error] [pid 971102:tid 971313] [client 134.185.85.61:57115] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "tengushee.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYMOcL08BTTQixEnpPAwAAAE8"]
[Thu Sep 17 15:14:25.306840 2026] [security2:error] [pid 971102:tid 971270] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPIAAAJAo"]
[Thu Sep 17 15:14:25.368848 2026] [security2:error] [pid 971102:tid 971343] [client 85.204.70.116:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMecL08BTTQixEnpPIgAAAG0"]
[Thu Sep 17 15:14:25.368975 2026] [security2:error] [pid 971102:tid 971343] [client 85.204.70.116:44594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMecL08BTTQixEnpPIgAAAG0"]
[Thu Sep 17 15:14:25.438788 2026] [security2:error] [pid 971102:tid 971311] [client 45.169.98.18:49205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPIwAAAE0"]
[Thu Sep 17 15:14:25.438891 2026] [security2:error] [pid 971102:tid 971311] [client 45.169.98.18:49205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPIwAAAE0"]
[Thu Sep 17 15:14:25.476212 2026] [security2:error] [pid 971102:tid 971144] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env"] [unique_id "aqxYMecL08BTTQixEnpPJAAAHCg"]
[Thu Sep 17 15:14:25.476646 2026] [security2:error] [pid 971102:tid 971154] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.bak"] [unique_id "aqxYMecL08BTTQixEnpPLgAAHDI"]
[Thu Sep 17 15:14:25.476651 2026] [security2:error] [pid 971102:tid 971228] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.old"] [unique_id "aqxYMecL08BTTQixEnpPKwAAHHs"]
[Thu Sep 17 15:14:25.476672 2026] [security2:error] [pid 971102:tid 971149] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.backup"] [unique_id "aqxYMecL08BTTQixEnpPLQAAHC0"]
[Thu Sep 17 15:14:25.529544 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/user/"] [unique_id "aqxYMecL08BTTQixEnpPTAAAAAQ"]
[Thu Sep 17 15:14:25.581605 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:42077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPUQAAAHY"]
[Thu Sep 17 15:14:25.586142 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:42077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPUQAAAHY"]
[Thu Sep 17 15:14:25.633439 2026] [security2:error] [pid 971102:tid 971115] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/.env.php"] [unique_id "aqxYMecL08BTTQixEnpPUwAAHAs"]
[Thu Sep 17 15:14:25.653475 2026] [security2:error] [pid 971102:tid 971295] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRAAAAD0"]
[Thu Sep 17 15:14:25.655746 2026] [security2:error] [pid 971102:tid 971291] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPQwAAADk"]
[Thu Sep 17 15:14:25.658591 2026] [security2:error] [pid 971102:tid 971256] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPQgAAABY"]
[Thu Sep 17 15:14:25.668803 2026] [security2:error] [pid 971102:tid 971341] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRwAAAGs"]
[Thu Sep 17 15:14:25.668803 2026] [security2:error] [pid 971102:tid 971354] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRQAAAHg"]
[Thu Sep 17 15:14:25.671175 2026] [security2:error] [pid 971102:tid 971302] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPSAAAAEQ"]
[Thu Sep 17 15:14:25.671683 2026] [security2:error] [pid 971102:tid 971334] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPSgAAAGQ"]
[Thu Sep 17 15:14:25.672121 2026] [security2:error] [pid 971102:tid 971261] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRgAAABs"]
[Thu Sep 17 15:14:25.679452 2026] [security2:error] [pid 971102:tid 971237] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPTQAAAAM"]
[Thu Sep 17 15:14:25.680373 2026] [security2:error] [pid 971102:tid 971257] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPSwAAABc"]
[Thu Sep 17 15:14:25.684011 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPTgAAAB4"]
[Thu Sep 17 15:14:25.691096 2026] [security2:error] [pid 971102:tid 971312] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPTwAAAE4"]
[Thu Sep 17 15:14:25.769239 2026] [security2:error] [pid 971102:tid 971111] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env~"] [unique_id "aqxYMecL08BTTQixEnpPXQAAHAc"]
[Thu Sep 17 15:14:25.770665 2026] [security2:error] [pid 971102:tid 971268] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPWQAAACI"]
[Thu Sep 17 15:14:25.770708 2026] [security2:error] [pid 971102:tid 971239] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPWgAAAAU"]
[Thu Sep 17 15:14:25.770784 2026] [security2:error] [pid 971102:tid 971279] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPWwAAAC0"]
[Thu Sep 17 15:14:25.801718 2026] [security2:error] [pid 971102:tid 971132] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.swp"] [unique_id "aqxYMecL08BTTQixEnpPXgAAHBw"]
[Thu Sep 17 15:14:25.900850 2026] [security2:error] [pid 971102:tid 971269] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/user/index.php"] [unique_id "aqxYMecL08BTTQixEnpPXAAAACM"]
[Thu Sep 17 15:14:25.933007 2026] [security2:error] [pid 971102:tid 971240] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPYQAAAAY"]
[Thu Sep 17 15:14:25.933968 2026] [security2:error] [pid 971102:tid 971138] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/backend/.env"] [unique_id "aqxYMecL08BTTQixEnpPagAAHCI"]
[Thu Sep 17 15:14:25.933988 2026] [security2:error] [pid 971102:tid 971171] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/app/.env"] [unique_id "aqxYMecL08BTTQixEnpPaAAAHEM"]
[Thu Sep 17 15:14:25.934055 2026] [security2:error] [pid 971102:tid 971108] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/api/.env"] [unique_id "aqxYMecL08BTTQixEnpPZgAAHAQ"]
[Thu Sep 17 15:14:26.235543 2026] [security2:error] [pid 971102:tid 971145] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/src/.env"] [unique_id "aqxYMucL08BTTQixEnpPgQAAHCk"]
[Thu Sep 17 15:14:26.235559 2026] [security2:error] [pid 971102:tid 971161] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/config/.env"] [unique_id "aqxYMucL08BTTQixEnpPggAAHDk"]
[Thu Sep 17 15:14:26.235582 2026] [security2:error] [pid 971102:tid 971168] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/server/.env"] [unique_id "aqxYMucL08BTTQixEnpPgAAAHEA"]
[Thu Sep 17 15:14:26.235603 2026] [security2:error] [pid 971102:tid 971188] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/web/.env"] [unique_id "aqxYMucL08BTTQixEnpPgwAAHFM"]
[Thu Sep 17 15:14:26.235684 2026] [security2:error] [pid 971102:tid 971174] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/client/.env"] [unique_id "aqxYMucL08BTTQixEnpPhAAAHEY"]
[Thu Sep 17 15:14:26.236587 2026] [security2:error] [pid 971102:tid 971172] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/public/.env"] [unique_id "aqxYMucL08BTTQixEnpPhgAAHEQ"]
[Thu Sep 17 15:14:26.236645 2026] [security2:error] [pid 971102:tid 971167] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/frontend/.env"] [unique_id "aqxYMucL08BTTQixEnpPhQAAHD8"]
[Thu Sep 17 15:14:26.236683 2026] [security2:error] [pid 971102:tid 971165] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/var/www/.env"] [unique_id "aqxYMucL08BTTQixEnpPhwAAHD0"]
[Thu Sep 17 15:14:26.236729 2026] [security2:error] [pid 971102:tid 971175] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/var/www/html/.env"] [unique_id "aqxYMucL08BTTQixEnpPiAAAHEc"]
[Thu Sep 17 15:14:26.324622 2026] [security2:error] [pid 971102:tid 971248] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPdgAAAA4"]
[Thu Sep 17 15:14:26.327293 2026] [security2:error] [pid 971102:tid 971340] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPeQAAAGo"]
[Thu Sep 17 15:14:26.328639 2026] [security2:error] [pid 971102:tid 971321] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPegAAAFc"]
[Thu Sep 17 15:14:26.328851 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPdwAAABQ"]
[Thu Sep 17 15:14:26.329649 2026] [security2:error] [pid 971102:tid 971246] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPeAAAAAw"]
[Thu Sep 17 15:14:26.330440 2026] [security2:error] [pid 971102:tid 971260] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPdQAAABo"]
[Thu Sep 17 15:14:26.334072 2026] [security2:error] [pid 971102:tid 971338] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPfAAAAGg"]
[Thu Sep 17 15:14:26.370269 2026] [security2:error] [pid 971102:tid 971137] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/apps/.env"] [unique_id "aqxYMucL08BTTQixEnpPiwAAKSE"]
[Thu Sep 17 15:14:26.370294 2026] [security2:error] [pid 971102:tid 971185] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/application/.env"] [unique_id "aqxYMucL08BTTQixEnpPigAAKVE"]
[Thu Sep 17 15:14:26.370313 2026] [security2:error] [pid 971102:tid 971177] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/back/.env"] [unique_id "aqxYMucL08BTTQixEnpPjAAAKUk"]
[Thu Sep 17 15:14:26.370355 2026] [security2:error] [pid 971102:tid 971179] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/backup/.env"] [unique_id "aqxYMucL08BTTQixEnpPjQAAKUs"]
[Thu Sep 17 15:14:26.370385 2026] [security2:error] [pid 971102:tid 971152] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/laravel/.env"] [unique_id "aqxYMucL08BTTQixEnpPiQAAKTA"]
[Thu Sep 17 15:14:26.370817 2026] [security2:error] [pid 971102:tid 971113] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/prod/.env"] [unique_id "aqxYMucL08BTTQixEnpPkAAAKQk"]
[Thu Sep 17 15:14:26.370849 2026] [security2:error] [pid 971102:tid 971182] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/dev/.env"] [unique_id "aqxYMucL08BTTQixEnpPjwAAKU4"]
[Thu Sep 17 15:14:26.370855 2026] [security2:error] [pid 971102:tid 971195] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/production/.env"] [unique_id "aqxYMucL08BTTQixEnpPkQAAKVo"]
[Thu Sep 17 15:14:26.371029 2026] [security2:error] [pid 971102:tid 971159] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/cms/.env"] [unique_id "aqxYMucL08BTTQixEnpPjgAAKTc"]
[Thu Sep 17 15:14:26.460412 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMucL08BTTQixEnpPlAAAAH0"]
[Thu Sep 17 15:14:26.460511 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:44610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMucL08BTTQixEnpPlAAAAH0"]
[Thu Sep 17 15:14:26.465578 2026] [security2:error] [pid 971102:tid 971211] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/staging/.env"] [unique_id "aqxYMucL08BTTQixEnpPlQAAPWo"]
[Thu Sep 17 15:14:26.467855 2026] [security2:error] [pid 971102:tid 971170] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/test/.env"] [unique_id "aqxYMucL08BTTQixEnpPlgAAOUI"]
[Thu Sep 17 15:14:26.469785 2026] [security2:error] [pid 971102:tid 971164] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/old/.env"] [unique_id "aqxYMucL08BTTQixEnpPlwAAFjw"]
[Thu Sep 17 15:14:26.505401 2026] [security2:error] [pid 971102:tid 971180] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/admin-app/.env"] [unique_id "aqxYMucL08BTTQixEnpPmwAAZUw"]
[Thu Sep 17 15:14:26.505464 2026] [security2:error] [pid 971102:tid 971151] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/node-api/.env"] [unique_id "aqxYMucL08BTTQixEnpPmAAAZS8"]
[Thu Sep 17 15:14:26.505490 2026] [security2:error] [pid 971102:tid 971183] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/new/.env"] [unique_id "aqxYMucL08BTTQixEnpPmQAAZU8"]
[Thu Sep 17 15:14:26.505525 2026] [security2:error] [pid 971102:tid 971205] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/api-backend/.env"] [unique_id "aqxYMucL08BTTQixEnpPmgAAZWQ"]
[Thu Sep 17 15:14:26.505841 2026] [security2:error] [pid 971102:tid 971213] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/current/.env"] [unique_id "aqxYMucL08BTTQixEnpPngAAZWw"]
[Thu Sep 17 15:14:26.505897 2026] [security2:error] [pid 971102:tid 971201] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.aws/.env"] [unique_id "aqxYMucL08BTTQixEnpPpAAAZWA"]
[Thu Sep 17 15:14:26.505941 2026] [security2:error] [pid 971102:tid 971189] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/public_html/.env"] [unique_id "aqxYMucL08BTTQixEnpPnQAAZVQ"]
[Thu Sep 17 15:14:26.505941 2026] [security2:error] [pid 971102:tid 971181] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/server/backend/.env"] [unique_id "aqxYMucL08BTTQixEnpPoAAAZU0"]
[Thu Sep 17 15:14:26.505953 2026] [security2:error] [pid 971102:tid 971193] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/aws/.env"] [unique_id "aqxYMucL08BTTQixEnpPogAAZVg"]
[Thu Sep 17 15:14:26.506004 2026] [security2:error] [pid 971102:tid 971198] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/server/api/.env"] [unique_id "aqxYMucL08BTTQixEnpPnwAAZV0"]
[Thu Sep 17 15:14:26.506018 2026] [security2:error] [pid 971102:tid 971210] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.docker/.env"] [unique_id "aqxYMucL08BTTQixEnpPoQAAZWk"]
[Thu Sep 17 15:14:26.506035 2026] [security2:error] [pid 971102:tid 971214] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxYMucL08BTTQixEnpPowAAZW0"]
[Thu Sep 17 15:14:26.537306 2026] [security2:error] [pid 971102:tid 971184] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/administrator/.env"] [unique_id "aqxYMucL08BTTQixEnpPnAAAZVA"]
[Thu Sep 17 15:14:26.600464 2026] [security2:error] [pid 971102:tid 971197] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/stripe/.env"] [unique_id "aqxYMucL08BTTQixEnpPpwAAO1w"]
[Thu Sep 17 15:14:26.639776 2026] [security2:error] [pid 971102:tid 971222] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/v3/.env"] [unique_id "aqxYMucL08BTTQixEnpPsAAAXHU"]
[Thu Sep 17 15:14:26.639791 2026] [security2:error] [pid 971102:tid 971192] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/v1/.env"] [unique_id "aqxYMucL08BTTQixEnpPrgAAXFc"]
[Thu Sep 17 15:14:26.639875 2026] [security2:error] [pid 971102:tid 971207] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/media/.env"] [unique_id "aqxYMucL08BTTQixEnpPsQAAXGY"]
[Thu Sep 17 15:14:26.639891 2026] [security2:error] [pid 971102:tid 971230] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/v2/.env"] [unique_id "aqxYMucL08BTTQixEnpPrwAAXH0"]
[Thu Sep 17 15:14:26.642691 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/"] [unique_id "aqxYMucL08BTTQixEnpPugAAABA"]
[Thu Sep 17 15:14:26.655586 2026] [security2:error] [pid 971102:tid 971235] [client 151.63.101.195:63293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYMucL08BTTQixEnpPpQAAAXA"]
[Thu Sep 17 15:14:26.745826 2026] [security2:error] [pid 971102:tid 971354] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPrQAAAHg"]
[Thu Sep 17 15:14:26.751202 2026] [security2:error] [pid 971102:tid 971341] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPrAAAAGs"]
[Thu Sep 17 15:14:26.775428 2026] [security2:error] [pid 971102:tid 971107] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.git/config.bak"] [unique_id "aqxYMucL08BTTQixEnpP0QAAXAM"]
[Thu Sep 17 15:14:26.794678 2026] [security2:error] [pid 971102:tid 971329] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPwwAAAF8"]
[Thu Sep 17 15:14:26.797185 2026] [security2:error] [pid 971102:tid 971245] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPxQAAAAs"]
[Thu Sep 17 15:14:26.798875 2026] [security2:error] [pid 971102:tid 971318] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPxgAAAFQ"]
[Thu Sep 17 15:14:26.811178 2026] [security2:error] [pid 971102:tid 971288] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPyAAAADY"]
[Thu Sep 17 15:14:26.814209 2026] [security2:error] [pid 971102:tid 971251] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPyQAAABE"]
[Thu Sep 17 15:14:26.816065 2026] [security2:error] [pid 971102:tid 971237] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPywAAAAM"]
[Thu Sep 17 15:14:26.821958 2026] [security2:error] [pid 971102:tid 971332] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPygAAAGI"]
[Thu Sep 17 15:14:26.853638 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/index.php"] [unique_id "aqxYMucL08BTTQixEnpP2gAAAEg"]
[Thu Sep 17 15:14:26.854579 2026] [security2:error] [pid 971102:tid 971333] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPzAAAAGM"]
[Thu Sep 17 15:14:26.893418 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP0wAAAB4"]
[Thu Sep 17 15:14:26.910574 2026] [security2:error] [pid 971102:tid 971308] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP1wAAAEo"]
[Thu Sep 17 15:14:26.927128 2026] [security2:error] [pid 971102:tid 971304] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP2QAAAEY"]
[Thu Sep 17 15:14:26.927475 2026] [security2:error] [pid 971102:tid 971247] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP2AAAAA0"]
[Thu Sep 17 15:14:26.957417 2026] [security2:error] [pid 971102:tid 971215] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxYMucL08BTTQixEnpP7QAAXG4"]
[Thu Sep 17 15:14:27.037430 2026] [security2:error] [pid 971102:tid 971110] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxYM-cL08BTTQixEnpQAgAAXAY"]
[Thu Sep 17 15:14:27.049323 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/"] [unique_id "aqxYM-cL08BTTQixEnpQBAAAAE8"]
[Thu Sep 17 15:14:27.052773 2026] [security2:error] [pid 971102:tid 971209] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/id_rsa"] [unique_id "aqxYM-cL08BTTQixEnpQBgAAXGg"]
[Thu Sep 17 15:14:27.247629 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQFAAAACk"]
[Thu Sep 17 15:14:27.320887 2026] [security2:error] [pid 971102:tid 971324] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP5AAAAFo"]
[Thu Sep 17 15:14:27.338957 2026] [security2:error] [pid 971102:tid 971289] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP6QAAADc"]
[Thu Sep 17 15:14:27.366788 2026] [security2:error] [pid 971102:tid 971270] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP9QAAACQ"]
[Thu Sep 17 15:14:27.367045 2026] [security2:error] [pid 971102:tid 971321] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP9gAAAFc"]
[Thu Sep 17 15:14:27.367574 2026] [security2:error] [pid 971102:tid 971246] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP9wAAAAw"]
[Thu Sep 17 15:14:27.369081 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP-AAAABQ"]
[Thu Sep 17 15:14:27.372037 2026] [security2:error] [pid 971102:tid 971327] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP-gAAAF0"]
[Thu Sep 17 15:14:27.377795 2026] [security2:error] [pid 971102:tid 971348] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpP_gAAAHI"]
[Thu Sep 17 15:14:27.378758 2026] [security2:error] [pid 971102:tid 971260] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP-QAAABo"]
[Thu Sep 17 15:14:27.379546 2026] [security2:error] [pid 971102:tid 971311] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQAwAAAE0"]
[Thu Sep 17 15:14:27.380993 2026] [security2:error] [pid 971102:tid 971282] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQDAAAADA"]
[Thu Sep 17 15:14:27.382607 2026] [security2:error] [pid 971102:tid 971323] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQEwAAAFk"]
[Thu Sep 17 15:14:27.435403 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/"] [unique_id "aqxYM-cL08BTTQixEnpQGwAAAE4"]
[Thu Sep 17 15:14:27.570037 2026] [security2:error] [pid 971102:tid 971332] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQIwAAAGI"]
[Thu Sep 17 15:14:27.585152 2026] [security2:error] [pid 971102:tid 971268] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQJQAAACI"]
[Thu Sep 17 15:14:27.623819 2026] [security2:error] [pid 971102:tid 971358] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQKAAAAHw"]
[Thu Sep 17 15:14:27.639741 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQRAAAAAA"]
[Thu Sep 17 15:14:27.707137 2026] [security2:error] [pid 971102:tid 971153] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config.php"] [unique_id "aqxYM-cL08BTTQixEnpQSwAAXDE"]
[Thu Sep 17 15:14:27.862016 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/includes/"] [unique_id "aqxYM-cL08BTTQixEnpQXAAAABw"]
[Thu Sep 17 15:14:28.069149 2026] [autoindex:error] [pid 971102:tid 971246] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:28.069702 2026] [security2:error] [pid 971102:tid 971246] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/includes/"] [unique_id "aqxYNOcL08BTTQixEnpQZgAAAAw"]
[Thu Sep 17 15:14:28.114326 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "aqxYNOcL08BTTQixEnpQaQAAATk"]
[Thu Sep 17 15:14:28.114334 2026] [security2:error] [pid 971102:tid 971168] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "aqxYNOcL08BTTQixEnpQbgAAAUA"]
[Thu Sep 17 15:14:28.115190 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "aqxYNOcL08BTTQixEnpQbwAAATk"]
[Thu Sep 17 15:14:28.159156 2026] [security2:error] [pid 971102:tid 971176] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "aqxYNOcL08BTTQixEnpQeAAAAUg"]
[Thu Sep 17 15:14:28.252587 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/"] [unique_id "aqxYNOcL08BTTQixEnpQeQAAAE0"]
[Thu Sep 17 15:14:28.273335 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxYNOcL08BTTQixEnpQfwAAMEk"]
[Thu Sep 17 15:14:28.277717 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxYNOcL08BTTQixEnpQfgAAMFE"]
[Thu Sep 17 15:14:28.278824 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQOwAAAB4"]
[Thu Sep 17 15:14:28.285389 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxYNOcL08BTTQixEnpQgAAAMEk"]
[Thu Sep 17 15:14:28.286603 2026] [security2:error] [pid 971102:tid 971320] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQPAAAAFY"]
[Thu Sep 17 15:14:28.295191 2026] [security2:error] [pid 971102:tid 971178] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxYNOcL08BTTQixEnpQiQAAMEo"]
[Thu Sep 17 15:14:28.297998 2026] [security2:error] [pid 971102:tid 971349] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQPgAAAHM"]
[Thu Sep 17 15:14:28.303613 2026] [security2:error] [pid 971102:tid 971247] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQQQAAAA0"]
[Thu Sep 17 15:14:28.304414 2026] [security2:error] [pid 971102:tid 971296] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQQwAAAD4"]
[Thu Sep 17 15:14:28.305319 2026] [security2:error] [pid 971102:tid 971308] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQPwAAAEo"]
[Thu Sep 17 15:14:28.317490 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQQgAAADg"]
[Thu Sep 17 15:14:28.341566 2026] [security2:error] [pid 971102:tid 971273] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQRQAAACc"]
[Thu Sep 17 15:14:28.384770 2026] [security2:error] [pid 971102:tid 971353] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQVAAAAHc"]
[Thu Sep 17 15:14:28.384771 2026] [security2:error] [pid 971102:tid 971238] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQXQAAAAQ"]
[Thu Sep 17 15:14:28.385225 2026] [security2:error] [pid 971102:tid 971361] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQSgAAAH8"]
[Thu Sep 17 15:14:28.398398 2026] [security2:error] [pid 971102:tid 971359] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQXgAAAH0"]
[Thu Sep 17 15:14:28.400282 2026] [security2:error] [pid 971102:tid 971275] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQXwAAACk"]
[Thu Sep 17 15:14:28.403212 2026] [security2:error] [pid 971102:tid 971321] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQZwAAAFc"]
[Thu Sep 17 15:14:28.403718 2026] [security2:error] [pid 971102:tid 971283] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQYAAAADE"]
[Thu Sep 17 15:14:28.407075 2026] [security2:error] [pid 971102:tid 971278] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQUQAAACw"]
[Thu Sep 17 15:14:28.465722 2026] [security2:error] [pid 971102:tid 971201] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/aws.php"] [unique_id "aqxYNOcL08BTTQixEnpQkwAAXGA"]
[Thu Sep 17 15:14:28.465731 2026] [security2:error] [pid 971102:tid 971181] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/stripe.php"] [unique_id "aqxYNOcL08BTTQixEnpQlQAAXE0"]
[Thu Sep 17 15:14:28.471436 2026] [security2:error] [pid 971102:tid 971184] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "aqxYNOcL08BTTQixEnpQmQAAZlA"]
[Thu Sep 17 15:14:28.471576 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "aqxYNOcL08BTTQixEnpQnQAAZlw"]
[Thu Sep 17 15:14:28.496728 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/.env.php"] [unique_id "aqxYNOcL08BTTQixEnpQmgAAZmk"]
[Thu Sep 17 15:14:28.524004 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/.env.php"] [unique_id "aqxYNOcL08BTTQixEnpQpAAANDs"]
[Thu Sep 17 15:14:28.539039 2026] [security2:error] [pid 971102:tid 971200] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxYNOcL08BTTQixEnpQqAAAUl8"]
[Thu Sep 17 15:14:28.542809 2026] [security2:error] [pid 971102:tid 971196] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/mail.php"] [unique_id "aqxYNOcL08BTTQixEnpQqgAAXFs"]
[Thu Sep 17 15:14:28.542842 2026] [security2:error] [pid 971102:tid 971120] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/config.inc.php"] [unique_id "aqxYNOcL08BTTQixEnpQqwAAXBA"]
[Thu Sep 17 15:14:28.547602 2026] [security2:error] [pid 971102:tid 971216] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/nexmo.php"] [unique_id "aqxYNOcL08BTTQixEnpQrgAAXG8"]
[Thu Sep 17 15:14:28.551707 2026] [security2:error] [pid 971102:tid 971106] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/wp-config.php"] [unique_id "aqxYNOcL08BTTQixEnpQsQAAXAI"]
[Thu Sep 17 15:14:28.585010 2026] [security2:error] [pid 971102:tid 971136] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxYNOcL08BTTQixEnpQtwAAACA"]
[Thu Sep 17 15:14:28.596221 2026] [security2:error] [pid 971102:tid 971110] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ivorygarlock.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYNOcL08BTTQixEnpQugAAXAY"]
[Thu Sep 17 15:14:28.599189 2026] [security2:error] [pid 971102:tid 971105] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ivorygarlock.com"] [uri "/wp-config.php.old"] [unique_id "aqxYNOcL08BTTQixEnpQuwAAXAE"]
[Thu Sep 17 15:14:28.599645 2026] [security2:error] [pid 971102:tid 971209] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ivorygarlock.com"] [uri "/wp-config.php.new"] [unique_id "aqxYNOcL08BTTQixEnpQvAAAXGg"]
[Thu Sep 17 15:14:28.601044 2026] [security2:error] [pid 971102:tid 971191] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYNOcL08BTTQixEnpQwAAAXFY"]
[Thu Sep 17 15:14:28.601628 2026] [security2:error] [pid 971102:tid 971118] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "aqxYNOcL08BTTQixEnpQvwAAEQ4"]
[Thu Sep 17 15:14:28.601748 2026] [security2:error] [pid 971102:tid 971204] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "aqxYNOcL08BTTQixEnpQvQAAEWM"]
[Thu Sep 17 15:14:28.613896 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQjwAAAH4"]
[Thu Sep 17 15:14:28.621915 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "aqxYNOcL08BTTQixEnpQxQAAEQg"]
[Thu Sep 17 15:14:28.644003 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "aqxYNOcL08BTTQixEnpQyAAAEQU"]
[Thu Sep 17 15:14:28.644054 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "aqxYNOcL08BTTQixEnpQzAAAEWE"]
[Thu Sep 17 15:14:28.644125 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "aqxYNOcL08BTTQixEnpQygAAESQ"]
[Thu Sep 17 15:14:28.644153 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "aqxYNOcL08BTTQixEnpQyQAAEWs"]
[Thu Sep 17 15:14:28.657369 2026] [security2:error] [pid 971102:tid 971285] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQpwAAADM"]
[Thu Sep 17 15:14:28.675576 2026] [security2:error] [pid 971102:tid 971261] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQtQAAABs"]
[Thu Sep 17 15:14:28.676558 2026] [security2:error] [pid 971102:tid 971218] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ0AAAdXE"]
[Thu Sep 17 15:14:28.676677 2026] [security2:error] [pid 971102:tid 971142] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "aqxYNOcL08BTTQixEnpQzwAAdSY"]
[Thu Sep 17 15:14:28.681226 2026] [security2:error] [pid 971102:tid 971356] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQtAAAAHo"]
[Thu Sep 17 15:14:28.681758 2026] [security2:error] [pid 971102:tid 971160] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ1QAAPTg"]
[Thu Sep 17 15:14:28.681899 2026] [security2:error] [pid 971102:tid 971224] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ1gAAHHc"]
[Thu Sep 17 15:14:28.682067 2026] [security2:error] [pid 971102:tid 971119] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxYNOcL08BTTQixEnpQ0gAAXA8"]
[Thu Sep 17 15:14:28.695726 2026] [security2:error] [pid 971102:tid 971104] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ2QAAJAA"]
[Thu Sep 17 15:14:28.703449 2026] [security2:error] [pid 971102:tid 971206] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ2wAABmU"]
[Thu Sep 17 15:14:28.723982 2026] [security2:error] [pid 971102:tid 971334] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQwQAAAGQ"]
[Thu Sep 17 15:14:28.739906 2026] [security2:error] [pid 971102:tid 971231] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ5QAAbH4"]
[Thu Sep 17 15:14:28.740003 2026] [security2:error] [pid 971102:tid 971114] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ5gAAbAo"]
[Thu Sep 17 15:14:28.752606 2026] [security2:error] [pid 971102:tid 971158] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ5wAAEDY"]
[Thu Sep 17 15:14:28.754654 2026] [security2:error] [pid 971102:tid 971288] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQxwAAADY"]
[Thu Sep 17 15:14:28.772028 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ6QAARDI"]
[Thu Sep 17 15:14:28.775501 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ6gAAczE"]
[Thu Sep 17 15:14:28.782547 2026] [security2:error] [pid 971102:tid 971174] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ6wAAPkY"]
[Thu Sep 17 15:14:28.782601 2026] [security2:error] [pid 971102:tid 971134] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7QAAPh4"]
[Thu Sep 17 15:14:28.782643 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7wAAPgc"]
[Thu Sep 17 15:14:28.782643 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7gAAPkQ"]
[Thu Sep 17 15:14:28.782918 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7AAAPlM"]
[Thu Sep 17 15:14:28.795961 2026] [security2:error] [pid 971102:tid 971167] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ8gAAeD8"]
[Thu Sep 17 15:14:28.804929 2026] [security2:error] [pid 971102:tid 971175] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ9QAAL0c"]
[Thu Sep 17 15:14:28.815366 2026] [security2:error] [pid 971102:tid 971176] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ9wAAF0g"]
[Thu Sep 17 15:14:28.815499 2026] [security2:error] [pid 971102:tid 971150] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxYNOcL08BTTQixEnpQ9gAAXC4"]
[Thu Sep 17 15:14:28.829117 2026] [security2:error] [pid 971102:tid 971139] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ_QAAeSM"]
[Thu Sep 17 15:14:28.839676 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxYNOcL08BTTQixEnpRAQAAOg0"]
[Thu Sep 17 15:14:28.852050 2026] [security2:error] [pid 971102:tid 971157] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBgAAUTU"]
[Thu Sep 17 15:14:28.852062 2026] [security2:error] [pid 971102:tid 971179] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "aqxYNOcL08BTTQixEnpRAwAAUUs"]
[Thu Sep 17 15:14:28.852122 2026] [security2:error] [pid 971102:tid 971164] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBAAAUTw"]
[Thu Sep 17 15:14:28.852128 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBQAAUQQ"]
[Thu Sep 17 15:14:28.852188 2026] [security2:error] [pid 971102:tid 971170] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBwAAUUI"]
[Thu Sep 17 15:14:28.993717 2026] [security2:error] [pid 971102:tid 971229] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxYNOcL08BTTQixEnpRHQAAC3w"]
[Thu Sep 17 15:14:29.008148 2026] [security2:error] [pid 971102:tid 971159] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "aqxYNecL08BTTQixEnpRHgAAaDc"]
[Thu Sep 17 15:14:29.008178 2026] [security2:error] [pid 971102:tid 971144] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRHwAAaCg"]
[Thu Sep 17 15:14:29.008224 2026] [security2:error] [pid 971102:tid 971149] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "aqxYNecL08BTTQixEnpRKgAAaC0"]
[Thu Sep 17 15:14:29.008274 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "aqxYNecL08BTTQixEnpRLQAAaCI"]
[Thu Sep 17 15:14:29.008279 2026] [security2:error] [pid 971102:tid 971113] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "aqxYNecL08BTTQixEnpRKAAAaAk"]
[Thu Sep 17 15:14:29.008316 2026] [security2:error] [pid 971102:tid 971146] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRJAAAaCo"]
[Thu Sep 17 15:14:29.008318 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "aqxYNecL08BTTQixEnpRIQAAaBU"]
[Thu Sep 17 15:14:29.008353 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRJQAAaBs"]
[Thu Sep 17 15:14:29.008413 2026] [security2:error] [pid 971102:tid 971129] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "aqxYNecL08BTTQixEnpRLAAAaBk"]
[Thu Sep 17 15:14:29.008414 2026] [security2:error] [pid 971102:tid 971211] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRIwAAaGo"]
[Thu Sep 17 15:14:29.008440 2026] [security2:error] [pid 971102:tid 971135] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "aqxYNecL08BTTQixEnpRJgAAaB8"]
[Thu Sep 17 15:14:29.008474 2026] [security2:error] [pid 971102:tid 971195] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "aqxYNecL08BTTQixEnpRIAAAaFo"]
[Thu Sep 17 15:14:29.008480 2026] [security2:error] [pid 971102:tid 971152] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "aqxYNecL08BTTQixEnpRIgAAaDA"]
[Thu Sep 17 15:14:29.043842 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxYNecL08BTTQixEnpRMAAAIUk"]
[Thu Sep 17 15:14:29.043901 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxYNecL08BTTQixEnpRLwAAIUM"]
[Thu Sep 17 15:14:29.043904 2026] [security2:error] [pid 971102:tid 971205] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxYNecL08BTTQixEnpRMwAAIWQ"]
[Thu Sep 17 15:14:29.043936 2026] [security2:error] [pid 971102:tid 971201] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxYNecL08BTTQixEnpRMgAAIWA"]
[Thu Sep 17 15:14:29.043958 2026] [security2:error] [pid 971102:tid 971181] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxYNecL08BTTQixEnpRMQAAIU0"]
[Thu Sep 17 15:14:29.060623 2026] [security2:error] [pid 971102:tid 971182] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "aqxYNecL08BTTQixEnpRJwAAaE4"]
[Thu Sep 17 15:14:29.132122 2026] [security2:error] [pid 971102:tid 971184] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxYNecL08BTTQixEnpRNgAAU1A"]
[Thu Sep 17 15:14:29.168474 2026] [security2:error] [pid 971102:tid 971143] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxYNecL08BTTQixEnpRPgAAQCc"]
[Thu Sep 17 15:14:29.168476 2026] [security2:error] [pid 971102:tid 971193] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/back/.env"] [unique_id "aqxYNecL08BTTQixEnpROgAAQFg"]
[Thu Sep 17 15:14:29.168504 2026] [security2:error] [pid 971102:tid 971192] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxYNecL08BTTQixEnpRQAAAQFc"]
[Thu Sep 17 15:14:29.168576 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxYNecL08BTTQixEnpRPQAAQHg"]
[Thu Sep 17 15:14:29.168576 2026] [security2:error] [pid 971102:tid 971198] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxYNecL08BTTQixEnpRPwAAQF0"]
[Thu Sep 17 15:14:29.168609 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxYNecL08BTTQixEnpROQAAQGk"]
[Thu Sep 17 15:14:29.168609 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxYNecL08BTTQixEnpRPAAAQG0"]
[Thu Sep 17 15:14:29.168624 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "aqxYNecL08BTTQixEnpRQQAAEzs"]
[Thu Sep 17 15:14:29.168806 2026] [security2:error] [pid 971102:tid 971207] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxYNecL08BTTQixEnpROwAAQGY"]
[Thu Sep 17 15:14:29.220502 2026] [security2:error] [pid 971102:tid 971222] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "aqxYNecL08BTTQixEnpRSQAAWHU"]
[Thu Sep 17 15:14:29.220613 2026] [security2:error] [pid 971102:tid 971186] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "aqxYNecL08BTTQixEnpRUQAAWFI"]
[Thu Sep 17 15:14:29.224769 2026] [security2:error] [pid 971102:tid 971191] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxYNecL08BTTQixEnpRUwAAFFY"]
[Thu Sep 17 15:14:29.243417 2026] [security2:error] [pid 971102:tid 971204] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxYNecL08BTTQixEnpRWAAAFmM"]
[Thu Sep 17 15:14:29.243455 2026] [security2:error] [pid 971102:tid 971118] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxYNecL08BTTQixEnpRVAAAFg4"]
[Thu Sep 17 15:14:29.243502 2026] [security2:error] [pid 971102:tid 971194] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/node-api/.env"] [unique_id "aqxYNecL08BTTQixEnpRVgAAFlk"]
[Thu Sep 17 15:14:29.243505 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/api-backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRVQAAFgg"]
[Thu Sep 17 15:14:29.243573 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/new/.env"] [unique_id "aqxYNecL08BTTQixEnpRVwAAFl4"]
[Thu Sep 17 15:14:29.284941 2026] [security2:error] [pid 971102:tid 971276] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQzgAAACo"]
[Thu Sep 17 15:14:29.310897 2026] [security2:error] [pid 971102:tid 971326] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ0wAAXBY"]
[Thu Sep 17 15:14:29.331609 2026] [security2:error] [pid 971102:tid 971289] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ2gAAADc"]
[Thu Sep 17 15:14:29.342449 2026] [security2:error] [pid 971102:tid 971327] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ3AAAAF0"]
[Thu Sep 17 15:14:29.392378 2026] [security2:error] [pid 971102:tid 971304] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpREAAAAEY"]
[Thu Sep 17 15:14:29.393444 2026] [security2:error] [pid 971102:tid 971318] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRQgAAAFQ"]
[Thu Sep 17 15:14:29.396448 2026] [security2:error] [pid 971102:tid 971330] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpRCgAAAGA"]
[Thu Sep 17 15:14:29.396945 2026] [security2:error] [pid 971102:tid 971278] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpRGAAAACw"]
[Thu Sep 17 15:14:29.397989 2026] [security2:error] [pid 971102:tid 971283] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpREwAAADE"]
[Thu Sep 17 15:14:29.398349 2026] [security2:error] [pid 971102:tid 971359] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpREQAAAH0"]
[Thu Sep 17 15:14:29.401214 2026] [security2:error] [pid 971102:tid 971280] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ9AAAAC4"]
[Thu Sep 17 15:14:29.402444 2026] [security2:error] [pid 971102:tid 971313] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXAAAAE8"]
[Thu Sep 17 15:14:29.422351 2026] [security2:error] [pid 971102:tid 971242] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpRAAAAAAg"]
[Thu Sep 17 15:14:29.432998 2026] [security2:error] [pid 971102:tid 971282] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXgAAADA"]
[Thu Sep 17 15:14:29.435919 2026] [security2:error] [pid 971102:tid 971350] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXQAAAHQ"]
[Thu Sep 17 15:14:29.441138 2026] [security2:error] [pid 971102:tid 971345] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXwAAAG8"]
[Thu Sep 17 15:14:29.509966 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYNecL08BTTQixEnpRbgAAAAM"]
[Thu Sep 17 15:14:29.510051 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:44616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYNecL08BTTQixEnpRbgAAAAM"]
[Thu Sep 17 15:14:29.528720 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxYNecL08BTTQixEnpRdgAADU8"]
[Thu Sep 17 15:14:29.528721 2026] [security2:error] [pid 971102:tid 971206] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/server/api/.env"] [unique_id "aqxYNecL08BTTQixEnpRegAADWU"]
[Thu Sep 17 15:14:29.528797 2026] [security2:error] [pid 971102:tid 971162] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.docker/.env"] [unique_id "aqxYNecL08BTTQixEnpReQAADTo"]
[Thu Sep 17 15:14:29.528837 2026] [security2:error] [pid 971102:tid 971224] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/admin-app/.env"] [unique_id "aqxYNecL08BTTQixEnpRcgAADXc"]
[Thu Sep 17 15:14:29.528868 2026] [security2:error] [pid 971102:tid 971208] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxYNecL08BTTQixEnpRcQAADWc"]
[Thu Sep 17 15:14:29.528885 2026] [security2:error] [pid 971102:tid 971151] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/server/backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRdAAADS8"]
[Thu Sep 17 15:14:29.528974 2026] [security2:error] [pid 971102:tid 971116] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxYNecL08BTTQixEnpReAAADQw"]
[Thu Sep 17 15:14:29.563903 2026] [security2:error] [pid 971102:tid 971174] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRhgAAOEY"]
[Thu Sep 17 15:14:29.564004 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRiAAAODE"]
[Thu Sep 17 15:14:29.564084 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxYNecL08BTTQixEnpRiwAAOFM"]
[Thu Sep 17 15:14:29.564106 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.docker/laravel/app/.env"] [unique_id "aqxYNecL08BTTQixEnpRjAAAODI"]
[Thu Sep 17 15:14:29.564123 2026] [security2:error] [pid 971102:tid 971230] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxYNecL08BTTQixEnpRjQAAOH0"]
[Thu Sep 17 15:14:29.564176 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/stripe/.env"] [unique_id "aqxYNecL08BTTQixEnpRiQAAOAc"]
[Thu Sep 17 15:14:29.568683 2026] [security2:error] [pid 971102:tid 971249] [client 186.105.232.15:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRjwAAAA8"]
[Thu Sep 17 15:14:29.568769 2026] [security2:error] [pid 971102:tid 971249] [client 186.105.232.15:61401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRjwAAAA8"]
[Thu Sep 17 15:14:29.570924 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRkAAAAEw"]
[Thu Sep 17 15:14:29.571555 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:56953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRkAAAAEw"]
[Thu Sep 17 15:14:29.602868 2026] [security2:error] [pid 971102:tid 971342] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRawAAAGw"]
[Thu Sep 17 15:14:29.604204 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRbAAAAB4"]
[Thu Sep 17 15:14:29.680321 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/.env.php"] [unique_id "aqxYNecL08BTTQixEnpRpAAAVw0"]
[Thu Sep 17 15:14:29.684531 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/credentials.bak"] [unique_id "aqxYNecL08BTTQixEnpRqQAACwQ"]
[Thu Sep 17 15:14:29.693393 2026] [security2:error] [pid 971102:tid 971159] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxYNecL08BTTQixEnpRrQAAaDc"]
[Thu Sep 17 15:14:29.693402 2026] [security2:error] [pid 971102:tid 971229] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxYNecL08BTTQixEnpRsgAAaHw"]
[Thu Sep 17 15:14:29.694626 2026] [security2:error] [pid 971102:tid 971137] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxYNecL08BTTQixEnpRsQAAaCE"]
[Thu Sep 17 15:14:29.699977 2026] [security2:error] [pid 971102:tid 971152] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.ssh/id_rsa"] [unique_id "aqxYNecL08BTTQixEnpRwQAARzA"]
[Thu Sep 17 15:14:29.700823 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/id_rsa"] [unique_id "aqxYNecL08BTTQixEnpRwgAAR1E"]
[Thu Sep 17 15:14:29.735154 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/upgrade/"] [unique_id "aqxYNecL08BTTQixEnpRywAAADU"]
[Thu Sep 17 15:14:29.752202 2026] [security2:error] [pid 971102:tid 971205] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxYNecL08BTTQixEnpRzgAAB2Q"]
[Thu Sep 17 15:14:29.899858 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/media/.env"] [unique_id "aqxYNecL08BTTQixEnpR4AAALGk"]
[Thu Sep 17 15:14:29.901740 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxYNecL08BTTQixEnpR4QAAX20"]
[Thu Sep 17 15:14:29.901759 2026] [security2:error] [pid 971102:tid 971207] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxYNecL08BTTQixEnpR4gAAX2Y"]
[Thu Sep 17 15:14:29.957956 2026] [autoindex:error] [pid 971102:tid 971359] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:29.959137 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/upgrade/"] [unique_id "aqxYNecL08BTTQixEnpR6AAAAH0"]
[Thu Sep 17 15:14:29.986420 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxYNecL08BTTQixEnpR7QAAUl4"]
[Thu Sep 17 15:14:30.002219 2026] [security2:error] [pid 971102:tid 971298] [client 115.244.164.14:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNucL08BTTQixEnpR7gAAAEA"]
[Thu Sep 17 15:14:30.002315 2026] [security2:error] [pid 971102:tid 971298] [client 115.244.164.14:61983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNucL08BTTQixEnpR7gAAAEA"]
[Thu Sep 17 15:14:30.045337 2026] [security2:error] [pid 971102:tid 971190] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxYNucL08BTTQixEnpR9QAAEVU"]
[Thu Sep 17 15:14:30.090725 2026] [security2:error] [pid 971102:tid 971107] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxYNucL08BTTQixEnpR-wAALQM"]
[Thu Sep 17 15:14:30.233509 2026] [security2:error] [pid 971102:tid 971123] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxYNucL08BTTQixEnpR_QAAChM"]
[Thu Sep 17 15:14:30.233543 2026] [security2:error] [pid 971102:tid 971209] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxYNucL08BTTQixEnpR_gAACmg"]
[Thu Sep 17 15:14:30.288419 2026] [security2:error] [pid 971102:tid 971292] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRmwAAADo"]
[Thu Sep 17 15:14:30.360197 2026] [security2:error] [pid 971102:tid 971273] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRoAAAACc"]
[Thu Sep 17 15:14:30.361978 2026] [security2:error] [pid 971102:tid 971339] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRnwAAAGk"]
[Thu Sep 17 15:14:30.372807 2026] [security2:error] [pid 971102:tid 971332] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRngAAAGI"]
[Thu Sep 17 15:14:30.382676 2026] [security2:error] [pid 971102:tid 971325] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRogAAAFs"]
[Thu Sep 17 15:14:30.384895 2026] [security2:error] [pid 971102:tid 971344] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRoQAAAG4"]
[Thu Sep 17 15:14:30.385991 2026] [security2:error] [pid 971102:tid 971168] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxYNucL08BTTQixEnpSBgAABkA"]
[Thu Sep 17 15:14:30.392807 2026] [security2:error] [pid 971102:tid 971268] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRzQAAACI"]
[Thu Sep 17 15:14:30.396524 2026] [security2:error] [pid 971102:tid 971276] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRzAAAACo"]
[Thu Sep 17 15:14:30.397406 2026] [security2:error] [pid 971102:tid 971353] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRpQAAAHc"]
[Thu Sep 17 15:14:30.397975 2026] [security2:error] [pid 971102:tid 971330] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpR3QAAAGA"]
[Thu Sep 17 15:14:30.401300 2026] [security2:error] [pid 971102:tid 971289] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRzwAAADc"]
[Thu Sep 17 15:14:30.401895 2026] [security2:error] [pid 971102:tid 971253] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRyAAAABM"]
[Thu Sep 17 15:14:30.408804 2026] [security2:error] [pid 971102:tid 971256] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRygAAABY"]
[Thu Sep 17 15:14:30.410909 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRyQAAABQ"]
[Thu Sep 17 15:14:30.416848 2026] [security2:error] [pid 971102:tid 971318] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpR1wAAAFQ"]
[Thu Sep 17 15:14:30.428969 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxYNucL08BTTQixEnpSDgAARAU"]
[Thu Sep 17 15:14:30.429077 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxYNucL08BTTQixEnpSDwAARFw"]
[Thu Sep 17 15:14:30.446192 2026] [security2:error] [pid 971102:tid 971284] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpR8gAAADI"]
[Thu Sep 17 15:14:30.446449 2026] [security2:error] [pid 971102:tid 971133] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config.php"] [unique_id "aqxYNucL08BTTQixEnpSEgAADR0"]
[Thu Sep 17 15:14:30.485144 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxYNucL08BTTQixEnpSFQAAHiQ"]
[Thu Sep 17 15:14:30.512172 2026] [security2:error] [pid 971102:tid 971162] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSHAAAXDo"]
[Thu Sep 17 15:14:30.528155 2026] [security2:error] [pid 971102:tid 971208] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/info.php"] [unique_id "aqxYNucL08BTTQixEnpSHwAAXGc"]
[Thu Sep 17 15:14:30.533031 2026] [security2:error] [pid 971102:tid 971151] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/infos.php"] [unique_id "aqxYNucL08BTTQixEnpSIAAAXC8"]
[Thu Sep 17 15:14:30.535988 2026] [security2:error] [pid 971102:tid 971116] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/php.php"] [unique_id "aqxYNucL08BTTQixEnpSIgAAXAw"]
[Thu Sep 17 15:14:30.535996 2026] [security2:error] [pid 971102:tid 971119] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/php_info.php"] [unique_id "aqxYNucL08BTTQixEnpSIwAAXA8"]
[Thu Sep 17 15:14:30.537648 2026] [security2:error] [pid 971102:tid 971128] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/infophp.php"] [unique_id "aqxYNucL08BTTQixEnpSJgAAXBg"]
[Thu Sep 17 15:14:30.537706 2026] [security2:error] [pid 971102:tid 971156] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/php-info.php"] [unique_id "aqxYNucL08BTTQixEnpSJQAAXDQ"]
[Thu Sep 17 15:14:30.545648 2026] [security2:error] [pid 971102:tid 971115] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSKgAAXAs"]
[Thu Sep 17 15:14:30.548914 2026] [security2:error] [pid 971102:tid 971114] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSLQAAXAo"]
[Thu Sep 17 15:14:30.562129 2026] [security2:error] [pid 971102:tid 971174] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSLgAAXEY"]
[Thu Sep 17 15:14:30.571942 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxYNucL08BTTQixEnpSMQAAQlM"]
[Thu Sep 17 15:14:30.578550 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSEwAAADg"]
[Thu Sep 17 15:14:30.635006 2026] [security2:error] [pid 971102:tid 971167] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSOgAAXD8"]
[Thu Sep 17 15:14:30.646366 2026] [security2:error] [pid 971102:tid 971104] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSOwAAXAA"]
[Thu Sep 17 15:14:30.650715 2026] [security2:error] [pid 971102:tid 971357] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSKQAAAHs"]
[Thu Sep 17 15:14:30.688560 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxYNucL08BTTQixEnpSTwAALlE"]
[Thu Sep 17 15:14:30.697124 2026] [security2:error] [pid 971102:tid 971177] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/database.sql"] [unique_id "aqxYNucL08BTTQixEnpSUAAAXEk"]
[Thu Sep 17 15:14:30.725730 2026] [security2:error] [pid 971102:tid 971211] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/aws.php"] [unique_id "aqxYNucL08BTTQixEnpSUwAAG2o"]
[Thu Sep 17 15:14:30.732341 2026] [security2:error] [pid 971102:tid 971122] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxYNucL08BTTQixEnpSVwAAKRI"]
[Thu Sep 17 15:14:30.774184 2026] [security2:error] [pid 971102:tid 971160] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxYNucL08BTTQixEnpSXwAAZTg"]
[Thu Sep 17 15:14:30.774418 2026] [security2:error] [pid 971102:tid 971149] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxYNucL08BTTQixEnpSYAAAZS0"]
[Thu Sep 17 15:14:30.793915 2026] [security2:error] [pid 971102:tid 971135] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/stripe.php"] [unique_id "aqxYNucL08BTTQixEnpSZwAAJB8"]
[Thu Sep 17 15:14:30.794404 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/mail.php"] [unique_id "aqxYNucL08BTTQixEnpSaQAAJBU"]
[Thu Sep 17 15:14:30.820298 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/config.inc.php"] [unique_id "aqxYNucL08BTTQixEnpSbQAAThs"]
[Thu Sep 17 15:14:30.837441 2026] [security2:error] [pid 971102:tid 971201] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxYNucL08BTTQixEnpSdAAAWWA"]
[Thu Sep 17 15:14:30.840252 2026] [security2:error] [pid 971102:tid 971182] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/nexmo.php"] [unique_id "aqxYNucL08BTTQixEnpSdQAAGU4"]
[Thu Sep 17 15:14:30.933890 2026] [security2:error] [pid 971102:tid 971258] [client 189.203.228.241:21134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYNucL08BTTQixEnpSbgAAGBk"]
[Thu Sep 17 15:14:30.935885 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYNucL08BTTQixEnpSewAABmk"]
[Thu Sep 17 15:14:30.936266 2026] [security2:error] [pid 971102:tid 971222] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php"] [unique_id "aqxYNucL08BTTQixEnpSegAABnU"]
[Thu Sep 17 15:14:30.941116 2026] [security2:error] [pid 971102:tid 971193] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php.old"] [unique_id "aqxYNucL08BTTQixEnpSfAAAa1g"]
[Thu Sep 17 15:14:31.038512 2026] [security2:error] [pid 971102:tid 971192] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php.new"] [unique_id "aqxYN-cL08BTTQixEnpSgAAAU1c"]
[Thu Sep 17 15:14:31.038881 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYN-cL08BTTQixEnpSggAAUzs"]
[Thu Sep 17 15:14:31.045442 2026] [security2:error] [pid 971102:tid 971120] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/back/.env"] [unique_id "aqxYN-cL08BTTQixEnpSgwAAbxA"]
[Thu Sep 17 15:14:31.045462 2026] [security2:error] [pid 971102:tid 971196] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxYN-cL08BTTQixEnpShAAAb1s"]
[Thu Sep 17 15:14:31.069347 2026] [security2:error] [pid 971102:tid 971191] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxYN-cL08BTTQixEnpShwAAbVY"]
[Thu Sep 17 15:14:31.081899 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "aqxYN-cL08BTTQixEnpSigAAL14"]
[Thu Sep 17 15:14:31.187383 2026] [security2:error] [pid 971102:tid 971126] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxYN-cL08BTTQixEnpSkQAAZBY"]
[Thu Sep 17 15:14:31.187431 2026] [security2:error] [pid 971102:tid 971220] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxYN-cL08BTTQixEnpSkgAAZHM"]
[Thu Sep 17 15:14:31.227822 2026] [security2:error] [pid 971102:tid 971110] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "aqxYN-cL08BTTQixEnpSkwAAIQY"]
[Thu Sep 17 15:14:31.298931 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSOQAAADg"]
[Thu Sep 17 15:14:31.299029 2026] [security2:error] [pid 971102:tid 971288] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSOAAAADY"]
[Thu Sep 17 15:14:31.300862 2026] [security2:error] [pid 971102:tid 971307] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSNwAAAEk"]
[Thu Sep 17 15:14:31.339774 2026] [security2:error] [pid 971102:tid 971232] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxYN-cL08BTTQixEnpSmQAAWH8"]
[Thu Sep 17 15:14:31.340877 2026] [security2:error] [pid 971102:tid 971209] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxYN-cL08BTTQixEnpSmgAAWGg"]
[Thu Sep 17 15:14:31.397798 2026] [security2:error] [pid 971102:tid 971244] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSXAAAAAo"]
[Thu Sep 17 15:14:31.399520 2026] [security2:error] [pid 971102:tid 971251] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSUgAAABE"]
[Thu Sep 17 15:14:31.401899 2026] [security2:error] [pid 971102:tid 971234] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSWgAAAAA"]
[Thu Sep 17 15:14:31.402784 2026] [security2:error] [pid 971102:tid 971339] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSawAAAGk"]
[Thu Sep 17 15:14:31.405947 2026] [security2:error] [pid 971102:tid 971347] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSVgAAAHE"]
[Thu Sep 17 15:14:31.407093 2026] [security2:error] [pid 971102:tid 971295] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSWwAAAD0"]
[Thu Sep 17 15:14:31.417353 2026] [security2:error] [pid 971102:tid 971351] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSUQAAAHU"]
[Thu Sep 17 15:14:31.420495 2026] [security2:error] [pid 971102:tid 971279] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSWQAAAC0"]
[Thu Sep 17 15:14:31.421014 2026] [security2:error] [pid 971102:tid 971273] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSagAAACc"]
[Thu Sep 17 15:14:31.425906 2026] [security2:error] [pid 971102:tid 971325] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSeAAAAFs"]
[Thu Sep 17 15:14:31.430085 2026] [security2:error] [pid 971102:tid 971331] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSbAAAAGE"]
[Thu Sep 17 15:14:31.433324 2026] [security2:error] [pid 971102:tid 971350] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSeQAAAHQ"]
[Thu Sep 17 15:14:31.549361 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxYN-cL08BTTQixEnpSpwAAcDk"]
[Thu Sep 17 15:14:31.549423 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxYN-cL08BTTQixEnpSqAAAcEM"]
[Thu Sep 17 15:14:31.586108 2026] [security2:error] [pid 971102:tid 971109] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/admin_dev.php"] [unique_id "aqxYN-cL08BTTQixEnpStwAAXAU"]
[Thu Sep 17 15:14:31.589545 2026] [security2:error] [pid 971102:tid 971212] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.sh_history"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.sh_history"] [unique_id "aqxYN-cL08BTTQixEnpSvwAAXGs"]
[Thu Sep 17 15:14:31.591315 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/new/.env"] [unique_id "aqxYN-cL08BTTQixEnpSwAAAWlQ"]
[Thu Sep 17 15:14:31.591576 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/node-api/.env"] [unique_id "aqxYN-cL08BTTQixEnpSwQAAWgg"]
[Thu Sep 17 15:14:31.631348 2026] [security2:error] [pid 971102:tid 971336] [client 185.55.149.49:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYN-cL08BTTQixEnpS0AAAAGY"]
[Thu Sep 17 15:14:31.631476 2026] [security2:error] [pid 971102:tid 971336] [client 185.55.149.49:60635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYN-cL08BTTQixEnpS0AAAAGY"]
[Thu Sep 17 15:14:31.724515 2026] [security2:error] [pid 971102:tid 971115] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/opt/.env"] [unique_id "aqxYN-cL08BTTQixEnpS3gAAXAs"]
[Thu Sep 17 15:14:31.729025 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/api-backend/.env"] [unique_id "aqxYN-cL08BTTQixEnpS5gAAalM"]
[Thu Sep 17 15:14:31.729060 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/admin-app/.env"] [unique_id "aqxYN-cL08BTTQixEnpS5wAAajE"]
[Thu Sep 17 15:14:31.735435 2026] [security2:error] [pid 971102:tid 971294] [client 160.177.85.210:38056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRowAAPD4"], referer: https://www.enolastable.com/2021/07/16/what-inspired-the-table/
[Thu Sep 17 15:14:31.853789 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxYN-cL08BTTQixEnpS9gAACkk"]
[Thu Sep 17 15:14:31.853792 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/server/backend/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_wAACkQ"]
[Thu Sep 17 15:14:31.853864 2026] [security2:error] [pid 971102:tid 971104] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-AAACgA"]
[Thu Sep 17 15:14:31.853867 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-QAACiw"]
[Thu Sep 17 15:14:31.853867 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.aws/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-gAACgQ"]
[Thu Sep 17 15:14:31.853915 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/stripe/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_AAACk8"]
[Thu Sep 17 15:14:31.853954 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.docker/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_QAAClE"]
[Thu Sep 17 15:14:31.853993 2026] [security2:error] [pid 971102:tid 971215] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/server/api/.env"] [unique_id "aqxYN-cL08BTTQixEnpS9wAACm4"]
[Thu Sep 17 15:14:31.854003 2026] [security2:error] [pid 971102:tid 971213] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_gAACmw"]
[Thu Sep 17 15:14:31.854034 2026] [security2:error] [pid 971102:tid 971130] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.docker/laravel/app/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-wAACho"]
[Thu Sep 17 15:14:31.901960 2026] [security2:error] [pid 971102:tid 971261] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS1AAAG2E"], referer: http://www.talent-in-borders.com/wp/
[Thu Sep 17 15:14:31.951525 2026] [security2:error] [pid 971102:tid 971217] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxYN-cL08BTTQixEnpTCwAALXA"]
[Thu Sep 17 15:14:31.998103 2026] [security2:error] [pid 971102:tid 971201] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxYN-cL08BTTQixEnpTDQAAEGA"]
[Thu Sep 17 15:14:31.998130 2026] [security2:error] [pid 971102:tid 971182] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxYN-cL08BTTQixEnpTDgAAEE4"]
[Thu Sep 17 15:14:31.999225 2026] [security2:error] [pid 971102:tid 971173] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/media/.env"] [unique_id "aqxYN-cL08BTTQixEnpTDwAAEEU"]
[Thu Sep 17 15:14:32.042703 2026] [security2:error] [pid 971102:tid 971305] [client 65.21.44.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.edmagik.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSVQAAAEc"]
[Thu Sep 17 15:14:32.072456 2026] [security2:error] [pid 971102:tid 971266] [client 65.21.44.205:59488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.edmagik.com"] [uri "/robots.txt"] [unique_id "aqxYNucL08BTTQixEnpSIQAAACA"]
[Thu Sep 17 15:14:32.141547 2026] [security2:error] [pid 971102:tid 971219] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.git/config.bak"] [unique_id "aqxYOOcL08BTTQixEnpTKgAAEHI"]
[Thu Sep 17 15:14:32.205992 2026] [security2:error] [pid 971102:tid 971247] [client 5.189.145.112:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxYOOcL08BTTQixEnpTLgAAAA0"], referer: binance.com
[Thu Sep 17 15:14:32.313096 2026] [security2:error] [pid 971102:tid 971345] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzAAAAG8"]
[Thu Sep 17 15:14:32.313784 2026] [security2:error] [pid 971102:tid 971293] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSygAAADs"]
[Thu Sep 17 15:14:32.315365 2026] [security2:error] [pid 971102:tid 971258] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSxQAAABg"]
[Thu Sep 17 15:14:32.325174 2026] [security2:error] [pid 971102:tid 971353] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSywAAAHc"]
[Thu Sep 17 15:14:32.329199 2026] [security2:error] [pid 971102:tid 971253] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzgAAABM"]
[Thu Sep 17 15:14:32.336167 2026] [security2:error] [pid 971102:tid 971309] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzQAAAEs"]
[Thu Sep 17 15:14:32.354995 2026] [security2:error] [pid 971102:tid 971343] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzwAAAG0"]
[Thu Sep 17 15:14:32.400154 2026] [security2:error] [pid 971102:tid 971245] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS7QAAAAs"]
[Thu Sep 17 15:14:32.400408 2026] [security2:error] [pid 971102:tid 971248] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS9AAAAA4"]
[Thu Sep 17 15:14:32.407332 2026] [security2:error] [pid 971102:tid 971307] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS7gAAAEk"]
[Thu Sep 17 15:14:32.411026 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS7AAAADg"]
[Thu Sep 17 15:14:32.411429 2026] [security2:error] [pid 971102:tid 971326] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpTAwAAXHo"]
[Thu Sep 17 15:14:32.416099 2026] [security2:error] [pid 971102:tid 971319] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS6wAAAFU"]
[Thu Sep 17 15:14:32.417722 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS8gAAABQ"]
[Thu Sep 17 15:14:32.421833 2026] [security2:error] [pid 971102:tid 971326] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpTDAAAXBs"]
[Thu Sep 17 15:14:32.434998 2026] [security2:error] [pid 971102:tid 971349] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS8wAAAHM"]
[Thu Sep 17 15:14:32.452710 2026] [security2:error] [pid 971102:tid 971139] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/db_backup.sql"] [unique_id "aqxYOOcL08BTTQixEnpTQAAAXCM"]
[Thu Sep 17 15:14:32.475178 2026] [security2:error] [pid 971102:tid 971150] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.aws/credentials.bak"] [unique_id "aqxYOOcL08BTTQixEnpTSgAAbi4"]
[Thu Sep 17 15:14:32.475189 2026] [security2:error] [pid 971102:tid 971195] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.ssh/id_rsa"] [unique_id "aqxYOOcL08BTTQixEnpTRgAAblo"]
[Thu Sep 17 15:14:32.475238 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/id_rsa"] [unique_id "aqxYOOcL08BTTQixEnpTRQAAbng"]
[Thu Sep 17 15:14:32.478194 2026] [security2:error] [pid 971102:tid 971169] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/local/.env"] [unique_id "aqxYOOcL08BTTQixEnpTTQAAXEE"]
[Thu Sep 17 15:14:32.619450 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpTYQAAZVw"]
[Thu Sep 17 15:14:32.628574 2026] [security2:error] [pid 971102:tid 971261] [client 65.21.44.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.edmagik.com"] [uri "/wp"] [unique_id "aqxYOOcL08BTTQixEnpTYgAAABs"]
[Thu Sep 17 15:14:32.635307 2026] [security2:error] [pid 971102:tid 971240] [client 65.21.44.205:59502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.edmagik.com"] [uri "/wp"] [unique_id "aqxYOOcL08BTTQixEnpTWQAAAAY"]
[Thu Sep 17 15:14:32.640069 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/info.php"] [unique_id "aqxYOOcL08BTTQixEnpTZQAAZVQ"]
[Thu Sep 17 15:14:32.684818 2026] [security2:error] [pid 971102:tid 971287] [client 167.172.76.13:56456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTTgAANXw"], referer: https://www.talent-in-borders.com/wp/
[Thu Sep 17 15:14:32.721646 2026] [security2:error] [pid 971102:tid 971322] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTVwAAAFg"]
[Thu Sep 17 15:14:32.721989 2026] [security2:error] [pid 971102:tid 971251] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTVgAAABE"]
[Thu Sep 17 15:14:32.787427 2026] [security2:error] [pid 971102:tid 971347] [client 171.96.135.239:61435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTYwAAcRc"]
[Thu Sep 17 15:14:32.923098 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/infos.php"] [unique_id "aqxYOOcL08BTTQixEnpTeAAAB1M"]
[Thu Sep 17 15:14:32.928311 2026] [security2:error] [pid 971102:tid 971166] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/php_info.php"] [unique_id "aqxYOOcL08BTTQixEnpTewAAWT4"]
[Thu Sep 17 15:14:32.928329 2026] [security2:error] [pid 971102:tid 971164] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/php.php"] [unique_id "aqxYOOcL08BTTQixEnpTfAAAWTw"]
[Thu Sep 17 15:14:32.928357 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/php-info.php"] [unique_id "aqxYOOcL08BTTQixEnpTfQAAWTI"]
[Thu Sep 17 15:14:32.928383 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/infophp.php"] [unique_id "aqxYOOcL08BTTQixEnpTfgAAWQc"]
[Thu Sep 17 15:14:32.951287 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpTggAAf1E"]
[Thu Sep 17 15:14:32.951305 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpTgQAAf08"]
[Thu Sep 17 15:14:32.951339 2026] [security2:error] [pid 971102:tid 971215] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpThAAAf24"]
[Thu Sep 17 15:14:32.951364 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpThQAAfyw"]
[Thu Sep 17 15:14:32.951410 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpThgAAfwQ"]
[Thu Sep 17 15:14:33.095788 2026] [security2:error] [pid 971102:tid 971181] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/database.sql"] [unique_id "aqxYOecL08BTTQixEnpTmQAATE0"]
[Thu Sep 17 15:14:33.111940 2026] [security2:error] [pid 971102:tid 971143] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config.php"] [unique_id "aqxYOecL08BTTQixEnpTnAAAOic"]
[Thu Sep 17 15:14:33.243354 2026] [security2:error] [pid 971102:tid 971309] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOecL08BTTQixEnpTlQAAS2A"], referer: http://www.talent-in-borders.com/new/
[Thu Sep 17 15:14:33.307364 2026] [security2:error] [pid 971102:tid 971358] [client 65.21.44.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.edmagik.com"] [uri "/wp/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTdAAAAHw"]
[Thu Sep 17 15:14:33.309381 2026] [security2:error] [pid 971102:tid 971284] [client 65.21.44.205:59502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.edmagik.com"] [uri "/wp/"] [unique_id "aqxYOOcL08BTTQixEnpTagAAADI"]
[Thu Sep 17 15:14:33.347627 2026] [security2:error] [pid 971102:tid 971327] [client 104.28.198.244:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYOecL08BTTQixEnpTsQAAAF0"]
[Thu Sep 17 15:14:33.347736 2026] [security2:error] [pid 971102:tid 971327] [client 104.28.198.244:22961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYOecL08BTTQixEnpTsQAAAF0"]
[Thu Sep 17 15:14:33.463291 2026] [security2:error] [pid 971102:tid 971216] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.bak"] [unique_id "aqxYOecL08BTTQixEnpTvgAAQ28"]
[Thu Sep 17 15:14:33.463301 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.backup"] [unique_id "aqxYOecL08BTTQixEnpTugAAQxE"]
[Thu Sep 17 15:14:33.464583 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.old"] [unique_id "aqxYOecL08BTTQixEnpTwQAAQxE"]
[Thu Sep 17 15:14:33.465559 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env"] [unique_id "aqxYOecL08BTTQixEnpTyAAAQxE"]
[Thu Sep 17 15:14:33.497110 2026] [security2:error] [pid 971102:tid 971128] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/.env.production.php"] [unique_id "aqxYOecL08BTTQixEnpTzQAAXxg"]
[Thu Sep 17 15:14:33.518785 2026] [security2:error] [pid 971102:tid 971114] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.git/config.bak"] [unique_id "aqxYOecL08BTTQixEnpT0QAAYgo"]
[Thu Sep 17 15:14:33.535918 2026] [security2:error] [pid 971102:tid 971145] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/aws.php"] [unique_id "aqxYOecL08BTTQixEnpT0gAABSk"]
[Thu Sep 17 15:14:33.585198 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "aqxYOecL08BTTQixEnpT2AAADng"]
[Thu Sep 17 15:14:33.598801 2026] [security2:error] [pid 971102:tid 971169] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/test.config.php"] [unique_id "aqxYOecL08BTTQixEnpT2QAADkE"]
[Thu Sep 17 15:14:33.653635 2026] [security2:error] [pid 971102:tid 971136] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.php"] [unique_id "aqxYOecL08BTTQixEnpT3gAAQyA"]
[Thu Sep 17 15:14:33.654223 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env~"] [unique_id "aqxYOecL08BTTQixEnpT3wAAQyI"]
[Thu Sep 17 15:14:33.664865 2026] [security2:error] [pid 971102:tid 971226] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.swp"] [unique_id "aqxYOecL08BTTQixEnpT4gAAQ3k"]
[Thu Sep 17 15:14:33.680485 2026] [security2:error] [pid 971102:tid 971144] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/stripe.php"] [unique_id "aqxYOecL08BTTQixEnpT5AAAKSg"]
[Thu Sep 17 15:14:33.680506 2026] [security2:error] [pid 971102:tid 971168] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/mail.php"] [unique_id "aqxYOecL08BTTQixEnpT5QAAKUA"]
[Thu Sep 17 15:14:33.680550 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/nexmo.php"] [unique_id "aqxYOecL08BTTQixEnpT5gAAKTk"]
[Thu Sep 17 15:14:33.680557 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/config.inc.php"] [unique_id "aqxYOecL08BTTQixEnpT6wAAKVQ"]
[Thu Sep 17 15:14:33.703420 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config.json.php"] [unique_id "aqxYOecL08BTTQixEnpT7AAAeiQ"]
[Thu Sep 17 15:14:33.797861 2026] [security2:error] [pid 971102:tid 971280] [client 47.79.201.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOecL08BTTQixEnpTtgAAAC4"], referer: https://www.google.com/
[Thu Sep 17 15:14:33.798973 2026] [security2:error] [pid 971102:tid 971223] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/aws_settings.php"] [unique_id "aqxYOecL08BTTQixEnpT8wAAcnY"]
[Thu Sep 17 15:14:33.799704 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/react-app/.env"] [unique_id "aqxYOecL08BTTQixEnpT9gAAcms"]
[Thu Sep 17 15:14:33.838891 2026] [security2:error] [pid 971102:tid 971132] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php"] [unique_id "aqxYOecL08BTTQixEnpT-AAARRw"]
[Thu Sep 17 15:14:33.870392 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYOecL08BTTQixEnpT-gAAVQU"]
[Thu Sep 17 15:14:33.902907 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php.old"] [unique_id "aqxYOecL08BTTQixEnpUAgAARFM"]
[Thu Sep 17 15:14:33.905275 2026] [security2:error] [pid 971102:tid 971166] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.aws/credentials.bak"] [unique_id "aqxYOecL08BTTQixEnpUAwAANz4"]
[Thu Sep 17 15:14:34.005670 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php.new"] [unique_id "aqxYOucL08BTTQixEnpUDgAAZEQ"]
[Thu Sep 17 15:14:34.007414 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/api/info.php"] [unique_id "aqxYOucL08BTTQixEnpUDwAAZ0k"]
[Thu Sep 17 15:14:34.079089 2026] [security2:error] [pid 971102:tid 971122] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYOucL08BTTQixEnpUFwAABBI"]
[Thu Sep 17 15:14:34.083445 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/id_rsa"] [unique_id "aqxYOucL08BTTQixEnpUGQAANhU"]
[Thu Sep 17 15:14:34.083504 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "aqxYOucL08BTTQixEnpUGAAANmE"]
[Thu Sep 17 15:14:34.112347 2026] [security2:error] [pid 971102:tid 971349] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOecL08BTTQixEnpUCQAAc08"], referer: http://www.talent-in-borders.com/wordpress/
[Thu Sep 17 15:14:34.147935 2026] [security2:error] [pid 971102:tid 971135] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/api/.env"] [unique_id "aqxYOucL08BTTQixEnpUIgAAQx8"]
[Thu Sep 17 15:14:34.343120 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/wp-content/mysql.sql"] [unique_id "aqxYOucL08BTTQixEnpUKgAADW0"]
[Thu Sep 17 15:14:34.449168 2026] [security2:error] [pid 971102:tid 971314] [client 167.172.76.13:56456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOucL08BTTQixEnpUKQAAUEU"], referer: https://www.talent-in-borders.com/wordpress/
[Thu Sep 17 15:14:34.604683 2026] [security2:error] [pid 971102:tid 971228] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/app/.env"] [unique_id "aqxYOucL08BTTQixEnpUSgAAQ3s"]
[Thu Sep 17 15:14:34.655827 2026] [security2:error] [pid 971102:tid 971206] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/terraform.tfstate.backup"] [unique_id "aqxYOucL08BTTQixEnpUTwAAMmU"]
[Thu Sep 17 15:14:34.753256 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backend/.env"] [unique_id "aqxYOucL08BTTQixEnpUWgAAQxE"]
[Thu Sep 17 15:14:34.758110 2026] [security2:error] [pid 971102:tid 971351] [client 37.139.53.80:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxYOucL08BTTQixEnpUVwAAAHU"], referer: https://www.norifon.com/index.php
[Thu Sep 17 15:14:34.903943 2026] [security2:error] [pid 971102:tid 971114] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/.env"] [unique_id "aqxYOucL08BTTQixEnpUYgAAYgo"]
[Thu Sep 17 15:14:34.904000 2026] [security2:error] [pid 971102:tid 971145] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/src/.env"] [unique_id "aqxYOucL08BTTQixEnpUZgAAYik"]
[Thu Sep 17 15:14:34.904006 2026] [security2:error] [pid 971102:tid 971209] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/web/.env"] [unique_id "aqxYOucL08BTTQixEnpUZQAAYmg"]
[Thu Sep 17 15:14:34.904045 2026] [security2:error] [pid 971102:tid 971221] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/client/.env"] [unique_id "aqxYOucL08BTTQixEnpUZwAAYnQ"]
[Thu Sep 17 15:14:34.904061 2026] [security2:error] [pid 971102:tid 971151] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/config/.env"] [unique_id "aqxYOucL08BTTQixEnpUYwAAYi8"]
[Thu Sep 17 15:14:34.904063 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/frontend/.env"] [unique_id "aqxYOucL08BTTQixEnpUaAAAYng"]
[Thu Sep 17 15:14:34.904115 2026] [security2:error] [pid 971102:tid 971195] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/public/.env"] [unique_id "aqxYOucL08BTTQixEnpUZAAAYlo"]
[Thu Sep 17 15:14:34.904115 2026] [security2:error] [pid 971102:tid 971169] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/var/www/.env"] [unique_id "aqxYOucL08BTTQixEnpUaQAAYkE"]
[Thu Sep 17 15:14:34.996259 2026] [security2:error] [pid 971102:tid 971144] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/var/www/html/.env"] [unique_id "aqxYOucL08BTTQixEnpUdQAAMSg"]
[Thu Sep 17 15:14:35.018522 2026] [security2:error] [pid 971102:tid 971134] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/laravel/.env"] [unique_id "aqxYO-cL08BTTQixEnpUdwAACx4"]
[Thu Sep 17 15:14:35.027870 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/application/.env"] [unique_id "aqxYO-cL08BTTQixEnpUfAAAIyQ"]
[Thu Sep 17 15:14:35.028579 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/apps/.env"] [unique_id "aqxYO-cL08BTTQixEnpUfQAAI1w"]
[Thu Sep 17 15:14:35.048731 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config.php"] [unique_id "aqxYO-cL08BTTQixEnpUfwAAUQ0"]
[Thu Sep 17 15:14:35.056808 2026] [security2:error] [pid 971102:tid 971157] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/back/.env"] [unique_id "aqxYO-cL08BTTQixEnpUgQAAKTU"]
[Thu Sep 17 15:14:35.066744 2026] [security2:error] [pid 971102:tid 971166] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/test/.env"] [unique_id "aqxYO-cL08BTTQixEnpUjgAACD4"]
[Thu Sep 17 15:14:35.066792 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/staging/.env"] [unique_id "aqxYO-cL08BTTQixEnpUigAACFM"]
[Thu Sep 17 15:14:35.066853 2026] [security2:error] [pid 971102:tid 971203] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/production/.env"] [unique_id "aqxYO-cL08BTTQixEnpUjAAACGI"]
[Thu Sep 17 15:14:35.066869 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/prod/.env"] [unique_id "aqxYO-cL08BTTQixEnpUiwAACAU"]
[Thu Sep 17 15:14:35.066869 2026] [security2:error] [pid 971102:tid 971155] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/dev/.env"] [unique_id "aqxYO-cL08BTTQixEnpUiAAACDM"]
[Thu Sep 17 15:14:35.066911 2026] [security2:error] [pid 971102:tid 971218] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/old/.env"] [unique_id "aqxYO-cL08BTTQixEnpUjQAACHE"]
[Thu Sep 17 15:14:35.066936 2026] [security2:error] [pid 971102:tid 971132] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backup/.env"] [unique_id "aqxYO-cL08BTTQixEnpUiQAACBw"]
[Thu Sep 17 15:14:35.067138 2026] [security2:error] [pid 971102:tid 971127] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/cms/.env"] [unique_id "aqxYO-cL08BTTQixEnpUhwAACBc"]
[Thu Sep 17 15:14:35.289464 2026] [security2:error] [pid 971102:tid 971313] [client 114.198.138.124:63756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpUnAAAAE8"]
[Thu Sep 17 15:14:35.289630 2026] [security2:error] [pid 971102:tid 971313] [client 114.198.138.124:63756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpUnAAAAE8"]
[Thu Sep 17 15:14:35.305482 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/api-backend/.env"] [unique_id "aqxYO-cL08BTTQixEnpUnwAAFDE"]
[Thu Sep 17 15:14:35.305531 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/new/.env"] [unique_id "aqxYO-cL08BTTQixEnpUnQAAFEk"]
[Thu Sep 17 15:14:35.305585 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/admin-app/.env"] [unique_id "aqxYO-cL08BTTQixEnpUoAAAFCw"]
[Thu Sep 17 15:14:35.305589 2026] [security2:error] [pid 971102:tid 971215] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/node-api/.env"] [unique_id "aqxYO-cL08BTTQixEnpUngAAFG4"]
[Thu Sep 17 15:14:35.305925 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/administrator/.env"] [unique_id "aqxYO-cL08BTTQixEnpUoQAAFAQ"]
[Thu Sep 17 15:14:35.464727 2026] [security2:error] [pid 971102:tid 971211] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.docker/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpAAAN2o"]
[Thu Sep 17 15:14:35.464735 2026] [security2:error] [pid 971102:tid 971181] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/stripe/.env"] [unique_id "aqxYO-cL08BTTQixEnpUqAAAN00"]
[Thu Sep 17 15:14:35.464842 2026] [security2:error] [pid 971102:tid 971104] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpgAANwA"]
[Thu Sep 17 15:14:35.464851 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.aws/.env"] [unique_id "aqxYO-cL08BTTQixEnpUqQAAN08"]
[Thu Sep 17 15:14:35.464871 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/api/.env"] [unique_id "aqxYO-cL08BTTQixEnpUqgAANxU"]
[Thu Sep 17 15:14:35.464880 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/backend/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpwAAN2E"]
[Thu Sep 17 15:14:35.464982 2026] [security2:error] [pid 971102:tid 971130] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/aws/.env"] [unique_id "aqxYO-cL08BTTQixEnpUogAANxo"]
[Thu Sep 17 15:14:35.464983 2026] [security2:error] [pid 971102:tid 971122] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/public_html/.env"] [unique_id "aqxYO-cL08BTTQixEnpUowAANxI"]
[Thu Sep 17 15:14:35.464999 2026] [security2:error] [pid 971102:tid 971213] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/current/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpQAAN2w"]
[Thu Sep 17 15:14:35.514990 2026] [security2:error] [pid 971102:tid 971198] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/mail.php"] [unique_id "aqxYO-cL08BTTQixEnpUugAAZ10"]
[Thu Sep 17 15:14:35.515002 2026] [security2:error] [pid 971102:tid 971220] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/nexmo.php"] [unique_id "aqxYO-cL08BTTQixEnpUvwAAZ3M"]
[Thu Sep 17 15:14:35.515022 2026] [security2:error] [pid 971102:tid 971204] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/stripe.php"] [unique_id "aqxYO-cL08BTTQixEnpUuwAAZ2M"]
[Thu Sep 17 15:14:35.515046 2026] [security2:error] [pid 971102:tid 971186] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/config.inc.php"] [unique_id "aqxYO-cL08BTTQixEnpUwgAAZ1I"]
[Thu Sep 17 15:14:35.515090 2026] [security2:error] [pid 971102:tid 971123] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/aws.php"] [unique_id "aqxYO-cL08BTTQixEnpUwAAAZxM"]
[Thu Sep 17 15:14:35.600123 2026] [security2:error] [pid 971102:tid 971228] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v2/.env"] [unique_id "aqxYO-cL08BTTQixEnpUygAAJns"]
[Thu Sep 17 15:14:35.600294 2026] [security2:error] [pid 971102:tid 971165] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/media/.env"] [unique_id "aqxYO-cL08BTTQixEnpUzQAAJj0"]
[Thu Sep 17 15:14:35.600298 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v3/.env"] [unique_id "aqxYO-cL08BTTQixEnpUyAAAJl4"]
[Thu Sep 17 15:14:35.600321 2026] [security2:error] [pid 971102:tid 971196] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v1/.env"] [unique_id "aqxYO-cL08BTTQixEnpUyQAAJls"]
[Thu Sep 17 15:14:35.630200 2026] [security2:error] [pid 971102:tid 971190] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php"] [unique_id "aqxYO-cL08BTTQixEnpU1QAALFU"]
[Thu Sep 17 15:14:35.655863 2026] [security2:error] [pid 971102:tid 971110] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYO-cL08BTTQixEnpU1wAAPQY"]
[Thu Sep 17 15:14:35.660619 2026] [security2:error] [pid 971102:tid 971227] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php.old"] [unique_id "aqxYO-cL08BTTQixEnpU2AAAAXo"]
[Thu Sep 17 15:14:35.674770 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php.new"] [unique_id "aqxYO-cL08BTTQixEnpU3wAALRs"]
[Thu Sep 17 15:14:35.675036 2026] [security2:error] [pid 971102:tid 971232] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYO-cL08BTTQixEnpU3gAALX8"]
[Thu Sep 17 15:14:35.675830 2026] [security2:error] [pid 971102:tid 971106] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/wp-content/mysql.sql"] [unique_id "aqxYO-cL08BTTQixEnpU3QAALQI"]
[Thu Sep 17 15:14:35.738904 2026] [security2:error] [pid 971102:tid 971150] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.git/config.bak"] [unique_id "aqxYO-cL08BTTQixEnpU8wAAWC4"]
[Thu Sep 17 15:14:35.768809 2026] [security2:error] [pid 971102:tid 971152] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/terraform.tfstate.backup"] [unique_id "aqxYO-cL08BTTQixEnpU-AAALTA"]
[Thu Sep 17 15:14:35.891011 2026] [security2:error] [pid 971102:tid 971299] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYO-cL08BTTQixEnpU6wAAQWg"], referer: http://www.talent-in-borders.com/blog/
[Thu Sep 17 15:14:35.907035 2026] [security2:error] [pid 971102:tid 971251] [client 45.169.98.18:50131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpVAQAAABE"]
[Thu Sep 17 15:14:35.907128 2026] [security2:error] [pid 971102:tid 971251] [client 45.169.98.18:50131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpVAQAAABE"]
[Thu Sep 17 15:14:36.145517 2026] [security2:error] [pid 971102:tid 971273] [client 154.190.208.131:41331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYPOcL08BTTQixEnpVCAAAACc"]
[Thu Sep 17 15:14:36.145685 2026] [security2:error] [pid 971102:tid 971273] [client 154.190.208.131:41331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYPOcL08BTTQixEnpVCAAAACc"]
[Thu Sep 17 15:14:36.250856 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/php.php"] [unique_id "aqxYPOcL08BTTQixEnpVFgAAfzk"]
[Thu Sep 17 15:14:36.250871 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/infos.php"] [unique_id "aqxYPOcL08BTTQixEnpVFwAAf1Q"]
[Thu Sep 17 15:14:36.250902 2026] [security2:error] [pid 971102:tid 971127] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVFQAAfxc"]
[Thu Sep 17 15:14:36.250924 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/info.php"] [unique_id "aqxYPOcL08BTTQixEnpVEwAAf0M"]
[Thu Sep 17 15:14:36.250951 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/php_info.php"] [unique_id "aqxYPOcL08BTTQixEnpVGAAAf2s"]
[Thu Sep 17 15:14:36.397418 2026] [security2:error] [pid 971102:tid 971164] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVIwAAajw"]
[Thu Sep 17 15:14:36.397428 2026] [security2:error] [pid 971102:tid 971223] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/infophp.php"] [unique_id "aqxYPOcL08BTTQixEnpVIgAAanY"]
[Thu Sep 17 15:14:36.397455 2026] [security2:error] [pid 971102:tid 971162] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVJQAAajo"]
[Thu Sep 17 15:14:36.397480 2026] [security2:error] [pid 971102:tid 971229] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/php-info.php"] [unique_id "aqxYPOcL08BTTQixEnpVIQAAanw"]
[Thu Sep 17 15:14:36.397508 2026] [security2:error] [pid 971102:tid 971156] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVHwAAajQ"]
[Thu Sep 17 15:14:36.397518 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVJAAAajI"]
[Thu Sep 17 15:14:36.451059 2026] [security2:error] [pid 971102:tid 971142] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVKwAAKyY"]
[Thu Sep 17 15:14:36.540837 2026] [security2:error] [pid 971102:tid 971116] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/database.sql"] [unique_id "aqxYPOcL08BTTQixEnpVNAAARgw"]
[Thu Sep 17 15:14:36.739652 2026] [security2:error] [pid 971102:tid 971359] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYPOcL08BTTQixEnpVSwAAfS0"], referer: http://www.talent-in-borders.com/old/
[Thu Sep 17 15:14:37.065579 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxYPecL08BTTQixEnpVcQAABBs"]
[Thu Sep 17 15:14:37.065636 2026] [security2:error] [pid 971102:tid 971180] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxYPecL08BTTQixEnpVcwAABEw"]
[Thu Sep 17 15:14:37.070727 2026] [security2:error] [pid 971102:tid 971106] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/.env.production.php"] [unique_id "aqxYPecL08BTTQixEnpVdwAANgI"]
[Thu Sep 17 15:14:37.070818 2026] [security2:error] [pid 971102:tid 971119] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config.json.php"] [unique_id "aqxYPecL08BTTQixEnpVfwAANg8"]
[Thu Sep 17 15:14:37.071031 2026] [security2:error] [pid 971102:tid 971133] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/aws_settings.php"] [unique_id "aqxYPecL08BTTQixEnpVggAANh0"]
[Thu Sep 17 15:14:37.071595 2026] [security2:error] [pid 971102:tid 971207] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/test.config.php"] [unique_id "aqxYPecL08BTTQixEnpVeQAANmY"]
[Thu Sep 17 15:14:37.071605 2026] [security2:error] [pid 971102:tid 971107] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/fe/.env"] [unique_id "aqxYPecL08BTTQixEnpVfgAANgM"]
[Thu Sep 17 15:14:37.072061 2026] [security2:error] [pid 971102:tid 971178] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/react-app/.env"] [unique_id "aqxYPecL08BTTQixEnpVgwAANko"]
[Thu Sep 17 15:14:37.221804 2026] [security2:error] [pid 971102:tid 971145] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/id_rsa"] [unique_id "aqxYPecL08BTTQixEnpVigAAKCk"]
[Thu Sep 17 15:14:37.268502 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/api/info.php"] [unique_id "aqxYPecL08BTTQixEnpVnwAAASQ"]
[Thu Sep 17 15:14:37.448245 2026] [security2:error] [pid 971102:tid 971223] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpVuQAADXY"]
[Thu Sep 17 15:14:37.539775 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/info.php"] [unique_id "aqxYPecL08BTTQixEnpVwAAAZQg"]
[Thu Sep 17 15:14:37.563687 2026] [security2:error] [pid 971102:tid 971142] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/infos.php"] [unique_id "aqxYPecL08BTTQixEnpVxAAAYyY"]
[Thu Sep 17 15:14:37.588580 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/php_info.php"] [unique_id "aqxYPecL08BTTQixEnpVxQAAbFE"]
[Thu Sep 17 15:14:37.596051 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/php.php"] [unique_id "aqxYPecL08BTTQixEnpVxgAAOwc"]
[Thu Sep 17 15:14:37.612200 2026] [security2:error] [pid 971102:tid 971294] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYPecL08BTTQixEnpVvAAAPHw"], referer: http://www.talent-in-borders.com/backup/
[Thu Sep 17 15:14:37.638966 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/infophp.php"] [unique_id "aqxYPecL08BTTQixEnpVyQAASCw"]
[Thu Sep 17 15:14:37.639032 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/php-info.php"] [unique_id "aqxYPecL08BTTQixEnpVygAASEk"]
[Thu Sep 17 15:14:37.705607 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpVzAAAezE"]
[Thu Sep 17 15:14:37.761880 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV1wAADxU"]
[Thu Sep 17 15:14:37.761904 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV2AAAD0Q"]
[Thu Sep 17 15:14:37.761953 2026] [security2:error] [pid 971102:tid 971208] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV1QAAD2c"]
[Thu Sep 17 15:14:37.761990 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV2QAAD08"]
[Thu Sep 17 15:14:37.945298 2026] [security2:error] [pid 971102:tid 971205] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/database.sql"] [unique_id "aqxYPecL08BTTQixEnpV5wAAPmQ"]
[Thu Sep 17 15:14:37.966732 2026] [security2:error] [pid 971102:tid 971355] [client 167.172.76.13:56456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYPecL08BTTQixEnpV3gAAeRM"], referer: https://www.talent-in-borders.com/backup/
[Thu Sep 17 15:14:38.109615 2026] [security2:error] [pid 971102:tid 971350] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYPecL08BTTQixEnpV3wAAAHQ"]
[Thu Sep 17 15:14:38.186277 2026] [security2:error] [pid 971102:tid 971308] [client 192.178.6.3:52003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYPucL08BTTQixEnpWAAAAAEo"]
[Thu Sep 17 15:14:38.207764 2026] [security2:error] [pid 971102:tid 971165] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config.php"] [unique_id "aqxYPucL08BTTQixEnpWBAAAOD0"]
[Thu Sep 17 15:14:38.233922 2026] [security2:error] [pid 971102:tid 971216] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/.env.production.php"] [unique_id "aqxYPucL08BTTQixEnpWDgAAFG8"]
[Thu Sep 17 15:14:38.265647 2026] [security2:error] [pid 971102:tid 971194] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/fe/.env"] [unique_id "aqxYPucL08BTTQixEnpWEgAALlk"]
[Thu Sep 17 15:14:38.277233 2026] [security2:error] [pid 971102:tid 971167] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/test.config.php"] [unique_id "aqxYPucL08BTTQixEnpWEwAALj8"]
[Thu Sep 17 15:14:38.305077 2026] [security2:error] [pid 971102:tid 971302] [client 34.55.12.4:62988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cjs.gdz.mybluehost.me"] [uri "/.env"] [unique_id "aqxYPucL08BTTQixEnpWFQAAAEQ"]
[Thu Sep 17 15:14:38.328911 2026] [security2:error] [pid 971102:tid 971196] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config.json.php"] [unique_id "aqxYPucL08BTTQixEnpWFgAAcls"]
[Thu Sep 17 15:14:38.367395 2026] [security2:error] [pid 971102:tid 971169] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/aws.php"] [unique_id "aqxYPucL08BTTQixEnpWGQAAZ0E"]
[Thu Sep 17 15:14:38.368497 2026] [security2:error] [pid 971102:tid 971128] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/stripe.php"] [unique_id "aqxYPucL08BTTQixEnpWHwAAZxg"]
[Thu Sep 17 15:14:38.373779 2026] [security2:error] [pid 971102:tid 971136] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/react-app/.env"] [unique_id "aqxYPucL08BTTQixEnpWIQAABCA"]
[Thu Sep 17 15:14:38.386467 2026] [security2:error] [pid 971102:tid 971230] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/aws_settings.php"] [unique_id "aqxYPucL08BTTQixEnpWIgAAW30"]
[Thu Sep 17 15:14:38.494156 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/mail.php"] [unique_id "aqxYPucL08BTTQixEnpWKAAACTs"]
[Thu Sep 17 15:14:38.680959 2026] [security2:error] [pid 971102:tid 971157] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/config.inc.php"] [unique_id "aqxYPucL08BTTQixEnpWPgAAaTU"]
[Thu Sep 17 15:14:38.680990 2026] [security2:error] [pid 971102:tid 971150] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/nexmo.php"] [unique_id "aqxYPucL08BTTQixEnpWOgAAaS4"]
[Thu Sep 17 15:14:38.681020 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php"] [unique_id "aqxYPucL08BTTQixEnpWPQAAaVM"]
[Thu Sep 17 15:14:38.737997 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/api/info.php"] [unique_id "aqxYPucL08BTTQixEnpWQQAAVEM"]
[Thu Sep 17 15:14:38.766513 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYPucL08BTTQixEnpWRwAAbyI"]
[Thu Sep 17 15:14:38.766513 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.old"] [unique_id "aqxYPucL08BTTQixEnpWSAAAbwU"]
[Thu Sep 17 15:14:38.767501 2026] [security2:error] [pid 971102:tid 971279] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYPucL08BTTQixEnpWLAAAAC0"]
[Thu Sep 17 15:14:38.767970 2026] [security2:error] [pid 971102:tid 971218] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.new"] [unique_id "aqxYPucL08BTTQixEnpWSgAAEXE"]
[Thu Sep 17 15:14:38.768232 2026] [security2:error] [pid 971102:tid 971203] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYPucL08BTTQixEnpWSQAAEWI"]
[Thu Sep 17 15:14:38.769106 2026] [security2:error] [pid 971102:tid 971170] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxYPucL08BTTQixEnpWTgAAEUI"]
[Thu Sep 17 15:14:38.819957 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxYPucL08BTTQixEnpWVAAAZVE"]
[Thu Sep 17 15:14:39.117928 2026] [security2:error] [pid 971102:tid 971330] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYPucL08BTTQixEnpWWgAAAGA"]
[Thu Sep 17 15:14:39.679337 2026] [security2:error] [pid 971102:tid 971351] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYP-cL08BTTQixEnpWdAAAAHU"]
[Thu Sep 17 15:14:39.845879 2026] [security2:error] [pid 971102:tid 971242] [client 5.189.145.112:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxYP-cL08BTTQixEnpWfAAAAAg"], referer: binance.com
[Thu Sep 17 15:14:40.195512 2026] [security2:error] [pid 971102:tid 971307] [client 156.192.234.52:57555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWiwAAAEk"]
[Thu Sep 17 15:14:40.195602 2026] [security2:error] [pid 971102:tid 971307] [client 156.192.234.52:57555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWiwAAAEk"]
[Thu Sep 17 15:14:40.238666 2026] [security2:error] [pid 971102:tid 971356] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYQOcL08BTTQixEnpWiQAAAHo"]
[Thu Sep 17 15:14:40.431170 2026] [security2:error] [pid 971102:tid 971165] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWnQAAaD0"]
[Thu Sep 17 15:14:40.471866 2026] [security2:error] [pid 971102:tid 971118] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php_info.php"] [unique_id "aqxYQOcL08BTTQixEnpWpQAAFA4"]
[Thu Sep 17 15:14:40.471888 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/info.php"] [unique_id "aqxYQOcL08BTTQixEnpWqQAAFG0"]
[Thu Sep 17 15:14:40.471924 2026] [security2:error] [pid 971102:tid 971191] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php-info.php"] [unique_id "aqxYQOcL08BTTQixEnpWpwAAFFY"]
[Thu Sep 17 15:14:40.471943 2026] [security2:error] [pid 971102:tid 971146] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWqwAAFCo"]
[Thu Sep 17 15:14:40.471974 2026] [security2:error] [pid 971102:tid 971224] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/infos.php"] [unique_id "aqxYQOcL08BTTQixEnpWqAAAFHc"]
[Thu Sep 17 15:14:40.471987 2026] [security2:error] [pid 971102:tid 971137] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/infophp.php"] [unique_id "aqxYQOcL08BTTQixEnpWqgAAFCE"]
[Thu Sep 17 15:14:40.472009 2026] [security2:error] [pid 971102:tid 971174] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php.php"] [unique_id "aqxYQOcL08BTTQixEnpWpAAAFEY"]
[Thu Sep 17 15:14:40.488453 2026] [security2:error] [pid 971102:tid 971259] [client 115.244.164.14:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWrQAAABk"]
[Thu Sep 17 15:14:40.488511 2026] [security2:error] [pid 971102:tid 971259] [client 115.244.164.14:62634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWrQAAABk"]
[Thu Sep 17 15:14:40.517896 2026] [security2:error] [pid 971102:tid 971298] [client 104.234.53.18:54053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxYQOcL08BTTQixEnpWrAAAAEA"]
[Thu Sep 17 15:14:40.570597 2026] [security2:error] [pid 971102:tid 971106] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWsgAAQwI"]
[Thu Sep 17 15:14:40.570620 2026] [security2:error] [pid 971102:tid 971190] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWswAAQ1U"]
[Thu Sep 17 15:14:40.570669 2026] [security2:error] [pid 971102:tid 971216] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWrwAAQ28"]
[Thu Sep 17 15:14:40.570687 2026] [security2:error] [pid 971102:tid 971232] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWrgAAQ38"]
[Thu Sep 17 15:14:40.608160 2026] [security2:error] [pid 971102:tid 971173] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/database.sql"] [unique_id "aqxYQOcL08BTTQixEnpWvAAANEU"]
[Thu Sep 17 15:14:40.790369 2026] [security2:error] [pid 971102:tid 971324] [client 186.105.232.15:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWyQAAAFo"]
[Thu Sep 17 15:14:40.790468 2026] [security2:error] [pid 971102:tid 971324] [client 186.105.232.15:61991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWyQAAAFo"]
[Thu Sep 17 15:14:40.941462 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYQOcL08BTTQixEnpWywAAAAk"]
[Thu Sep 17 15:14:41.159109 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/test.config.php"] [unique_id "aqxYQecL08BTTQixEnpW3AAAAGs"]
[Thu Sep 17 15:14:41.159133 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.production.php"] [unique_id "aqxYQecL08BTTQixEnpW4AAAAA0"]
[Thu Sep 17 15:14:41.159973 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/fe/.env"] [unique_id "aqxYQecL08BTTQixEnpW3gAAAFQ"]
[Thu Sep 17 15:14:41.357412 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/aws_settings.php"] [unique_id "aqxYQecL08BTTQixEnpW5AAAZQU"]
[Thu Sep 17 15:14:41.357439 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config.json.php"] [unique_id "aqxYQecL08BTTQixEnpW6AAAZVw"]
[Thu Sep 17 15:14:41.358476 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/react-app/.env"] [unique_id "aqxYQecL08BTTQixEnpW5wAAZSI"]
[Thu Sep 17 15:14:42.492483 2026] [security2:error] [pid 971102:tid 971310] [client 185.55.149.49:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYQucL08BTTQixEnpXEQAAAEw"]
[Thu Sep 17 15:14:42.494521 2026] [security2:error] [pid 971102:tid 971310] [client 185.55.149.49:61285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYQucL08BTTQixEnpXEQAAAEw"]
[Thu Sep 17 15:14:42.525649 2026] [security2:error] [pid 971102:tid 971303] [client 127.0.0.1:55912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxYQucL08BTTQixEnpXEAAAAEU"]
[Thu Sep 17 15:14:42.525783 2026] [security2:error] [pid 971102:tid 971329] [client 74.7.244.39:43476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.oem.izd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYQucL08BTTQixEnpXDwAAXzI"]
[Thu Sep 17 15:14:42.770768 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/api/info.php"] [unique_id "aqxYQucL08BTTQixEnpXJAAAMmE"]
[Thu Sep 17 15:14:43.827769 2026] [security2:error] [pid 971102:tid 971274] [client 212.63.124.56:22283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxYQ-cL08BTTQixEnpXTgAAKE8"], referer: https://www.enolastable.com/2021/07/16/what-inspired-the-table/
[Thu Sep 17 15:14:43.945481 2026] [security2:error] [pid 971102:tid 971283] [client 104.28.198.244:22992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQ-cL08BTTQixEnpXUAAAADE"]
[Thu Sep 17 15:14:43.945626 2026] [security2:error] [pid 971102:tid 971283] [client 104.28.198.244:22992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQ-cL08BTTQixEnpXUAAAADE"]
[Thu Sep 17 15:14:44.934456 2026] [security2:error] [pid 971102:tid 971286] [client 84.54.44.204:51542] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "84.54.44.204" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "daprayer.com"] [uri "/wp-comments-post.php"] [unique_id "aqxYROcL08BTTQixEnpXWwAAADQ"], referer: https://daprayer.com/baby-e-the-birth-story/
[Thu Sep 17 15:14:44.934547 2026] [security2:error] [pid 971102:tid 971286] [client 84.54.44.204:51542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "daprayer.com"] [uri "/wp-comments-post.php"] [unique_id "aqxYROcL08BTTQixEnpXWwAAADQ"], referer: https://daprayer.com/baby-e-the-birth-story/
[Thu Sep 17 15:14:45.803440 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRecL08BTTQixEnpXcAAAAF0"]
[Thu Sep 17 15:14:45.803552 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:60669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRecL08BTTQixEnpXcAAAAF0"]
[Thu Sep 17 15:14:46.408585 2026] [security2:error] [pid 971102:tid 971340] [client 45.169.98.18:50690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXfAAAAGo"]
[Thu Sep 17 15:14:46.408691 2026] [security2:error] [pid 971102:tid 971340] [client 45.169.98.18:50690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXfAAAAGo"]
[Thu Sep 17 15:14:46.573371 2026] [security2:error] [pid 971102:tid 971206] [remote 111.225.149.178:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joeledmundanderson.com"] [uri "/"] [unique_id "aqxYRucL08BTTQixEnpXfgAAIGU"]
[Thu Sep 17 15:14:46.603433 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXgQAAACo"]
[Thu Sep 17 15:14:46.603527 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:41931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXgQAAACo"]
[Thu Sep 17 15:14:47.998527 2026] [security2:error] [pid 971102:tid 971316] [client 5.189.145.112:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxYR-cL08BTTQixEnpXlwAAAFI"], referer: binance.com
[Thu Sep 17 15:14:48.218189 2026] [security2:error] [pid 971102:tid 971264] [client 216.73.216.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxYSOcL08BTTQixEnpXngAAAB4"]
[Thu Sep 17 15:14:48.779998 2026] [security2:error] [pid 971102:tid 971283] [client 32.223.98.46:54863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYSOcL08BTTQixEnpXrgAAMQM"]
[Thu Sep 17 15:14:50.180350 2026] [core:error] [pid 971102:tid 971254] [client 138.246.253.24:57814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:50.180370 2026] [core:error] [pid 971102:tid 971254] [client 138.246.253.24:57814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:50.716222 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYSucL08BTTQixEnpXwgAAAEw"]
[Thu Sep 17 15:14:50.716796 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:58163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYSucL08BTTQixEnpXwgAAAEw"]
[Thu Sep 17 15:14:50.819131 2026] [security2:error] [pid 971102:tid 971320] [client 32.223.98.46:54905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYSucL08BTTQixEnpXwwAAVio"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260522203933&hideliu=1&hidemyself=1&limit=250&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:14:51.120602 2026] [security2:error] [pid 971102:tid 971243] [client 115.244.164.14:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpXzQAAAAk"]
[Thu Sep 17 15:14:51.120745 2026] [security2:error] [pid 971102:tid 971243] [client 115.244.164.14:63045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpXzQAAAAk"]
[Thu Sep 17 15:14:51.638999 2026] [security2:error] [pid 971102:tid 971327] [client 186.105.232.15:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpX1QAAAF0"]
[Thu Sep 17 15:14:51.639115 2026] [security2:error] [pid 971102:tid 971327] [client 186.105.232.15:62592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpX1QAAAF0"]
[Thu Sep 17 15:14:51.999418 2026] [security2:error] [pid 971102:tid 971255] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/uploads/"] [unique_id "aqxYS-cL08BTTQixEnpX2wAAABU"]
[Thu Sep 17 15:14:52.075423 2026] [security2:error] [pid 971102:tid 971321] [client 20.244.34.24:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxYTOcL08BTTQixEnpX3gAAAFc"], referer: binance.com
[Thu Sep 17 15:14:52.208169 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.121:39470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTOcL08BTTQixEnpX4AAAAA4"]
[Thu Sep 17 15:14:52.536389 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.121:39482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.idautovic.com"] [uri "/xmlrpc.php"] [unique_id "aqxYTOcL08BTTQixEnpX4wAAAHU"]
[Thu Sep 17 15:14:52.607621 2026] [autoindex:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:52.608352 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-sys/403.html"] [unique_id "aqxYTOcL08BTTQixEnpX5wAAAHQ"]
[Thu Sep 17 15:14:52.720282 2026] [security2:error] [pid 971102:tid 971329] [client 45.179.29.134:17092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYTOcL08BTTQixEnpX6AAAXxA"]
[Thu Sep 17 15:14:52.758127 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/"] [unique_id "aqxYTOcL08BTTQixEnpX6wAAADM"]
[Thu Sep 17 15:14:52.825602 2026] [cgid:error] [pid 971102:tid 971340] [client 66.249.93.225:47853] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:14:52.920245 2026] [autoindex:error] [pid 971102:tid 971298] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:52.920898 2026] [security2:error] [pid 971102:tid 971298] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/"] [unique_id "aqxYTOcL08BTTQixEnpX7gAAAEA"]
[Thu Sep 17 15:14:53.071325 2026] [security2:error] [pid 971102:tid 971344] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/css/"] [unique_id "aqxYTecL08BTTQixEnpX8AAAAG4"]
[Thu Sep 17 15:14:53.226179 2026] [autoindex:error] [pid 971102:tid 971310] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:53.226677 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/css/"] [unique_id "aqxYTecL08BTTQixEnpX-QAAAEw"]
[Thu Sep 17 15:14:53.250435 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.121:39496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTecL08BTTQixEnpX-wAAADQ"]
[Thu Sep 17 15:14:53.264041 2026] [security2:error] [pid 971102:tid 971345] [client 185.55.149.49:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYTecL08BTTQixEnpX_AAAAG8"]
[Thu Sep 17 15:14:53.264131 2026] [security2:error] [pid 971102:tid 971345] [client 185.55.149.49:64611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYTecL08BTTQixEnpX_AAAAG8"]
[Thu Sep 17 15:14:53.528869 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.121:39504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTecL08BTTQixEnpYBAAAAHk"]
[Thu Sep 17 15:14:53.599562 2026] [security2:error] [pid 971102:tid 971318] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxYTecL08BTTQixEnpYCQAAAFQ"]
[Thu Sep 17 15:14:53.647967 2026] [security2:error] [pid 971102:tid 971341] [client 47.79.200.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYTecL08BTTQixEnpX_wAAAGs"], referer: https://www.google.com/
[Thu Sep 17 15:14:53.757154 2026] [autoindex:error] [pid 971102:tid 971360] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:53.757653 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxYTecL08BTTQixEnpYCwAAAH4"]
[Thu Sep 17 15:14:53.822873 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.121:39508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTecL08BTTQixEnpYDAAAAAM"]
[Thu Sep 17 15:14:53.905859 2026] [security2:error] [pid 971102:tid 971289] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxYTecL08BTTQixEnpYDgAAADc"]
[Thu Sep 17 15:14:54.070082 2026] [autoindex:error] [pid 971102:tid 971302] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:54.070576 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxYTucL08BTTQixEnpYDwAAAEQ"]
[Thu Sep 17 15:14:54.107914 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.121:39516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTucL08BTTQixEnpYEgAAAAc"]
[Thu Sep 17 15:14:54.224370 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxYTucL08BTTQixEnpYFAAAAEo"]
[Thu Sep 17 15:14:54.410862 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.121:39526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTucL08BTTQixEnpYFgAAACg"]
[Thu Sep 17 15:14:54.414651 2026] [autoindex:error] [pid 971102:tid 971311] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:54.415132 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxYTucL08BTTQixEnpYFQAAAE0"]
[Thu Sep 17 15:14:54.534859 2026] [security2:error] [pid 971102:tid 971296] [client 104.28.198.244:22780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYTucL08BTTQixEnpYGQAAAD4"]
[Thu Sep 17 15:14:54.534971 2026] [security2:error] [pid 971102:tid 971296] [client 104.28.198.244:22780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYTucL08BTTQixEnpYGQAAAD4"]
[Thu Sep 17 15:14:54.596948 2026] [security2:error] [pid 971102:tid 971343] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxYTucL08BTTQixEnpYHQAAAG0"]
[Thu Sep 17 15:14:54.702000 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.121:39528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTucL08BTTQixEnpYIAAAAC4"]
[Thu Sep 17 15:14:54.755764 2026] [autoindex:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:54.756289 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxYTucL08BTTQixEnpYIQAAADg"]
[Thu Sep 17 15:14:54.910802 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/"] [unique_id "aqxYTucL08BTTQixEnpYIwAAACs"]
[Thu Sep 17 15:14:55.007947 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.121:39542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYJQAAAFk"]
[Thu Sep 17 15:14:55.075166 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:55.075820 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/"] [unique_id "aqxYT-cL08BTTQixEnpYKAAAACA"]
[Thu Sep 17 15:14:55.222975 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxYT-cL08BTTQixEnpYKgAAAFs"]
[Thu Sep 17 15:14:55.307391 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.121:39544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYKwAAAHo"]
[Thu Sep 17 15:14:55.511436 2026] [security2:error] [pid 971102:tid 971275] [client 200.42.105.146:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYT-cL08BTTQixEnpYLwAAKTs"]
[Thu Sep 17 15:14:55.628213 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.121:39554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYOAAAAAY"]
[Thu Sep 17 15:14:55.917073 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.121:39564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYOwAAAAQ"]
[Thu Sep 17 15:14:56.132926 2026] [security2:error] [pid 971102:tid 971316] [client 5.189.145.112:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/config.php"] [unique_id "aqxYUOcL08BTTQixEnpYQgAAAFI"], referer: binance.com
[Thu Sep 17 15:14:56.223677 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.121:39566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUOcL08BTTQixEnpYRAAAAGw"]
[Thu Sep 17 15:14:56.248602 2026] [security2:error] [pid 971102:tid 971168] [remote 157.55.39.8:17891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtbclubdecampo.com"] [uri "/navas.php"] [unique_id "aqxYUOcL08BTTQixEnpYRQAAf0A"]
[Thu Sep 17 15:14:56.482706 2026] [security2:error] [pid 971102:tid 971293] [client 114.198.138.124:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYRwAAADs"]
[Thu Sep 17 15:14:56.482811 2026] [security2:error] [pid 971102:tid 971293] [client 114.198.138.124:61388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYRwAAADs"]
[Thu Sep 17 15:14:56.528709 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.121:39580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUOcL08BTTQixEnpYSAAAAGI"]
[Thu Sep 17 15:14:56.822504 2026] [security2:error] [pid 971102:tid 971241] [client 134.185.85.61:51219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "rickanddonnaproctor.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYUOcL08BTTQixEnpYTwAAAAc"]
[Thu Sep 17 15:14:56.822565 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.121:39582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUOcL08BTTQixEnpYTgAAAEo"]
[Thu Sep 17 15:14:56.879898 2026] [security2:error] [pid 971102:tid 971289] [client 45.169.98.18:51255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYUAAAADc"]
[Thu Sep 17 15:14:56.880911 2026] [security2:error] [pid 971102:tid 971289] [client 45.169.98.18:51255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYUAAAADc"]
[Thu Sep 17 15:14:57.041588 2026] [autoindex:error] [pid 971102:tid 971136] [remote 93.152.209.11:21850] AH01276: Cannot serve directory /home1/yrtoccmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:57.112911 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.121:39584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUecL08BTTQixEnpYVgAAACg"]
[Thu Sep 17 15:14:57.143354 2026] [security2:error] [pid 971102:tid 971333] [client 44.239.144.77:60669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxYUecL08BTTQixEnpYUQAAAGM"], referer: http://worthtranslations.com/oldsite
[Thu Sep 17 15:14:57.192646 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUecL08BTTQixEnpYWAAAABc"]
[Thu Sep 17 15:14:57.200321 2026] [security2:error] [pid 971102:tid 971321] [client 134.185.85.61:57299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "rickanddonnaproctor.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYUecL08BTTQixEnpYWQAAAFc"]
[Thu Sep 17 15:14:57.200351 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUecL08BTTQixEnpYWAAAABc"]
[Thu Sep 17 15:14:57.658748 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYT-cL08BTTQixEnpYLgAAAFE"]
[Thu Sep 17 15:14:57.658779 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYT-cL08BTTQixEnpYLgAAAFE"]
[Thu Sep 17 15:14:57.943053 2026] [security2:error] [pid 971102:tid 971298] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxYUecL08BTTQixEnpYZAAAAEA"]
[Thu Sep 17 15:14:58.387290 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYUucL08BTTQixEnpYaAAAAHM"]
[Thu Sep 17 15:14:58.387312 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYUucL08BTTQixEnpYaAAAAHM"]
[Thu Sep 17 15:14:58.542204 2026] [security2:error] [pid 971102:tid 971322] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxYUucL08BTTQixEnpYbgAAAFg"]
[Thu Sep 17 15:14:58.711499 2026] [security2:error] [pid 971102:tid 971265] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/ninja-forms/index.php"] [unique_id "aqxYUucL08BTTQixEnpYcwAAAB8"]
[Thu Sep 17 15:14:58.856526 2026] [security2:error] [pid 971102:tid 971334] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxYUucL08BTTQixEnpYdAAAAGQ"]
[Thu Sep 17 15:14:59.012620 2026] [autoindex:error] [pid 971102:tid 971253] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:59.013211 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxYUucL08BTTQixEnpYdQAAABM"]
[Thu Sep 17 15:14:59.094978 2026] [security2:error] [pid 971102:tid 971316] [client 20.244.34.24:49582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxYU-cL08BTTQixEnpYdgAAAFI"], referer: binance.com
[Thu Sep 17 15:14:59.191642 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxYU-cL08BTTQixEnpYegAAABo"]
[Thu Sep 17 15:14:59.351169 2026] [autoindex:error] [pid 971102:tid 971332] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:59.351689 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxYU-cL08BTTQixEnpYggAAAGI"]
[Thu Sep 17 15:14:59.498140 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/blocks/"] [unique_id "aqxYU-cL08BTTQixEnpYhAAAAAM"]
[Thu Sep 17 15:14:59.655819 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxYU-cL08BTTQixEnpYigAAAGs"]
[Thu Sep 17 15:14:59.805180 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxYU-cL08BTTQixEnpYjwAAAGM"]
[Thu Sep 17 15:14:59.960175 2026] [autoindex:error] [pid 971102:tid 971248] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:59.960650 2026] [security2:error] [pid 971102:tid 971248] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxYU-cL08BTTQixEnpYlAAAAA4"]
[Thu Sep 17 15:15:00.108090 2026] [security2:error] [pid 971102:tid 971328] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/customize/"] [unique_id "aqxYVOcL08BTTQixEnpYmAAAAF4"]
[Thu Sep 17 15:15:00.262643 2026] [autoindex:error] [pid 971102:tid 971351] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:00.263131 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/customize/"] [unique_id "aqxYVOcL08BTTQixEnpYnQAAAHU"]
[Thu Sep 17 15:15:00.363645 2026] [security2:error] [pid 971102:tid 971283] [client 74.7.175.152:58020] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nebulous-llc.com"] [uri "/robots.txt"] [unique_id "aqxYVOcL08BTTQixEnpYngAAMTY"]
[Thu Sep 17 15:15:00.408551 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxYVOcL08BTTQixEnpYpAAAACs"]
[Thu Sep 17 15:15:00.571573 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:00.572122 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxYVOcL08BTTQixEnpYqwAAACA"]
[Thu Sep 17 15:15:00.719779 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/images/"] [unique_id "aqxYVOcL08BTTQixEnpYrwAAACk"]
[Thu Sep 17 15:15:00.904708 2026] [autoindex:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:00.905208 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/images/"] [unique_id "aqxYVOcL08BTTQixEnpYtQAAAGk"]
[Thu Sep 17 15:15:00.911395 2026] [security2:error] [pid 971102:tid 971317] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYVOcL08BTTQixEnpYsgAAAFM"]
[Thu Sep 17 15:15:01.107787 2026] [autoindex:error] [pid 971102:tid 971319] [client 85.204.70.96:33034] AH01276: Cannot serve directory /home2/savemor0/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:01.108250 2026] [security2:error] [pid 971102:tid 971319] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/.well-known/"] [unique_id "aqxYVecL08BTTQixEnpYugAAAFU"]
[Thu Sep 17 15:15:01.255491 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/ALFA_DATA/"] [unique_id "aqxYVecL08BTTQixEnpYuwAAADA"]
[Thu Sep 17 15:15:01.352821 2026] [security2:error] [pid 971102:tid 971244] [client 156.192.234.52:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVecL08BTTQixEnpYvgAAAAo"]
[Thu Sep 17 15:15:01.352901 2026] [security2:error] [pid 971102:tid 971244] [client 156.192.234.52:59023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVecL08BTTQixEnpYvgAAAAo"]
[Thu Sep 17 15:15:01.564343 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpYvwAAAGw"]
[Thu Sep 17 15:15:01.564374 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpYvwAAAGw"]
[Thu Sep 17 15:15:01.714793 2026] [security2:error] [pid 971102:tid 971247] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/.well-knownold/"] [unique_id "aqxYVecL08BTTQixEnpYyAAAAA0"]
[Thu Sep 17 15:15:01.761220 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env"] [unique_id "aqxYVecL08BTTQixEnpYyQAAAAk"]
[Thu Sep 17 15:15:01.910085 2026] [security2:error] [pid 971102:tid 971245] [client 104.248.203.175:60404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYUecL08BTTQixEnpYYAAAC1Q"], referer: http://mail.get-hope.org/wordpress/
[Thu Sep 17 15:15:02.035118 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpY0gAAAAc"]
[Thu Sep 17 15:15:02.035142 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpY0gAAAAc"]
[Thu Sep 17 15:15:02.196298 2026] [autoindex:error] [pid 971102:tid 971262] [client 85.204.70.96:33034] AH01276: Cannot serve directory /home2/savemor0/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:02.196836 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxYVucL08BTTQixEnpY2wAAABw"]
[Thu Sep 17 15:15:02.200356 2026] [security2:error] [pid 971102:tid 971296] [client 192.178.6.3:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYVucL08BTTQixEnpY3QAAAD4"]
[Thu Sep 17 15:15:02.264465 2026] [security2:error] [pid 971102:tid 971324] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY2gAAAFo"]
[Thu Sep 17 15:15:02.341983 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-bin/"] [unique_id "aqxYVucL08BTTQixEnpY5QAAAEU"]
[Thu Sep 17 15:15:02.530015 2026] [cgid:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] AH01265: stderr from /home2/savemor0/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:15:02.530561 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-bin/"] [unique_id "aqxYVucL08BTTQixEnpY6wAAAHQ"]
[Thu Sep 17 15:15:02.697736 2026] [security2:error] [pid 971102:tid 971300] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY6gAAAEI"]
[Thu Sep 17 15:15:02.702999 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/index/"] [unique_id "aqxYVucL08BTTQixEnpY7QAAAD0"]
[Thu Sep 17 15:15:02.872005 2026] [security2:error] [pid 971102:tid 971359] [client 186.105.232.15:63174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVucL08BTTQixEnpY7gAAAH0"]
[Thu Sep 17 15:15:02.872151 2026] [security2:error] [pid 971102:tid 971359] [client 186.105.232.15:63174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVucL08BTTQixEnpY7gAAAH0"]
[Thu Sep 17 15:15:02.895450 2026] [security2:error] [pid 971102:tid 971290] [client 104.248.203.175:60404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY3wAAOCY"], referer: http://mail.get-hope.org/old/
[Thu Sep 17 15:15:03.060191 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY7wAAACk"]
[Thu Sep 17 15:15:03.060213 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY7wAAACk"]
[Thu Sep 17 15:15:03.210086 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpY9QAAAEg"]
[Thu Sep 17 15:15:03.212870 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/id/"] [unique_id "aqxYV-cL08BTTQixEnpY9wAAABQ"]
[Thu Sep 17 15:15:03.538328 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpY_AAAAGk"]
[Thu Sep 17 15:15:03.538355 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpY_AAAAGk"]
[Thu Sep 17 15:15:03.656473 2026] [security2:error] [pid 971102:tid 971239] [client 212.200.122.55:57208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZAQAABSw"], referer: https://www.enolastable.com/2022/11/
[Thu Sep 17 15:15:03.681103 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZAAAAAHY"]
[Thu Sep 17 15:15:03.697336 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/www/"] [unique_id "aqxYV-cL08BTTQixEnpZAgAAAHc"]
[Thu Sep 17 15:15:03.979164 2026] [security2:error] [pid 971102:tid 971354] [client 5.189.145.112:49627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxYV-cL08BTTQixEnpZCwAAAHg"], referer: binance.com
[Thu Sep 17 15:15:03.987387 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZBAAAAAA"]
[Thu Sep 17 15:15:03.987406 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZBAAAAAA"]
[Thu Sep 17 15:15:03.995899 2026] [security2:error] [pid 971102:tid 971301] [client 185.55.149.49:65305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYV-cL08BTTQixEnpZDAAAAEM"]
[Thu Sep 17 15:15:03.995978 2026] [security2:error] [pid 971102:tid 971301] [client 185.55.149.49:65305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYV-cL08BTTQixEnpZDAAAAEM"]
[Thu Sep 17 15:15:04.139719 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/web/"] [unique_id "aqxYWOcL08BTTQixEnpZEAAAACw"]
[Thu Sep 17 15:15:04.177299 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZDwAAAHA"]
[Thu Sep 17 15:15:04.240795 2026] [autoindex:error] [pid 971102:tid 971312] [client 20.244.34.24:53325] AH01276: Cannot serve directory /home1/wxxngamy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:15:04.443318 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZEgAAABY"]
[Thu Sep 17 15:15:04.443343 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZEgAAABY"]
[Thu Sep 17 15:15:04.596978 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/uploads/"] [unique_id "aqxYWOcL08BTTQixEnpZGwAAACg"]
[Thu Sep 17 15:15:04.643526 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZGAAAAAc"]
[Thu Sep 17 15:15:04.650221 2026] [security2:error] [pid 971102:tid 971248] [client 20.244.34.24:54179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxYWOcL08BTTQixEnpZHAAAAA4"], referer: binance.com
[Thu Sep 17 15:15:04.883428 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZHwAAACY"]
[Thu Sep 17 15:15:04.883459 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZHwAAACY"]
[Thu Sep 17 15:15:04.929484 2026] [security2:error] [pid 971102:tid 971246] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxYWOcL08BTTQixEnpZJgAAAAw"]
[Thu Sep 17 15:15:05.046110 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/upload/"] [unique_id "aqxYWecL08BTTQixEnpZKAAAAEU"]
[Thu Sep 17 15:15:05.073002 2026] [security2:error] [pid 971102:tid 971302] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxYWecL08BTTQixEnpZKQAAAEQ"]
[Thu Sep 17 15:15:05.394188 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZLAAAAFs"]
[Thu Sep 17 15:15:05.394214 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZLAAAAFs"]
[Thu Sep 17 15:15:05.414021 2026] [security2:error] [pid 971102:tid 971266] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZLQAAACA"]
[Thu Sep 17 15:15:05.438500 2026] [access_compat:error] [pid 971102:tid 971286] [client 78.46.218.89:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/elven-legend-8-the-wicked-gears-collectors-edition
[Thu Sep 17 15:15:05.540906 2026] [security2:error] [pid 971102:tid 971298] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/uploads/"] [unique_id "aqxYWecL08BTTQixEnpZNgAAAEA"]
[Thu Sep 17 15:15:05.620831 2026] [security2:error] [pid 971102:tid 971319] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxYWecL08BTTQixEnpZOQAAAFU"]
[Thu Sep 17 15:15:05.833128 2026] [security2:error] [pid 971102:tid 971239] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZPAAAAAU"]
[Thu Sep 17 15:15:05.833159 2026] [security2:error] [pid 971102:tid 971239] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZPAAAAAU"]
[Thu Sep 17 15:15:05.914008 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZQAAAABM"]
[Thu Sep 17 15:15:05.990592 2026] [security2:error] [pid 971102:tid 971301] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Admin/uploads/"] [unique_id "aqxYWecL08BTTQixEnpZRQAAAEM"]
[Thu Sep 17 15:15:06.279866 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZRwAAAFA"]
[Thu Sep 17 15:15:06.279892 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZRwAAAFA"]
[Thu Sep 17 15:15:06.405402 2026] [security2:error] [pid 971102:tid 971344] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZSgAAAG4"]
[Thu Sep 17 15:15:06.437438 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/"] [unique_id "aqxYWucL08BTTQixEnpZUQAAACg"]
[Thu Sep 17 15:15:06.722583 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZVQAAABw"]
[Thu Sep 17 15:15:06.722611 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZVQAAABw"]
[Thu Sep 17 15:15:06.917911 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZWAAAABg"]
[Thu Sep 17 15:15:06.989737 2026] [security2:error] [pid 971102:tid 971246] [client 162.241.226.11:42902] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxYWucL08BTTQixEnpZYQAAAAw"]
[Thu Sep 17 15:15:07.105753 2026] [security2:error] [pid 971102:tid 971307] [client 114.198.138.124:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZYwAAAEk"]
[Thu Sep 17 15:15:07.105841 2026] [security2:error] [pid 971102:tid 971307] [client 114.198.138.124:62032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZYwAAAEk"]
[Thu Sep 17 15:15:07.332657 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYW-cL08BTTQixEnpZZwAAAEE"]
[Thu Sep 17 15:15:07.375421 2026] [security2:error] [pid 971102:tid 971338] [client 45.169.98.18:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZbAAAAGg"]
[Thu Sep 17 15:15:07.375531 2026] [security2:error] [pid 971102:tid 971338] [client 45.169.98.18:51818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZbAAAAGg"]
[Thu Sep 17 15:15:07.392128 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYWucL08BTTQixEnpZXgAAAHU"]
[Thu Sep 17 15:15:07.626348 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYW-cL08BTTQixEnpZdAAAADg"]
[Thu Sep 17 15:15:07.626472 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYW-cL08BTTQixEnpZdAAAADg"]
[Thu Sep 17 15:15:07.675580 2026] [security2:error] [pid 971102:tid 971325] [client 154.190.208.131:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZeAAAAFs"]
[Thu Sep 17 15:15:07.680098 2026] [security2:error] [pid 971102:tid 971325] [client 154.190.208.131:41794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZeAAAAFs"]
[Thu Sep 17 15:15:07.770371 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/images/"] [unique_id "aqxYW-cL08BTTQixEnpZegAAACE"]
[Thu Sep 17 15:15:07.914129 2026] [security2:error] [pid 971102:tid 971339] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYW-cL08BTTQixEnpZeQAAAGk"]
[Thu Sep 17 15:15:08.363809 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZhAAAAHA"]
[Thu Sep 17 15:15:08.627150 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZhQAAAFM"]
[Thu Sep 17 15:15:08.627176 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZhQAAAFM"]
[Thu Sep 17 15:15:08.721920 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZjwAAAFw"]
[Thu Sep 17 15:15:08.910420 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/assets/"] [unique_id "aqxYXOcL08BTTQixEnpZmwAAAEQ"]
[Thu Sep 17 15:15:09.031914 2026] [core:error] [pid 971102:tid 971315] [client 74.7.230.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:09.031933 2026] [core:error] [pid 971102:tid 971315] [client 74.7.230.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:09.032053 2026] [security2:error] [pid 971102:tid 971315] [client 74.7.230.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.athikerrev.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "aqxYXecL08BTTQixEnpZogAAAFE"]
[Thu Sep 17 15:15:09.033743 2026] [security2:error] [pid 971102:tid 971279] [client 74.7.230.17:34942] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.athikerrev.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxYXOcL08BTTQixEnpZnwAALVg"]
[Thu Sep 17 15:15:09.060952 2026] [security2:error] [pid 971102:tid 971271] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZmgAAACU"]
[Thu Sep 17 15:15:09.344486 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZowAAAHQ"]
[Thu Sep 17 15:15:09.344513 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZowAAAHQ"]
[Thu Sep 17 15:15:09.487496 2026] [security2:error] [pid 971102:tid 971295] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZrAAAAD0"]
[Thu Sep 17 15:15:09.493547 2026] [security2:error] [pid 971102:tid 971349] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxYXecL08BTTQixEnpZsQAAAHM"]
[Thu Sep 17 15:15:09.786143 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZuAAAAHg"]
[Thu Sep 17 15:15:09.786163 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZuAAAAHg"]
[Thu Sep 17 15:15:09.897532 2026] [security2:error] [pid 971102:tid 971256] [client 20.244.34.24:58049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxYXecL08BTTQixEnpZxgAAABY"], referer: binance.com
[Thu Sep 17 15:15:09.930163 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/upload/image/"] [unique_id "aqxYXecL08BTTQixEnpZxwAAAGY"]
[Thu Sep 17 15:15:09.950964 2026] [security2:error] [pid 971102:tid 971260] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZvgAAABo"]
[Thu Sep 17 15:15:10.241242 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZygAAAD4"]
[Thu Sep 17 15:15:10.241266 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZygAAAD4"]
[Thu Sep 17 15:15:10.410380 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/assets/images/"] [unique_id "aqxYXucL08BTTQixEnpZ0QAAAGw"]
[Thu Sep 17 15:15:10.524272 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZzwAAAFw"]
[Thu Sep 17 15:15:10.710680 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZ1AAAACY"]
[Thu Sep 17 15:15:10.710713 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZ1AAAACY"]
[Thu Sep 17 15:15:10.757599 2026] [security2:error] [pid 971102:tid 971317] [client 104.248.203.175:48070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZyQAAU3o"], referer: http://mail.get-hope.org/blog/
[Thu Sep 17 15:15:10.990160 2026] [security2:error] [pid 971102:tid 971275] [client 5.189.145.112:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxYXucL08BTTQixEnpZ3QAAACk"], referer: binance.com
[Thu Sep 17 15:15:11.032265 2026] [security2:error] [pid 971102:tid 971250] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxYX-cL08BTTQixEnpZ3wAAABA"]
[Thu Sep 17 15:15:11.049945 2026] [authz_core:error] [pid 971102:tid 971337] [client 172.239.147.162:51217] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-content/uploads/wpcf7_uploads/, referer: binance.com
[Thu Sep 17 15:15:11.119800 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env~"] [unique_id "aqxYX-cL08BTTQixEnpZ4QAAAFk"]
[Thu Sep 17 15:15:11.163232 2026] [security2:error] [pid 971102:tid 971270] [client 74.7.175.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.asrendering.com.au"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZngAAACQ"]
[Thu Sep 17 15:15:11.205431 2026] [security2:error] [pid 971102:tid 971324] [client 74.7.175.141:37522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.asrendering.com.au"] [uri "/robots.txt"] [unique_id "aqxYXOcL08BTTQixEnpZnAAAWgw"]
[Thu Sep 17 15:15:11.350039 2026] [security2:error] [pid 971102:tid 971340] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Public/"] [unique_id "aqxYX-cL08BTTQixEnpZ6gAAAGo"]
[Thu Sep 17 15:15:11.490520 2026] [security2:error] [pid 971102:tid 971357] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ5wAAAHs"]
[Thu Sep 17 15:15:11.647264 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ7QAAACE"]
[Thu Sep 17 15:15:11.647284 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ7QAAACE"]
[Thu Sep 17 15:15:11.806769 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/vendor/"] [unique_id "aqxYX-cL08BTTQixEnpZ8wAAADo"]
[Thu Sep 17 15:15:11.843099 2026] [security2:error] [pid 971102:tid 971325] [client 156.192.234.52:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYX-cL08BTTQixEnpZ9AAAAFs"]
[Thu Sep 17 15:15:11.843217 2026] [security2:error] [pid 971102:tid 971325] [client 156.192.234.52:59733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYX-cL08BTTQixEnpZ9AAAAFs"]
[Thu Sep 17 15:15:12.017069 2026] [security2:error] [pid 971102:tid 971277] [client 104.248.203.175:48070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ6wAAK3s"], referer: http://mail.get-hope.org/wp/
[Thu Sep 17 15:15:12.097578 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ-wAAAEw"]
[Thu Sep 17 15:15:12.097604 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ-wAAAEw"]
[Thu Sep 17 15:15:12.166944 2026] [security2:error] [pid 971102:tid 971239] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpZ_QAAAAU"]
[Thu Sep 17 15:15:12.246991 2026] [security2:error] [pid 971102:tid 971331] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/local/"] [unique_id "aqxYYOcL08BTTQixEnpaAgAAAGE"]
[Thu Sep 17 15:15:12.561554 2026] [security2:error] [pid 971102:tid 971321] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaCwAAAFc"]
[Thu Sep 17 15:15:12.561578 2026] [security2:error] [pid 971102:tid 971321] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaCwAAAFc"]
[Thu Sep 17 15:15:12.577594 2026] [autoindex:error] [pid 971102:tid 971285] [client 105.113.91.150:7441] AH01276: Cannot serve directory /home1/afbacoco/public_html/windyisland/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://allbacklinkschecker.website/dir/link-outreach-services-232789
[Thu Sep 17 15:15:12.631634 2026] [security2:error] [pid 971102:tid 971333] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaDAAAAGM"]
[Thu Sep 17 15:15:12.708094 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/modules/"] [unique_id "aqxYYOcL08BTTQixEnpaEQAAAE4"]
[Thu Sep 17 15:15:12.970436 2026] [security2:error] [pid 971102:tid 971244] [client 104.248.203.175:48070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaBQAACmY"], referer: http://mail.get-hope.org/new/
[Thu Sep 17 15:15:13.029431 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaFAAAAHI"]
[Thu Sep 17 15:15:13.029454 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaFAAAAHI"]
[Thu Sep 17 15:15:13.196315 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Site/"] [unique_id "aqxYYecL08BTTQixEnpaGwAAAEo"]
[Thu Sep 17 15:15:13.210655 2026] [security2:error] [pid 971102:tid 971334] [client 44.252.126.63:8295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ7wAAAGQ"]
[Thu Sep 17 15:15:13.486720 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaHQAAAEU"]
[Thu Sep 17 15:15:13.486753 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaHQAAAEU"]
[Thu Sep 17 15:15:13.562538 2026] [security2:error] [pid 971102:tid 971315] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaJgAAAFE"]
[Thu Sep 17 15:15:13.578336 2026] [authz_core:error] [pid 971102:tid 971343] [client 172.239.147.162:53756] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-content/uploads/wpcf7_uploads/, referer: binance.com
[Thu Sep 17 15:15:13.632833 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/system/"] [unique_id "aqxYYecL08BTTQixEnpaKQAAAC4"]
[Thu Sep 17 15:15:13.957684 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaLgAAAEg"]
[Thu Sep 17 15:15:13.957721 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaLgAAAEg"]
[Thu Sep 17 15:15:13.980361 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaLwAAAF4"]
[Thu Sep 17 15:15:14.105057 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/template/"] [unique_id "aqxYYucL08BTTQixEnpaOAAAAHg"]
[Thu Sep 17 15:15:14.105082 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaOQAAAHs"]
[Thu Sep 17 15:15:14.105164 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaOQAAAHs"]
[Thu Sep 17 15:15:14.213854 2026] [security2:error] [pid 971102:tid 971251] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxYYucL08BTTQixEnpaPAAAABE"]
[Thu Sep 17 15:15:14.331741 2026] [security2:error] [pid 971102:tid 971314] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxYYucL08BTTQixEnpaPwAAAFA"]
[Thu Sep 17 15:15:14.395306 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYucL08BTTQixEnpaPQAAAHY"]
[Thu Sep 17 15:15:14.395331 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYucL08BTTQixEnpaPQAAAHY"]
[Thu Sep 17 15:15:14.419629 2026] [security2:error] [pid 971102:tid 971333] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxYYucL08BTTQixEnpaQwAAAGM"]
[Thu Sep 17 15:15:14.519522 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxYYucL08BTTQixEnpaRQAAAAE"]
[Thu Sep 17 15:15:14.592326 2026] [security2:error] [pid 971102:tid 971330] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/shop/"] [unique_id "aqxYYucL08BTTQixEnpaSQAAAGA"]
[Thu Sep 17 15:15:14.611427 2026] [security2:error] [pid 971102:tid 971278] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxYYucL08BTTQixEnpaSgAAACw"]
[Thu Sep 17 15:15:14.699165 2026] [core:error] [pid 971102:tid 971296] [client 35.185.138.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:14.699183 2026] [core:error] [pid 971102:tid 971296] [client 35.185.138.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:14.699290 2026] [security2:error] [pid 971102:tid 971296] [client 35.185.138.72:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.sahlan.24eastyard.com"] [uri "/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/.git/config"] [unique_id "aqxYYucL08BTTQixEnpaSwAAAD4"]
[Thu Sep 17 15:15:14.705178 2026] [security2:error] [pid 971102:tid 971245] [client 35.185.138.72:60656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.sahlan.24eastyard.com"] [uri "/.git/config"] [unique_id "aqxYYucL08BTTQixEnpaRwAAAAs"]
[Thu Sep 17 15:15:14.723517 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:23029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTAAAADQ"]
[Thu Sep 17 15:15:14.723595 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:23029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTAAAADQ"]
[Thu Sep 17 15:15:14.735643 2026] [security2:error] [pid 971102:tid 971348] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxYYucL08BTTQixEnpaTQAAAHI"]
[Thu Sep 17 15:15:14.818472 2026] [security2:error] [pid 971102:tid 971312] [client 185.55.149.49:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTgAAAE4"]
[Thu Sep 17 15:15:14.818570 2026] [security2:error] [pid 971102:tid 971312] [client 185.55.149.49:49896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTgAAAE4"]
[Thu Sep 17 15:15:15.037682 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYucL08BTTQixEnpaUwAAAFw"]
[Thu Sep 17 15:15:15.154048 2026] [security2:error] [pid 971102:tid 971318] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaVgAAAFQ"]
[Thu Sep 17 15:15:15.154068 2026] [security2:error] [pid 971102:tid 971318] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaVgAAAFQ"]
[Thu Sep 17 15:15:15.303193 2026] [security2:error] [pid 971102:tid 971249] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/files/"] [unique_id "aqxYY-cL08BTTQixEnpaWwAAAA8"]
[Thu Sep 17 15:15:15.346434 2026] [security2:error] [pid 971102:tid 971315] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxYY-cL08BTTQixEnpaXgAAAFE"]
[Thu Sep 17 15:15:15.382459 2026] [security2:error] [pid 971102:tid 971282] [client 210.222.43.21:49378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaWgAAADA"], referer: http://talent-in-borders.com/2021
[Thu Sep 17 15:15:15.442251 2026] [security2:error] [pid 971102:tid 971271] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxYY-cL08BTTQixEnpaYQAAACU"]
[Thu Sep 17 15:15:15.563651 2026] [security2:error] [pid 971102:tid 971329] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxYY-cL08BTTQixEnpaZQAAAF8"]
[Thu Sep 17 15:15:15.633680 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaYgAAABM"]
[Thu Sep 17 15:15:15.633710 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaYgAAABM"]
[Thu Sep 17 15:15:15.654142 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxYY-cL08BTTQixEnpaZwAAAC0"]
[Thu Sep 17 15:15:15.671171 2026] [security2:error] [pid 971102:tid 971289] [client 49.13.24.81:4846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaKwAAADc"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:15:15.770639 2026] [security2:error] [pid 971102:tid 971340] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxYY-cL08BTTQixEnpaaAAAAGo"]
[Thu Sep 17 15:15:15.804831 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/editor/"] [unique_id "aqxYY-cL08BTTQixEnpabAAAAC8"]
[Thu Sep 17 15:15:15.851836 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxYY-cL08BTTQixEnpabgAAAAY"]
[Thu Sep 17 15:15:15.958314 2026] [security2:error] [pid 971102:tid 971327] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxYY-cL08BTTQixEnpadAAAAF0"]
[Thu Sep 17 15:15:16.061251 2026] [security2:error] [pid 971102:tid 971290] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxYZOcL08BTTQixEnpadwAAADg"]
[Thu Sep 17 15:15:16.091053 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpacgAAADo"]
[Thu Sep 17 15:15:16.091084 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpacgAAADo"]
[Thu Sep 17 15:15:16.164347 2026] [security2:error] [pid 971102:tid 971295] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxYZOcL08BTTQixEnpaeQAAAD0"]
[Thu Sep 17 15:15:16.237824 2026] [security2:error] [pid 971102:tid 971278] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxYZOcL08BTTQixEnpaegAAACw"]
[Thu Sep 17 15:15:16.238877 2026] [security2:error] [pid 971102:tid 971335] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/include/"] [unique_id "aqxYZOcL08BTTQixEnpaewAAAGU"]
[Thu Sep 17 15:15:16.258040 2026] [security2:error] [pid 971102:tid 971300] [client 49.13.24.81:19406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnpaeAAAAEI"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:15:16.292082 2026] [security2:error] [pid 971102:tid 971268] [client 3.82.141.143:36162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php.save"] [unique_id "aqxYZOcL08BTTQixEnpagQAAACI"]
[Thu Sep 17 15:15:16.292322 2026] [security2:error] [pid 971102:tid 971313] [client 3.82.141.143:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.meatlessmusings.com"] [uri "/config.php"] [unique_id "aqxYZOcL08BTTQixEnpaggAAAE8"]
[Thu Sep 17 15:15:16.296879 2026] [proxy_http:error] [pid 971102:tid 971353] (20014)Internal error (specific information not available): [client 3.82.141.143:35872] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.296893 2026] [proxy:error] [pid 971102:tid 971353] [client 3.82.141.143:35872] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.local
[Thu Sep 17 15:15:16.302042 2026] [proxy_http:error] [pid 971102:tid 971235] (20014)Internal error (specific information not available): [client 3.82.141.143:36112] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.302062 2026] [proxy:error] [pid 971102:tid 971235] [client 3.82.141.143:36112] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.netrc
[Thu Sep 17 15:15:16.303765 2026] [security2:error] [pid 971102:tid 971286] [client 3.82.141.143:36184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php~"] [unique_id "aqxYZOcL08BTTQixEnpaigAAADQ"]
[Thu Sep 17 15:15:16.306954 2026] [proxy_http:error] [pid 971102:tid 971361] (20014)Internal error (specific information not available): [client 3.82.141.143:36010] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.306967 2026] [proxy:error] [pid 971102:tid 971361] [client 3.82.141.143:36010] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/web.config
[Thu Sep 17 15:15:16.307021 2026] [security2:error] [pid 971102:tid 971260] [client 3.82.141.143:36154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php.old"] [unique_id "aqxYZOcL08BTTQixEnpalAAAABo"]
[Thu Sep 17 15:15:16.318751 2026] [proxy_http:error] [pid 971102:tid 971274] (20014)Internal error (specific information not available): [client 3.82.141.143:36070] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.318764 2026] [proxy:error] [pid 971102:tid 971274] [client 3.82.141.143:36070] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.aws/config
[Thu Sep 17 15:15:16.318985 2026] [security2:error] [pid 971102:tid 971348] [client 3.82.141.143:36176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYZOcL08BTTQixEnpapAAAAHI"]
[Thu Sep 17 15:15:16.319355 2026] [security2:error] [pid 971102:tid 971273] [client 3.82.141.143:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php"] [unique_id "aqxYZOcL08BTTQixEnpapQAAACc"]
[Thu Sep 17 15:15:16.323423 2026] [proxy_http:error] [pid 971102:tid 971331] (20014)Internal error (specific information not available): [client 3.82.141.143:35924] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.323433 2026] [proxy:error] [pid 971102:tid 971331] [client 3.82.141.143:35924] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.bak
[Thu Sep 17 15:15:16.334236 2026] [proxy_http:error] [pid 971102:tid 971296] (20014)Internal error (specific information not available): [client 3.82.141.143:35894] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.334247 2026] [proxy:error] [pid 971102:tid 971296] [client 3.82.141.143:35894] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.staging
[Thu Sep 17 15:15:16.338919 2026] [proxy_http:error] [pid 971102:tid 971319] (20014)Internal error (specific information not available): [client 3.82.141.143:35998] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.338934 2026] [proxy:error] [pid 971102:tid 971319] [client 3.82.141.143:35998] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/secret.json
[Thu Sep 17 15:15:16.343050 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxYZOcL08BTTQixEnpaqAAAAFw"]
[Thu Sep 17 15:15:16.349778 2026] [proxy_http:error] [pid 971102:tid 971320] (20014)Internal error (specific information not available): [client 3.82.141.143:35946] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.349794 2026] [proxy:error] [pid 971102:tid 971320] [client 3.82.141.143:35946] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/config.json
[Thu Sep 17 15:15:16.354504 2026] [proxy_http:error] [pid 971102:tid 971241] (20014)Internal error (specific information not available): [client 3.82.141.143:36022] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.354516 2026] [proxy:error] [pid 971102:tid 971241] [client 3.82.141.143:36022] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/application.yml
[Thu Sep 17 15:15:16.359189 2026] [proxy_http:error] [pid 971102:tid 971321] (20014)Internal error (specific information not available): [client 3.82.141.143:35944] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.359206 2026] [proxy:error] [pid 971102:tid 971321] [client 3.82.141.143:35944] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.dist
[Thu Sep 17 15:15:16.363759 2026] [proxy_http:error] [pid 971102:tid 971347] (20014)Internal error (specific information not available): [client 3.82.141.143:36146] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.363774 2026] [proxy:error] [pid 971102:tid 971347] [client 3.82.141.143:36146] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.git-credentials
[Thu Sep 17 15:15:16.369122 2026] [proxy_http:error] [pid 971102:tid 971262] (20014)Internal error (specific information not available): [client 3.82.141.143:36086] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.369139 2026] [proxy:error] [pid 971102:tid 971262] [client 3.82.141.143:36086] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.s3cfg
[Thu Sep 17 15:15:16.374180 2026] [proxy_http:error] [pid 971102:tid 971266] (20014)Internal error (specific information not available): [client 3.82.141.143:36126] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.374194 2026] [proxy:error] [pid 971102:tid 971266] [client 3.82.141.143:36126] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.gitlab-ci.yml
[Thu Sep 17 15:15:16.379093 2026] [proxy_http:error] [pid 971102:tid 971336] (20014)Internal error (specific information not available): [client 3.82.141.143:35984] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.379106 2026] [proxy:error] [pid 971102:tid 971336] [client 3.82.141.143:35984] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/settings.json
[Thu Sep 17 15:15:16.384381 2026] [proxy_http:error] [pid 971102:tid 971342] (20014)Internal error (specific information not available): [client 3.82.141.143:35932] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.384393 2026] [proxy:error] [pid 971102:tid 971342] [client 3.82.141.143:35932] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.save
[Thu Sep 17 15:15:16.389201 2026] [proxy_http:error] [pid 971102:tid 971274] (20014)Internal error (specific information not available): [client 3.82.141.143:36070] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.389216 2026] [proxy:error] [pid 971102:tid 971274] [client 3.82.141.143:36070] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Thu Sep 17 15:15:16.394339 2026] [proxy_http:error] [pid 971102:tid 971331] (20014)Internal error (specific information not available): [client 3.82.141.143:35924] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.394351 2026] [proxy:error] [pid 971102:tid 971331] [client 3.82.141.143:35924] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Thu Sep 17 15:15:16.398473 2026] [security2:error] [pid 971102:tid 971284] [client 24.250.150.202:57311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYZOcL08BTTQixEnpafAAAMl4"]
[Thu Sep 17 15:15:16.442639 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxYZOcL08BTTQixEnparwAAAFk"]
[Thu Sep 17 15:15:16.519235 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxYZOcL08BTTQixEnpaswAAAAY"]
[Thu Sep 17 15:15:16.536270 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnparAAAAFM"]
[Thu Sep 17 15:15:16.536292 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnparAAAAFM"]
[Thu Sep 17 15:15:16.598802 2026] [security2:error] [pid 971102:tid 971356] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxYZOcL08BTTQixEnpatAAAAHo"]
[Thu Sep 17 15:15:16.696331 2026] [security2:error] [pid 971102:tid 971293] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Assets/"] [unique_id "aqxYZOcL08BTTQixEnpatwAAADs"]
[Thu Sep 17 15:15:16.720880 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxYZOcL08BTTQixEnpauAAAAEg"]
[Thu Sep 17 15:15:16.868304 2026] [security2:error] [pid 971102:tid 971267] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxYZOcL08BTTQixEnpauwAAACE"]
[Thu Sep 17 15:15:16.977069 2026] [security2:error] [pid 971102:tid 971335] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxYZOcL08BTTQixEnpavwAAAGU"]
[Thu Sep 17 15:15:16.978278 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnpauQAAACs"]
[Thu Sep 17 15:15:16.978298 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnpauQAAACs"]
[Thu Sep 17 15:15:17.082040 2026] [security2:error] [pid 971102:tid 971325] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxYZecL08BTTQixEnpawgAAAFs"]
[Thu Sep 17 15:15:17.123620 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/images/stories/"] [unique_id "aqxYZecL08BTTQixEnpaxAAAAE8"]
[Thu Sep 17 15:15:17.162241 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxYZecL08BTTQixEnpaxgAAAAk"]
[Thu Sep 17 15:15:17.240601 2026] [security2:error] [pid 971102:tid 971348] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxYZecL08BTTQixEnpaxwAAAHI"]
[Thu Sep 17 15:15:17.259990 2026] [security2:error] [pid 971102:tid 971322] [client 20.244.34.24:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxYZecL08BTTQixEnpaygAAAFg"], referer: binance.com
[Thu Sep 17 15:15:17.322201 2026] [security2:error] [pid 971102:tid 971314] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxYZecL08BTTQixEnpazQAAAFA"]
[Thu Sep 17 15:15:17.393319 2026] [security2:error] [pid 971102:tid 971305] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxYZecL08BTTQixEnpa0QAAAEc"]
[Thu Sep 17 15:15:17.458610 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpaywAAACo"]
[Thu Sep 17 15:15:17.458628 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpaywAAACo"]
[Thu Sep 17 15:15:17.469087 2026] [security2:error] [pid 971102:tid 971248] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxYZecL08BTTQixEnpa0wAAAA4"]
[Thu Sep 17 15:15:17.562353 2026] [security2:error] [pid 971102:tid 971291] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxYZecL08BTTQixEnpa1QAAADk"]
[Thu Sep 17 15:15:17.610411 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/plugins/"] [unique_id "aqxYZecL08BTTQixEnpa1gAAAAo"]
[Thu Sep 17 15:15:17.633054 2026] [security2:error] [pid 971102:tid 971274] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxYZecL08BTTQixEnpa1wAAACg"]
[Thu Sep 17 15:15:17.732237 2026] [security2:error] [pid 971102:tid 971296] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxYZecL08BTTQixEnpa3AAAAD4"]
[Thu Sep 17 15:15:17.813916 2026] [security2:error] [pid 971102:tid 971347] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxYZecL08BTTQixEnpa3wAAAHE"]
[Thu Sep 17 15:15:17.827861 2026] [security2:error] [pid 971102:tid 971319] [client 24.250.150.202:42873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYZecL08BTTQixEnpa3QAAVSA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821163557&hideanons=1&limit=500&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:15:17.866185 2026] [security2:error] [pid 971102:tid 971245] [client 114.198.138.124:62680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa4wAAAAs"]
[Thu Sep 17 15:15:17.866312 2026] [security2:error] [pid 971102:tid 971245] [client 114.198.138.124:62680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa4wAAAAs"]
[Thu Sep 17 15:15:17.875154 2026] [security2:error] [pid 971102:tid 971284] [client 45.169.98.18:52381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa5AAAADI"]
[Thu Sep 17 15:15:17.875288 2026] [security2:error] [pid 971102:tid 971284] [client 45.169.98.18:52381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa5AAAADI"]
[Thu Sep 17 15:15:17.892673 2026] [security2:error] [pid 971102:tid 971320] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpa3gAAAFY"]
[Thu Sep 17 15:15:17.892705 2026] [security2:error] [pid 971102:tid 971320] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpa3gAAAFY"]
[Thu Sep 17 15:15:17.919752 2026] [security2:error] [pid 971102:tid 971336] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxYZecL08BTTQixEnpa5QAAAGY"]
[Thu Sep 17 15:15:18.015821 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxYZucL08BTTQixEnpa5wAAAEY"]
[Thu Sep 17 15:15:18.046883 2026] [security2:error] [pid 971102:tid 971249] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/php/"] [unique_id "aqxYZucL08BTTQixEnpa6AAAAA8"]
[Thu Sep 17 15:15:18.128249 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxYZucL08BTTQixEnpa6gAAAFk"]
[Thu Sep 17 15:15:18.143419 2026] [security2:error] [pid 971102:tid 971234] [client 172.239.147.162:61390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpa2AAAAAA"], referer: binance.com
[Thu Sep 17 15:15:18.202258 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxYZucL08BTTQixEnpa7AAAAEE"]
[Thu Sep 17 15:15:18.295257 2026] [security2:error] [pid 971102:tid 971275] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxYZucL08BTTQixEnpa7gAAACk"]
[Thu Sep 17 15:15:18.338533 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZucL08BTTQixEnpa7QAAAF8"]
[Thu Sep 17 15:15:18.338558 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZucL08BTTQixEnpa7QAAAF8"]
[Thu Sep 17 15:15:18.495973 2026] [security2:error] [pid 971102:tid 971301] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/"] [unique_id "aqxYZucL08BTTQixEnpa-QAAAEM"]
[Thu Sep 17 15:15:18.651445 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxYZucL08BTTQixEnpa-wAAADw"]
[Thu Sep 17 15:15:18.688182 2026] [autoindex:error] [pid 971102:tid 971332] [client 85.204.70.96:35964] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:18.688686 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/"] [unique_id "aqxYZucL08BTTQixEnpa-gAAAGI"]
[Thu Sep 17 15:15:18.759650 2026] [security2:error] [pid 971102:tid 971290] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxYZucL08BTTQixEnpa_AAAADg"]
[Thu Sep 17 15:15:18.842846 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxYZucL08BTTQixEnpa_QAAAEs"]
[Thu Sep 17 15:15:18.862880 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxYZucL08BTTQixEnpa_gAAAEg"]
[Thu Sep 17 15:15:19.000965 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "aqxYZucL08BTTQixEnpbAwAAAFs"]
[Thu Sep 17 15:15:19.011778 2026] [security2:error] [pid 971102:tid 971292] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbBAAAADo"]
[Thu Sep 17 15:15:19.147266 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/cache/"] [unique_id "aqxYZ-cL08BTTQixEnpbCAAAAHc"]
[Thu Sep 17 15:15:19.158817 2026] [security2:error] [pid 971102:tid 971251] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbCQAAABE"]
[Thu Sep 17 15:15:19.248709 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbCwAAAHA"]
[Thu Sep 17 15:15:19.255149 2026] [security2:error] [pid 971102:tid 971270] [client 154.190.208.131:42444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZ-cL08BTTQixEnpbDAAAACQ"]
[Thu Sep 17 15:15:19.255215 2026] [security2:error] [pid 971102:tid 971270] [client 154.190.208.131:42444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZ-cL08BTTQixEnpbDAAAACQ"]
[Thu Sep 17 15:15:19.346340 2026] [security2:error] [pid 971102:tid 971272] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbDQAAACY"]
[Thu Sep 17 15:15:19.457729 2026] [security2:error] [pid 971102:tid 971246] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbDwAAAAw"]
[Thu Sep 17 15:15:19.528973 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbEQAAABg"]
[Thu Sep 17 15:15:19.621249 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbFAAAADU"]
[Thu Sep 17 15:15:19.715495 2026] [security2:error] [pid 971102:tid 971296] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbGAAAAD4"]
[Thu Sep 17 15:15:19.795114 2026] [security2:error] [pid 971102:tid 971260] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbGgAAABo"]
[Thu Sep 17 15:15:19.925607 2026] [security2:error] [pid 971102:tid 971284] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbGwAAADI"]
[Thu Sep 17 15:15:20.004627 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZ-cL08BTTQixEnpbEgAAAE4"]
[Thu Sep 17 15:15:20.004650 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZ-cL08BTTQixEnpbEgAAAE4"]
[Thu Sep 17 15:15:20.006893 2026] [security2:error] [pid 971102:tid 971239] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxYaOcL08BTTQixEnpbHQAAAAU"]
[Thu Sep 17 15:15:20.100814 2026] [security2:error] [pid 971102:tid 971342] [client 5.189.145.112:57399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxYaOcL08BTTQixEnpbHgAAAGw"], referer: binance.com
[Thu Sep 17 15:15:20.105535 2026] [security2:error] [pid 971102:tid 971266] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxYaOcL08BTTQixEnpbHwAAACA"]
[Thu Sep 17 15:15:20.194906 2026] [security2:error] [pid 971102:tid 971330] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxYaOcL08BTTQixEnpbJQAAAGA"]
[Thu Sep 17 15:15:20.237299 2026] [authz_core:error] [pid 971102:tid 971245] [client 172.239.147.162:57278] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:20.293804 2026] [security2:error] [pid 971102:tid 971249] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxYaOcL08BTTQixEnpbJgAAAA8"]
[Thu Sep 17 15:15:20.385705 2026] [security2:error] [pid 971102:tid 971351] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxYaOcL08BTTQixEnpbJwAAAHU"]
[Thu Sep 17 15:15:20.478341 2026] [security2:error] [pid 971102:tid 971271] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxYaOcL08BTTQixEnpbKgAAACU"]
[Thu Sep 17 15:15:20.505221 2026] [security2:error] [pid 971102:tid 971337] [client 172.239.147.162:63347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxYaOcL08BTTQixEnpbKAAAAGc"], referer: binance.com
[Thu Sep 17 15:15:20.527582 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/maint/"] [unique_id "aqxYaOcL08BTTQixEnpbKwAAAAA"]
[Thu Sep 17 15:15:20.553256 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxYaOcL08BTTQixEnpbLAAAAEE"]
[Thu Sep 17 15:15:20.659268 2026] [security2:error] [pid 971102:tid 971307] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxYaOcL08BTTQixEnpbMQAAAEk"]
[Thu Sep 17 15:15:20.731796 2026] [autoindex:error] [pid 971102:tid 971329] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:20.732286 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/maint/"] [unique_id "aqxYaOcL08BTTQixEnpbMgAAAF8"]
[Thu Sep 17 15:15:20.786867 2026] [security2:error] [pid 971102:tid 971242] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxYaOcL08BTTQixEnpbNAAAAAg"]
[Thu Sep 17 15:15:20.876310 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxYaOcL08BTTQixEnpbNQAAAC0"]
[Thu Sep 17 15:15:20.889571 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYaOcL08BTTQixEnpbNgAAAEQ"]
[Thu Sep 17 15:15:21.023588 2026] [security2:error] [pid 971102:tid 971356] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxYaecL08BTTQixEnpbOAAAAHo"]
[Thu Sep 17 15:15:21.034635 2026] [authz_core:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] AH01630: client denied by server configuration: /home2/savemor0/public_html/wp-content/plugins/akismet/
[Thu Sep 17 15:15:21.035525 2026] [security2:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYaecL08BTTQixEnpbOQAAADw"]
[Thu Sep 17 15:15:21.162914 2026] [security2:error] [pid 971102:tid 971335] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxYaecL08BTTQixEnpbPwAAAGU"]
[Thu Sep 17 15:15:21.194742 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/assets/"] [unique_id "aqxYaecL08BTTQixEnpbQQAAAHQ"]
[Thu Sep 17 15:15:21.242548 2026] [security2:error] [pid 971102:tid 971238] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxYaecL08BTTQixEnpbQwAAAAQ"]
[Thu Sep 17 15:15:21.352517 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxYaecL08BTTQixEnpbRQAAAHA"]
[Thu Sep 17 15:15:21.354360 2026] [autoindex:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:21.354837 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/assets/"] [unique_id "aqxYaecL08BTTQixEnpbRAAAAFA"]
[Thu Sep 17 15:15:21.426861 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxYaecL08BTTQixEnpbRgAAAHY"]
[Thu Sep 17 15:15:21.506396 2026] [security2:error] [pid 971102:tid 971326] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYaecL08BTTQixEnpbSQAAAFw"]
[Thu Sep 17 15:15:21.534895 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxYaecL08BTTQixEnpbSgAAADU"]
[Thu Sep 17 15:15:21.616905 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxYaecL08BTTQixEnpbTwAAAAc"]
[Thu Sep 17 15:15:21.659164 2026] [autoindex:error] [pid 971102:tid 971260] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:21.659677 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYaecL08BTTQixEnpbVAAAABo"]
[Thu Sep 17 15:15:21.707789 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxYaecL08BTTQixEnpbWAAAAAo"]
[Thu Sep 17 15:15:21.804111 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxYaecL08BTTQixEnpbWQAAAE4"]
[Thu Sep 17 15:15:21.808112 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYaecL08BTTQixEnpbWgAAACs"]
[Thu Sep 17 15:15:21.879975 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxYaecL08BTTQixEnpbWwAAAFQ"]
[Thu Sep 17 15:15:21.964520 2026] [autoindex:error] [pid 971102:tid 971358] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:21.965031 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYaecL08BTTQixEnpbXAAAAHw"]
[Thu Sep 17 15:15:22.010091 2026] [security2:error] [pid 971102:tid 971331] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxYaucL08BTTQixEnpbXQAAAGE"]
[Thu Sep 17 15:15:22.090416 2026] [security2:error] [pid 971102:tid 971342] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxYaucL08BTTQixEnpbYQAAAGw"]
[Thu Sep 17 15:15:22.110140 2026] [security2:error] [pid 971102:tid 971334] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxYaucL08BTTQixEnpbZAAAAGQ"]
[Thu Sep 17 15:15:22.173622 2026] [authz_core:error] [pid 971102:tid 971336] [client 172.239.147.162:59412] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:22.174878 2026] [security2:error] [pid 971102:tid 971249] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxYaucL08BTTQixEnpbaAAAAA8"]
[Thu Sep 17 15:15:22.268795 2026] [security2:error] [pid 971102:tid 971282] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxYaucL08BTTQixEnpbagAAADA"]
[Thu Sep 17 15:15:22.274744 2026] [autoindex:error] [pid 971102:tid 971323] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:22.275393 2026] [security2:error] [pid 971102:tid 971323] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxYaucL08BTTQixEnpbaQAAAFk"]
[Thu Sep 17 15:15:22.363967 2026] [security2:error] [pid 971102:tid 971257] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxYaucL08BTTQixEnpbawAAABc"]
[Thu Sep 17 15:15:22.389201 2026] [security2:error] [pid 971102:tid 971293] [client 156.192.234.52:60329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYaucL08BTTQixEnpbbQAAADs"]
[Thu Sep 17 15:15:22.389297 2026] [security2:error] [pid 971102:tid 971293] [client 156.192.234.52:60329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYaucL08BTTQixEnpbbQAAADs"]
[Thu Sep 17 15:15:22.420525 2026] [security2:error] [pid 971102:tid 971337] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/js/"] [unique_id "aqxYaucL08BTTQixEnpbbgAAAGc"]
[Thu Sep 17 15:15:22.441517 2026] [security2:error] [pid 971102:tid 971234] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxYaucL08BTTQixEnpbbwAAAAA"]
[Thu Sep 17 15:15:22.520882 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxYaucL08BTTQixEnpbcAAAAEE"]
[Thu Sep 17 15:15:22.574932 2026] [autoindex:error] [pid 971102:tid 971349] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:22.575440 2026] [security2:error] [pid 971102:tid 971349] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/js/"] [unique_id "aqxYaucL08BTTQixEnpbcQAAAHM"]
[Thu Sep 17 15:15:22.630999 2026] [security2:error] [pid 971102:tid 971341] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxYaucL08BTTQixEnpbdgAAAGs"]
[Thu Sep 17 15:15:22.708107 2026] [security2:error] [pid 971102:tid 971330] [client 212.195.220.248:54847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYaucL08BTTQixEnpbcwAAYFE"]
[Thu Sep 17 15:15:22.719928 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYaucL08BTTQixEnpbeQAAAAg"]
[Thu Sep 17 15:15:22.724089 2026] [security2:error] [pid 971102:tid 971247] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxYaucL08BTTQixEnpbegAAAA0"]
[Thu Sep 17 15:15:22.796920 2026] [security2:error] [pid 971102:tid 971327] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxYaucL08BTTQixEnpbewAAAF0"]
[Thu Sep 17 15:15:22.903313 2026] [autoindex:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:22.903788 2026] [security2:error] [pid 971102:tid 971288] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxYaucL08BTTQixEnpbfgAAADY"]
[Thu Sep 17 15:15:22.903858 2026] [security2:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYaucL08BTTQixEnpbfQAAADw"]
[Thu Sep 17 15:15:22.985516 2026] [security2:error] [pid 971102:tid 971345] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxYaucL08BTTQixEnpbfwAAAG8"]
[Thu Sep 17 15:15:23.050248 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYa-cL08BTTQixEnpbggAAAEg"]
[Thu Sep 17 15:15:23.068681 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxYa-cL08BTTQixEnpbgwAAAAY"]
[Thu Sep 17 15:15:23.159889 2026] [security2:error] [pid 971102:tid 971309] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxYa-cL08BTTQixEnpbiAAAAEs"]
[Thu Sep 17 15:15:23.202684 2026] [autoindex:error] [pid 971102:tid 971328] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:23.203183 2026] [security2:error] [pid 971102:tid 971328] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYa-cL08BTTQixEnpbiQAAAF4"]
[Thu Sep 17 15:15:23.253495 2026] [security2:error] [pid 971102:tid 971301] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxYa-cL08BTTQixEnpbjAAAAEM"]
[Thu Sep 17 15:15:23.275881 2026] [authz_core:error] [pid 971102:tid 971335] [client 172.239.147.162:59946] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:23.348584 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxYa-cL08BTTQixEnpbjQAAAE8"]
[Thu Sep 17 15:15:23.369396 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxYa-cL08BTTQixEnpbjgAAAAk"]
[Thu Sep 17 15:15:23.451868 2026] [security2:error] [pid 971102:tid 971251] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxYa-cL08BTTQixEnpbjwAAABE"]
[Thu Sep 17 15:15:23.504908 2026] [autoindex:error] [pid 971102:tid 971322] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:23.505403 2026] [security2:error] [pid 971102:tid 971322] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxYa-cL08BTTQixEnpbkQAAAFg"]
[Thu Sep 17 15:15:23.534407 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxYa-cL08BTTQixEnpbkgAAAHA"]
[Thu Sep 17 15:15:23.610320 2026] [security2:error] [pid 971102:tid 971361] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxYa-cL08BTTQixEnpblgAAAH8"]
[Thu Sep 17 15:15:23.654261 2026] [security2:error] [pid 971102:tid 971268] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/random_compat/"] [unique_id "aqxYa-cL08BTTQixEnpbmAAAACI"]
[Thu Sep 17 15:15:23.685653 2026] [security2:error] [pid 971102:tid 971360] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxYa-cL08BTTQixEnpbmgAAAH4"]
[Thu Sep 17 15:15:23.761424 2026] [security2:error] [pid 971102:tid 971355] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxYa-cL08BTTQixEnpbmwAAAHk"]
[Thu Sep 17 15:15:23.844542 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxYa-cL08BTTQixEnpbnwAAAFw"]
[Thu Sep 17 15:15:23.924090 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxYa-cL08BTTQixEnpboAAAAAc"]
[Thu Sep 17 15:15:24.017878 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxYbOcL08BTTQixEnpboQAAAAo"]
[Thu Sep 17 15:15:24.092873 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYa-cL08BTTQixEnpbnQAAACo"]
[Thu Sep 17 15:15:24.092896 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYa-cL08BTTQixEnpbnQAAACo"]
[Thu Sep 17 15:15:24.103404 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxYbOcL08BTTQixEnpbpQAAAE4"]
[Thu Sep 17 15:15:24.201347 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxYbOcL08BTTQixEnpbqgAAAFQ"]
[Thu Sep 17 15:15:24.243715 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYbOcL08BTTQixEnpbrgAAAHw"]
[Thu Sep 17 15:15:24.303070 2026] [security2:error] [pid 971102:tid 971334] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxYbOcL08BTTQixEnpbrwAAAGQ"]
[Thu Sep 17 15:15:24.309256 2026] [security2:error] [pid 971102:tid 971331] [client 74.7.244.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.revelinfear.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "aqxYbOcL08BTTQixEnpbsAAAAGE"]
[Thu Sep 17 15:15:24.321238 2026] [security2:error] [pid 971102:tid 971246] [client 74.7.244.33:57572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.revelinfear.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxYbOcL08BTTQixEnpbpgAADDI"]
[Thu Sep 17 15:15:24.393213 2026] [security2:error] [pid 971102:tid 971250] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxYbOcL08BTTQixEnpbtAAAABA"]
[Thu Sep 17 15:15:24.403459 2026] [autoindex:error] [pid 971102:tid 971262] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:24.403967 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYbOcL08BTTQixEnpbswAAABw"]
[Thu Sep 17 15:15:24.486172 2026] [security2:error] [pid 971102:tid 971293] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxYbOcL08BTTQixEnpbtQAAADs"]
[Thu Sep 17 15:15:24.557195 2026] [security2:error] [pid 971102:tid 971337] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYbOcL08BTTQixEnpbtgAAAGc"]
[Thu Sep 17 15:15:24.579220 2026] [security2:error] [pid 971102:tid 971349] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxYbOcL08BTTQixEnpbtwAAAHM"]
[Thu Sep 17 15:15:24.657295 2026] [security2:error] [pid 971102:tid 971343] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxYbOcL08BTTQixEnpbugAAAG0"]
[Thu Sep 17 15:15:24.715376 2026] [autoindex:error] [pid 971102:tid 971253] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:24.715919 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYbOcL08BTTQixEnpbvAAAABM"]
[Thu Sep 17 15:15:24.733390 2026] [security2:error] [pid 971102:tid 971359] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxYbOcL08BTTQixEnpbvQAAAH0"]
[Thu Sep 17 15:15:24.813451 2026] [security2:error] [pid 971102:tid 971330] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxYbOcL08BTTQixEnpbwAAAAGA"]
[Thu Sep 17 15:15:24.839969 2026] [authz_core:error] [pid 971102:tid 971271] [client 172.239.147.162:58545] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:24.864761 2026] [security2:error] [pid 971102:tid 971247] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYbOcL08BTTQixEnpbwQAAAA0"]
[Thu Sep 17 15:15:24.917054 2026] [security2:error] [pid 971102:tid 971239] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxYbOcL08BTTQixEnpbwgAAAAU"]
[Thu Sep 17 15:15:24.991005 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxYbOcL08BTTQixEnpbxQAAADw"]
[Thu Sep 17 15:15:25.016495 2026] [autoindex:error] [pid 971102:tid 971267] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:25.016950 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYbecL08BTTQixEnpbxgAAACE"]
[Thu Sep 17 15:15:25.076682 2026] [security2:error] [pid 971102:tid 971309] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxYbecL08BTTQixEnpbxwAAAEs"]
[Thu Sep 17 15:15:25.196574 2026] [security2:error] [pid 971102:tid 971243] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYbecL08BTTQixEnpbzQAAAAk"]
[Thu Sep 17 15:15:25.254676 2026] [security2:error] [pid 971102:tid 971325] [client 191.179.68.110:2358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYbecL08BTTQixEnpbywAAWzo"]
[Thu Sep 17 15:15:25.350183 2026] [autoindex:error] [pid 971102:tid 971251] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:25.350720 2026] [security2:error] [pid 971102:tid 971251] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYbecL08BTTQixEnpb0QAAABE"]
[Thu Sep 17 15:15:25.370523 2026] [security2:error] [pid 971102:tid 971242] [client 186.105.232.15:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb0gAAAAg"]
[Thu Sep 17 15:15:25.370627 2026] [security2:error] [pid 971102:tid 971242] [client 186.105.232.15:64343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb0gAAAAg"]
[Thu Sep 17 15:15:25.516016 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYbecL08BTTQixEnpb0wAAAH8"]
[Thu Sep 17 15:15:25.527680 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxYbecL08BTTQixEnpbzAAAAEY"]
[Thu Sep 17 15:15:25.540317 2026] [security2:error] [pid 971102:tid 971281] [client 185.55.149.49:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb1AAAAC8"]
[Thu Sep 17 15:15:25.540426 2026] [security2:error] [pid 971102:tid 971281] [client 185.55.149.49:64031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb1AAAAC8"]
[Thu Sep 17 15:15:25.605761 2026] [security2:error] [pid 971102:tid 971305] [client 127.0.0.1:51234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYbecL08BTTQixEnpb1gAAAEc"]
[Thu Sep 17 15:15:25.605793 2026] [security2:error] [pid 971102:tid 971300] [client 74.7.241.190:50212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tth.pdv.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYbecL08BTTQixEnpb1QAAQkQ"]
[Thu Sep 17 15:15:25.634623 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxYbecL08BTTQixEnpb2wAAAHY"]
[Thu Sep 17 15:15:25.702183 2026] [autoindex:error] [pid 971102:tid 971296] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:25.702747 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYbecL08BTTQixEnpb3gAAAD4"]
[Thu Sep 17 15:15:25.711077 2026] [security2:error] [pid 971102:tid 971255] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxYbecL08BTTQixEnpb3wAAABU"]
[Thu Sep 17 15:15:25.800109 2026] [security2:error] [pid 971102:tid 971286] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxYbecL08BTTQixEnpb4QAAADQ"]
[Thu Sep 17 15:15:25.855077 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxYbecL08BTTQixEnpb4gAAABg"]
[Thu Sep 17 15:15:26.010998 2026] [autoindex:error] [pid 971102:tid 971244] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:26.011511 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxYbecL08BTTQixEnpb6QAAAAo"]
[Thu Sep 17 15:15:26.039778 2026] [fcgid:warn] [pid 971102:tid 971312] (70014)End of file found: [client 118.26.105.144:45362] mod_fcgid: can't get data from http client
[Thu Sep 17 15:15:26.114993 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYbecL08BTTQixEnpb5gAAAAc"]
[Thu Sep 17 15:15:26.169478 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYbucL08BTTQixEnpb8AAAACs"]
[Thu Sep 17 15:15:26.360011 2026] [autoindex:error] [pid 971102:tid 971351] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:26.360542 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYbucL08BTTQixEnpb-AAAAHU"]
[Thu Sep 17 15:15:26.503561 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYbucL08BTTQixEnpb_QAAAH0"]
[Thu Sep 17 15:15:26.601471 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYbucL08BTTQixEnpb_AAAAEE"]
[Thu Sep 17 15:15:26.726899 2026] [security2:error] [pid 971102:tid 971275] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxYbucL08BTTQixEnpcBwAAACk"]
[Thu Sep 17 15:15:26.735818 2026] [autoindex:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:26.736355 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYbucL08BTTQixEnpcBQAAADE"]
[Thu Sep 17 15:15:26.758592 2026] [security2:error] [pid 971102:tid 971291] [client 57.141.14.64:25766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYbucL08BTTQixEnpcAQAAOU4"]
[Thu Sep 17 15:15:26.900400 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/images/slider/"] [unique_id "aqxYbucL08BTTQixEnpcCQAAAG8"]
[Thu Sep 17 15:15:27.017137 2026] [security2:error] [pid 971102:tid 971267] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxYb-cL08BTTQixEnpcDAAAACE"]
[Thu Sep 17 15:15:27.062994 2026] [security2:error] [pid 971102:tid 971130] [remote 216.73.217.142:43100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYb-cL08BTTQixEnpcDwAABho"]
[Thu Sep 17 15:15:27.088029 2026] [security2:error] [pid 971102:tid 971273] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxYb-cL08BTTQixEnpcEQAAACc"]
[Thu Sep 17 15:15:27.166979 2026] [security2:error] [pid 971102:tid 971348] [client 5.189.145.112:52195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxYb-cL08BTTQixEnpcFAAAAHI"], referer: binance.com
[Thu Sep 17 15:15:27.169250 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxYb-cL08BTTQixEnpcFQAAAF4"]
[Thu Sep 17 15:15:27.203361 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcDQAAAGg"]
[Thu Sep 17 15:15:27.203386 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcDQAAAGg"]
[Thu Sep 17 15:15:27.244658 2026] [security2:error] [pid 971102:tid 971325] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxYb-cL08BTTQixEnpcFwAAAFs"]
[Thu Sep 17 15:15:27.315862 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxYb-cL08BTTQixEnpcGQAAABQ"]
[Thu Sep 17 15:15:27.355594 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxYb-cL08BTTQixEnpcGgAAAHc"]
[Thu Sep 17 15:15:27.394410 2026] [security2:error] [pid 971102:tid 971313] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxYb-cL08BTTQixEnpcGwAAAE8"]
[Thu Sep 17 15:15:27.500544 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxYb-cL08BTTQixEnpcHwAAAEY"]
[Thu Sep 17 15:15:27.587271 2026] [security2:error] [pid 971102:tid 971305] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxYb-cL08BTTQixEnpcIgAAAEc"]
[Thu Sep 17 15:15:27.651997 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcIAAAAC8"]
[Thu Sep 17 15:15:27.652018 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcIAAAAC8"]
[Thu Sep 17 15:15:27.663772 2026] [security2:error] [pid 971102:tid 971314] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxYb-cL08BTTQixEnpcKQAAAFA"]
[Thu Sep 17 15:15:27.751965 2026] [security2:error] [pid 971102:tid 971360] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxYb-cL08BTTQixEnpcKgAAAH4"]
[Thu Sep 17 15:15:27.824514 2026] [security2:error] [pid 971102:tid 971344] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxYb-cL08BTTQixEnpcKwAAAG4"]
[Thu Sep 17 15:15:27.903535 2026] [security2:error] [pid 971102:tid 971308] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxYb-cL08BTTQixEnpcLAAAAEo"]
[Thu Sep 17 15:15:27.951360 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/sites/default/files/"] [unique_id "aqxYb-cL08BTTQixEnpcLwAAAFM"]
[Thu Sep 17 15:15:27.984529 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxYb-cL08BTTQixEnpcMgAAAE4"]
[Thu Sep 17 15:15:28.070777 2026] [security2:error] [pid 971102:tid 971358] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxYcOcL08BTTQixEnpcNAAAAHw"]
[Thu Sep 17 15:15:28.141037 2026] [security2:error] [pid 971102:tid 971250] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxYcOcL08BTTQixEnpcOQAAABA"]
[Thu Sep 17 15:15:28.235565 2026] [security2:error] [pid 971102:tid 971276] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxYcOcL08BTTQixEnpcPgAAACo"]
[Thu Sep 17 15:15:28.249866 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcNwAAADA"]
[Thu Sep 17 15:15:28.249887 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcNwAAADA"]
[Thu Sep 17 15:15:28.307366 2026] [security2:error] [pid 971102:tid 971237] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcJAAAAAM"]
[Thu Sep 17 15:15:28.334949 2026] [security2:error] [pid 971102:tid 971257] [client 45.169.98.18:52943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcQwAAABc"]
[Thu Sep 17 15:15:28.335065 2026] [security2:error] [pid 971102:tid 971257] [client 45.169.98.18:52943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcQwAAABc"]
[Thu Sep 17 15:15:28.346883 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxYcOcL08BTTQixEnpcRQAAABM"]
[Thu Sep 17 15:15:28.404083 2026] [security2:error] [pid 971102:tid 971330] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxYcOcL08BTTQixEnpcRgAAAGA"]
[Thu Sep 17 15:15:28.425562 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxYcOcL08BTTQixEnpcSQAAAC0"]
[Thu Sep 17 15:15:28.528715 2026] [security2:error] [pid 971102:tid 971247] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxYcOcL08BTTQixEnpcSwAAAA0"]
[Thu Sep 17 15:15:28.601094 2026] [security2:error] [pid 971102:tid 971329] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxYcOcL08BTTQixEnpcTgAAAF8"]
[Thu Sep 17 15:15:28.687550 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxYcOcL08BTTQixEnpcUgAAADw"]
[Thu Sep 17 15:15:28.703206 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcTAAAAFE"]
[Thu Sep 17 15:15:28.703227 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcTAAAAFE"]
[Thu Sep 17 15:15:28.750371 2026] [security2:error] [pid 971102:tid 971262] [client 154.190.208.131:41739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcVAAAABw"]
[Thu Sep 17 15:15:28.754956 2026] [security2:error] [pid 971102:tid 971262] [client 154.190.208.131:41739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcVAAAABw"]
[Thu Sep 17 15:15:28.801215 2026] [security2:error] [pid 971102:tid 971307] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxYcOcL08BTTQixEnpcVQAAAEk"]
[Thu Sep 17 15:15:28.856263 2026] [security2:error] [pid 971102:tid 971273] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxYcOcL08BTTQixEnpcWAAAACc"]
[Thu Sep 17 15:15:28.876843 2026] [security2:error] [pid 971102:tid 971348] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxYcOcL08BTTQixEnpcWgAAAHI"]
[Thu Sep 17 15:15:28.977512 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxYcOcL08BTTQixEnpcWwAAAF4"]
[Thu Sep 17 15:15:29.058250 2026] [security2:error] [pid 971102:tid 971301] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxYcecL08BTTQixEnpcXQAAAEM"]
[Thu Sep 17 15:15:29.130454 2026] [security2:error] [pid 971102:tid 971285] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxYcecL08BTTQixEnpcYQAAADM"]
[Thu Sep 17 15:15:29.172602 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcXAAAAFo"]
[Thu Sep 17 15:15:29.172628 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcXAAAAFo"]
[Thu Sep 17 15:15:29.215844 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxYcecL08BTTQixEnpcYwAAAHc"]
[Thu Sep 17 15:15:29.320645 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxYcecL08BTTQixEnpcZAAAAEY"]
[Thu Sep 17 15:15:29.327791 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/components/"] [unique_id "aqxYcecL08BTTQixEnpcZQAAAEs"]
[Thu Sep 17 15:15:29.397940 2026] [security2:error] [pid 971102:tid 971255] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxYcecL08BTTQixEnpcaAAAABU"]
[Thu Sep 17 15:15:29.491389 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxYcecL08BTTQixEnpcagAAAHY"]
[Thu Sep 17 15:15:29.557139 2026] [security2:error] [pid 971102:tid 971289] [client 114.198.138.124:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcecL08BTTQixEnpcawAAADc"]
[Thu Sep 17 15:15:29.557240 2026] [security2:error] [pid 971102:tid 971289] [client 114.198.138.124:63339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcecL08BTTQixEnpcawAAADc"]
[Thu Sep 17 15:15:29.573631 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxYcecL08BTTQixEnpcbAAAAAE"]
[Thu Sep 17 15:15:29.623179 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpcaQAAAGI"]
[Thu Sep 17 15:15:29.623197 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpcaQAAAGI"]
[Thu Sep 17 15:15:29.666531 2026] [security2:error] [pid 971102:tid 971344] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxYcecL08BTTQixEnpccQAAAG4"]
[Thu Sep 17 15:15:29.734903 2026] [security2:error] [pid 971102:tid 971308] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxYcecL08BTTQixEnpccwAAAEo"]
[Thu Sep 17 15:15:29.782270 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/uploads/images/"] [unique_id "aqxYcecL08BTTQixEnpcdQAAAEU"]
[Thu Sep 17 15:15:29.824892 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxYcecL08BTTQixEnpcdgAAAAo"]
[Thu Sep 17 15:15:29.900079 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxYcecL08BTTQixEnpceAAAAFQ"]
[Thu Sep 17 15:15:29.991998 2026] [security2:error] [pid 971102:tid 971270] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxYcecL08BTTQixEnpcfQAAACQ"]
[Thu Sep 17 15:15:30.073785 2026] [security2:error] [pid 971102:tid 971354] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxYcucL08BTTQixEnpcfwAAAHg"]
[Thu Sep 17 15:15:30.078560 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpceQAAACs"]
[Thu Sep 17 15:15:30.078579 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpceQAAACs"]
[Thu Sep 17 15:15:30.169478 2026] [security2:error] [pid 971102:tid 971319] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxYcucL08BTTQixEnpcgwAAAFU"]
[Thu Sep 17 15:15:30.222762 2026] [security2:error] [pid 971102:tid 971246] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxYcucL08BTTQixEnpchgAAAAw"]
[Thu Sep 17 15:15:30.231035 2026] [security2:error] [pid 971102:tid 971260] [client 172.239.147.162:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-login.php"] [unique_id "aqxYcucL08BTTQixEnpchQAAABo"], referer: binance.com
[Thu Sep 17 15:15:30.258763 2026] [security2:error] [pid 971102:tid 971261] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxYcucL08BTTQixEnpcnAAAABs"]
[Thu Sep 17 15:15:30.348777 2026] [security2:error] [pid 971102:tid 971342] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxYcucL08BTTQixEnpcngAAAGw"]
[Thu Sep 17 15:15:30.424167 2026] [security2:error] [pid 971102:tid 971337] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxYcucL08BTTQixEnpcoAAAAGc"]
[Thu Sep 17 15:15:30.498248 2026] [security2:error] [pid 971102:tid 971257] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxYcucL08BTTQixEnpcoQAAABc"]
[Thu Sep 17 15:15:30.498720 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcnwAAAAM"]
[Thu Sep 17 15:15:30.498746 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcnwAAAAM"]
[Thu Sep 17 15:15:30.595066 2026] [security2:error] [pid 971102:tid 971334] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxYcucL08BTTQixEnpcogAAAGQ"]
[Thu Sep 17 15:15:30.641734 2026] [security2:error] [pid 971102:tid 971326] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/fonts/"] [unique_id "aqxYcucL08BTTQixEnpcpgAAAFw"]
[Thu Sep 17 15:15:30.682786 2026] [security2:error] [pid 971102:tid 971320] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxYcucL08BTTQixEnpcqAAAAFY"]
[Thu Sep 17 15:15:30.766939 2026] [security2:error] [pid 971102:tid 971245] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxYcucL08BTTQixEnpcqQAAAAs"]
[Thu Sep 17 15:15:30.838979 2026] [security2:error] [pid 971102:tid 971356] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxYcucL08BTTQixEnpcqwAAAHo"]
[Thu Sep 17 15:15:30.915531 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcqgAAADE"]
[Thu Sep 17 15:15:30.915557 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcqgAAADE"]
[Thu Sep 17 15:15:30.928356 2026] [security2:error] [pid 971102:tid 971264] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxYcucL08BTTQixEnpcrAAAAB4"]
[Thu Sep 17 15:15:31.029040 2026] [security2:error] [pid 971102:tid 971341] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxYc-cL08BTTQixEnpcrQAAAGs"]
[Thu Sep 17 15:15:31.087149 2026] [security2:error] [pid 971102:tid 971307] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxYc-cL08BTTQixEnpcsQAAAEk"]
[Thu Sep 17 15:15:31.166937 2026] [security2:error] [pid 971102:tid 971274] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxYc-cL08BTTQixEnpctgAAACg"]
[Thu Sep 17 15:15:31.241778 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxYc-cL08BTTQixEnpcuQAAAF4"]
[Thu Sep 17 15:15:31.330784 2026] [security2:error] [pid 971102:tid 971285] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxYc-cL08BTTQixEnpcugAAADM"]
[Thu Sep 17 15:15:31.388516 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpcuAAAAHI"]
[Thu Sep 17 15:15:31.388539 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpcuAAAAHI"]
[Thu Sep 17 15:15:31.425780 2026] [security2:error] [pid 971102:tid 971238] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxYc-cL08BTTQixEnpcvAAAAAQ"]
[Thu Sep 17 15:15:31.497387 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxYc-cL08BTTQixEnpcvwAAAAY"]
[Thu Sep 17 15:15:31.534415 2026] [security2:error] [pid 971102:tid 971304] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxYc-cL08BTTQixEnpcwgAAAEY"]
[Thu Sep 17 15:15:31.596925 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxYc-cL08BTTQixEnpcywAAABQ"]
[Thu Sep 17 15:15:31.676834 2026] [security2:error] [pid 971102:tid 971335] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxYc-cL08BTTQixEnpc0AAAAGU"]
[Thu Sep 17 15:15:31.752419 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxYc-cL08BTTQixEnpc1AAAAHY"]
[Thu Sep 17 15:15:31.815873 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpczwAAAEc"]
[Thu Sep 17 15:15:31.815896 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpczwAAAEc"]
[Thu Sep 17 15:15:31.827577 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxYc-cL08BTTQixEnpc1gAAAAE"]
[Thu Sep 17 15:15:31.913991 2026] [security2:error] [pid 971102:tid 971332] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxYc-cL08BTTQixEnpc2AAAAGI"]
[Thu Sep 17 15:15:31.966724 2026] [security2:error] [pid 971102:tid 971268] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wordpress/"] [unique_id "aqxYc-cL08BTTQixEnpc2QAAACI"]
[Thu Sep 17 15:15:31.988193 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxYc-cL08BTTQixEnpc2wAAAAo"]
[Thu Sep 17 15:15:32.069917 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxYdOcL08BTTQixEnpc3AAAAFQ"]
[Thu Sep 17 15:15:32.074766 2026] [security2:error] [pid 971102:tid 971317] [client 172.239.147.162:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-login.php"] [unique_id "aqxYdOcL08BTTQixEnpc3QAAAFM"], referer: binance.com
[Thu Sep 17 15:15:32.165423 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:52418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxYdOcL08BTTQixEnpc4wAAABg"]
[Thu Sep 17 15:15:32.244625 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdOcL08BTTQixEnpc3gAAAAc"]
[Thu Sep 17 15:15:32.244647 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdOcL08BTTQixEnpc3gAAAAc"]
[Thu Sep 17 15:15:32.395397 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/images/"] [unique_id "aqxYdOcL08BTTQixEnpc6AAAAGY"]
[Thu Sep 17 15:15:32.412273 2026] [security2:error] [pid 971102:tid 971357] [client 34.95.61.66:43686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/info.php"] [unique_id "aqxYdOcL08BTTQixEnpc6QAAAHs"]
[Thu Sep 17 15:15:32.421206 2026] [security2:error] [pid 971102:tid 971339] [client 172.239.147.162:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-login.php"] [unique_id "aqxYdOcL08BTTQixEnpc6gAAAGk"], referer: binance.com
[Thu Sep 17 15:15:32.598183 2026] [autoindex:error] [pid 971102:tid 971287] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:32.598742 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/images/"] [unique_id "aqxYdOcL08BTTQixEnpc7AAAADU"]
[Thu Sep 17 15:15:32.703676 2026] [security2:error] [pid 971102:tid 971343] [client 34.95.61.66:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/php.php"] [unique_id "aqxYdOcL08BTTQixEnpc8gAAAG0"]
[Thu Sep 17 15:15:32.743756 2026] [security2:error] [pid 971102:tid 971320] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYdOcL08BTTQixEnpc8wAAAFY"]
[Thu Sep 17 15:15:32.906961 2026] [security2:error] [pid 971102:tid 971284] [client 74.7.241.145:46600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.popcup.com"] [uri "/robots.txt"] [unique_id "aqxYdOcL08BTTQixEnpc-AAAMlM"]
[Thu Sep 17 15:15:32.907154 2026] [autoindex:error] [pid 971102:tid 971242] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:32.907582 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYdOcL08BTTQixEnpc9wAAAAg"]
[Thu Sep 17 15:15:32.972068 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:43702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/i.php"] [unique_id "aqxYdOcL08BTTQixEnpc-gAAAEE"]
[Thu Sep 17 15:15:32.990893 2026] [security2:error] [pid 971102:tid 971237] [client 156.192.234.52:60929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYdOcL08BTTQixEnpc-wAAAAM"]
[Thu Sep 17 15:15:32.992202 2026] [security2:error] [pid 971102:tid 971237] [client 156.192.234.52:60929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYdOcL08BTTQixEnpc-wAAAAM"]
[Thu Sep 17 15:15:33.056452 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxYdecL08BTTQixEnpdAQAAAFE"]
[Thu Sep 17 15:15:33.210945 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "aqxYdecL08BTTQixEnpdCAAAAFo"]
[Thu Sep 17 15:15:33.229825 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxYdecL08BTTQixEnpdCQAAAF4"]
[Thu Sep 17 15:15:33.356035 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/js/"] [unique_id "aqxYdecL08BTTQixEnpdCwAAAAQ"]
[Thu Sep 17 15:15:33.444370 2026] [core:error] [pid 971102:tid 971300] [client 199.19.226.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:33.444387 2026] [core:error] [pid 971102:tid 971300] [client 199.19.226.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:33.497543 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:43716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxYdecL08BTTQixEnpdFAAAAHA"]
[Thu Sep 17 15:15:33.635010 2026] [security2:error] [pid 971102:tid 971290] [client 66.249.66.76:63652] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.freemarkjordan.com"] [uri "/robots.txt"] [unique_id "aqxYdecL08BTTQixEnpdGgAAADg"]
[Thu Sep 17 15:15:33.643558 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdEwAAAAE"]
[Thu Sep 17 15:15:33.643583 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdEwAAAAE"]
[Thu Sep 17 15:15:33.770440 2026] [security2:error] [pid 971102:tid 971303] [client 34.95.61.66:43724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/test.php"] [unique_id "aqxYdecL08BTTQixEnpdHQAAAEU"]
[Thu Sep 17 15:15:33.787219 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYdecL08BTTQixEnpdHgAAAE4"]
[Thu Sep 17 15:15:34.060099 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdIAAAABg"]
[Thu Sep 17 15:15:34.060121 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdIAAAABg"]
[Thu Sep 17 15:15:34.206283 2026] [security2:error] [pid 971102:tid 971257] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYducL08BTTQixEnpdMgAAABc"]
[Thu Sep 17 15:15:34.244768 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdJAAAAAc"]
[Thu Sep 17 15:15:34.387864 2026] [security2:error] [pid 971102:tid 971260] [client 74.7.244.47:41974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcalendars.saherihbaisha.com"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxYducL08BTTQixEnpdNwAAABo"]
[Thu Sep 17 15:15:34.409185 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:43740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/p.php"] [unique_id "aqxYducL08BTTQixEnpdOAAAAFk"]
[Thu Sep 17 15:15:34.501873 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdNQAAAC4"]
[Thu Sep 17 15:15:34.501899 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdNQAAAC4"]
[Thu Sep 17 15:15:34.646738 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/meta/"] [unique_id "aqxYducL08BTTQixEnpdTgAAAAs"]
[Thu Sep 17 15:15:34.683623 2026] [security2:error] [pid 971102:tid 971324] [client 172.239.147.162:52002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-login.php"] [unique_id "aqxYducL08BTTQixEnpdUQAAAFo"], referer: binance.com
[Thu Sep 17 15:15:34.684348 2026] [security2:error] [pid 971102:tid 971315] [client 34.95.61.66:43748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxYducL08BTTQixEnpdUwAAAFE"]
[Thu Sep 17 15:15:34.926456 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdYQAAAFs"]
[Thu Sep 17 15:15:34.926479 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdYQAAAFs"]
[Thu Sep 17 15:15:34.986292 2026] [security2:error] [pid 971102:tid 971321] [client 34.95.61.66:43754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxYducL08BTTQixEnpdYgAAAFc"]
[Thu Sep 17 15:15:35.074246 2026] [security2:error] [pid 971102:tid 971264] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/network/"] [unique_id "aqxYd-cL08BTTQixEnpdaQAAAB4"]
[Thu Sep 17 15:15:35.242891 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:43768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxYd-cL08BTTQixEnpdbgAAADw"]
[Thu Sep 17 15:15:35.359802 2026] [security2:error] [pid 971102:tid 971251] [client 5.189.145.112:65063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxYd-cL08BTTQixEnpdcAAAABE"], referer: binance.com
[Thu Sep 17 15:15:35.381267 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxYd-cL08BTTQixEnpdbAAAABQ"]
[Thu Sep 17 15:15:35.495133 2026] [core:error] [pid 971102:tid 971346] [client 177.136.231.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:35.495151 2026] [core:error] [pid 971102:tid 971346] [client 177.136.231.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:35.512302 2026] [security2:error] [pid 971102:tid 971282] [client 34.95.61.66:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxYd-cL08BTTQixEnpdegAAADA"]
[Thu Sep 17 15:15:35.522053 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYd-cL08BTTQixEnpdewAAAFA"]
[Thu Sep 17 15:15:35.522127 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYd-cL08BTTQixEnpdewAAAFA"]
[Thu Sep 17 15:15:35.664204 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/user/"] [unique_id "aqxYd-cL08BTTQixEnpdgAAAAE4"]
[Thu Sep 17 15:15:35.804714 2026] [security2:error] [pid 971102:tid 971281] [client 34.95.61.66:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxYd-cL08BTTQixEnpdgQAAAC8"]
[Thu Sep 17 15:15:35.830956 2026] [security2:error] [pid 971102:tid 971307] [client 65.109.83.100:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nickdunne.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdTQAASWM"]
[Thu Sep 17 15:15:35.862447 2026] [security2:error] [pid 971102:tid 971255] [client 112.86.225.42:46448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rocketboxcreative.com"] [uri "/"] [unique_id "aqxYd-cL08BTTQixEnpdgwAAABU"]
[Thu Sep 17 15:15:35.862561 2026] [security2:error] [pid 971102:tid 971255] [client 112.86.225.42:46448] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.rocketboxcreative.com"] [uri "/"] [unique_id "aqxYd-cL08BTTQixEnpdgwAAABU"]
[Thu Sep 17 15:15:36.160797 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYeOcL08BTTQixEnpdmQAAAAc"]
[Thu Sep 17 15:15:36.217659 2026] [security2:error] [pid 971102:tid 971257] [client 185.55.149.49:64692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdnwAAABc"]
[Thu Sep 17 15:15:36.217827 2026] [security2:error] [pid 971102:tid 971257] [client 185.55.149.49:64692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdnwAAABc"]
[Thu Sep 17 15:15:36.254417 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:51750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxYeOcL08BTTQixEnpdlAAAAHU"]
[Thu Sep 17 15:15:36.390746 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeOcL08BTTQixEnpdoQAAACk"]
[Thu Sep 17 15:15:36.390853 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:51750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeOcL08BTTQixEnpdoQAAACk"]
[Thu Sep 17 15:15:36.412146 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxYeOcL08BTTQixEnpdogAAABM"]
[Thu Sep 17 15:15:36.538381 2026] [security2:error] [pid 971102:tid 971331] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/"] [unique_id "aqxYeOcL08BTTQixEnpdpAAAAGE"]
[Thu Sep 17 15:15:36.694712 2026] [security2:error] [pid 971102:tid 971234] [client 186.105.232.15:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdpwAAAAA"]
[Thu Sep 17 15:15:36.697350 2026] [security2:error] [pid 971102:tid 971234] [client 186.105.232.15:64943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdpwAAAAA"]
[Thu Sep 17 15:15:36.943448 2026] [security2:error] [pid 971102:tid 971334] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYeOcL08BTTQixEnpdqwAAAGQ"]
[Thu Sep 17 15:15:36.993909 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env"] [unique_id "aqxYeOcL08BTTQixEnpdsgAAb20"]
[Thu Sep 17 15:15:37.000746 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/index.php"] [unique_id "aqxYeOcL08BTTQixEnpdrgAAAGs"]
[Thu Sep 17 15:15:37.003031 2026] [security2:error] [pid 971102:tid 971146] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.old"] [unique_id "aqxYeOcL08BTTQixEnpdtwAAbyo"]
[Thu Sep 17 15:15:37.005512 2026] [security2:error] [pid 971102:tid 971207] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.backup"] [unique_id "aqxYeOcL08BTTQixEnpduwAAb2Y"]
[Thu Sep 17 15:15:37.005674 2026] [security2:error] [pid 971102:tid 971135] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.bak"] [unique_id "aqxYeOcL08BTTQixEnpdvAAAbx8"]
[Thu Sep 17 15:15:37.037994 2026] [security2:error] [pid 971102:tid 971359] [client 104.28.198.244:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeecL08BTTQixEnpdvwAAAH0"]
[Thu Sep 17 15:15:37.038129 2026] [security2:error] [pid 971102:tid 971359] [client 104.28.198.244:22839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeecL08BTTQixEnpdvwAAAH0"]
[Thu Sep 17 15:15:37.158990 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/"] [unique_id "aqxYeecL08BTTQixEnpdxQAAAFo"]
[Thu Sep 17 15:15:37.186622 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:43834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxYeecL08BTTQixEnpdxgAAAEg"]
[Thu Sep 17 15:15:37.318776 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYeecL08BTTQixEnpd0QAAAHc"]
[Thu Sep 17 15:15:37.364472 2026] [security2:error] [pid 971102:tid 971196] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env~"] [unique_id "aqxYeecL08BTTQixEnpd1gAAW1s"]
[Thu Sep 17 15:15:37.374691 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/.env.php"] [unique_id "aqxYeecL08BTTQixEnpd1AAAW0E"]
[Thu Sep 17 15:15:37.449327 2026] [security2:error] [pid 971102:tid 971321] [client 34.95.61.66:43840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxYeecL08BTTQixEnpd2QAAAFc"]
[Thu Sep 17 15:15:37.463386 2026] [security2:error] [pid 971102:tid 971294] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/"] [unique_id "aqxYeecL08BTTQixEnpd2gAAADw"]
[Thu Sep 17 15:15:37.514913 2026] [security2:error] [pid 971102:tid 971243] [client 112.196.8.34:61472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYeecL08BTTQixEnpd2AAACSg"]
[Thu Sep 17 15:15:37.531398 2026] [security2:error] [pid 971102:tid 971140] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.swp"] [unique_id "aqxYeecL08BTTQixEnpd2wAANiQ"]
[Thu Sep 17 15:15:37.541608 2026] [security2:error] [pid 971102:tid 971200] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/api/.env"] [unique_id "aqxYeecL08BTTQixEnpd4QAAFF8"]
[Thu Sep 17 15:15:37.618493 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/index.php"] [unique_id "aqxYeecL08BTTQixEnpd4gAAAD0"]
[Thu Sep 17 15:15:37.716935 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/backend/.env"] [unique_id "aqxYeecL08BTTQixEnpd6AAAYnk"]
[Thu Sep 17 15:15:37.716945 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/app/.env"] [unique_id "aqxYeecL08BTTQixEnpd5gAAYlM"]
[Thu Sep 17 15:15:37.719445 2026] [security2:error] [pid 971102:tid 971350] [client 34.95.61.66:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxYeecL08BTTQixEnpd6gAAAHQ"]
[Thu Sep 17 15:15:37.724565 2026] [security2:error] [pid 971102:tid 971109] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/server/.env"] [unique_id "aqxYeecL08BTTQixEnpd7AAAMAU"]
[Thu Sep 17 15:15:37.724627 2026] [security2:error] [pid 971102:tid 971138] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/web/.env"] [unique_id "aqxYeecL08BTTQixEnpd7wAAMCI"]
[Thu Sep 17 15:15:37.724678 2026] [security2:error] [pid 971102:tid 971105] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/frontend/.env"] [unique_id "aqxYeecL08BTTQixEnpd8QAAMAE"]
[Thu Sep 17 15:15:37.724730 2026] [security2:error] [pid 971102:tid 971218] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/client/.env"] [unique_id "aqxYeecL08BTTQixEnpd8AAAMHE"]
[Thu Sep 17 15:15:37.724732 2026] [security2:error] [pid 971102:tid 971117] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/config/.env"] [unique_id "aqxYeecL08BTTQixEnpd7QAAMA0"]
[Thu Sep 17 15:15:37.724767 2026] [security2:error] [pid 971102:tid 971150] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/src/.env"] [unique_id "aqxYeecL08BTTQixEnpd7gAAMC4"]
[Thu Sep 17 15:15:37.724885 2026] [security2:error] [pid 971102:tid 971166] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/public/.env"] [unique_id "aqxYeecL08BTTQixEnpd8gAAMD4"]
[Thu Sep 17 15:15:37.728408 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/var/www/.env"] [unique_id "aqxYeecL08BTTQixEnpd8wAAMEI"]
[Thu Sep 17 15:15:37.728456 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/var/www/html/.env"] [unique_id "aqxYeecL08BTTQixEnpd9AAAMDY"]
[Thu Sep 17 15:15:37.764108 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYeecL08BTTQixEnpd9QAAAFA"]
[Thu Sep 17 15:15:37.902977 2026] [security2:error] [pid 971102:tid 971171] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/laravel/.env"] [unique_id "aqxYeecL08BTTQixEnpd-QAAH0M"]
[Thu Sep 17 15:15:37.902995 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/application/.env"] [unique_id "aqxYeecL08BTTQixEnpd-AAAH1w"]
[Thu Sep 17 15:15:37.907452 2026] [security2:error] [pid 971102:tid 971151] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/apps/.env"] [unique_id "aqxYeecL08BTTQixEnpd-gAAeS8"]
[Thu Sep 17 15:15:37.907506 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/back/.env"] [unique_id "aqxYeecL08BTTQixEnpd-wAAeUg"]
[Thu Sep 17 15:15:37.912790 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/backup/.env"] [unique_id "aqxYeecL08BTTQixEnpd_AAAIlE"]
[Thu Sep 17 15:15:37.913137 2026] [security2:error] [pid 971102:tid 971175] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/cms/.env"] [unique_id "aqxYeecL08BTTQixEnpd_QAAIkc"]
[Thu Sep 17 15:15:37.913201 2026] [security2:error] [pid 971102:tid 971156] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/dev/.env"] [unique_id "aqxYeecL08BTTQixEnpd_gAAIjQ"]
[Thu Sep 17 15:15:37.913221 2026] [security2:error] [pid 971102:tid 971139] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/staging/.env"] [unique_id "aqxYeecL08BTTQixEnpeAQAAIiM"]
[Thu Sep 17 15:15:37.913272 2026] [security2:error] [pid 971102:tid 971189] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/production/.env"] [unique_id "aqxYeecL08BTTQixEnpeAAAAIlQ"]
[Thu Sep 17 15:15:37.913282 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/prod/.env"] [unique_id "aqxYeecL08BTTQixEnpd_wAAIks"]
[Thu Sep 17 15:15:37.913326 2026] [security2:error] [pid 971102:tid 971203] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/new/.env"] [unique_id "aqxYeecL08BTTQixEnpeAwAAImI"]
[Thu Sep 17 15:15:37.913358 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/test/.env"] [unique_id "aqxYeecL08BTTQixEnpeAgAAIjk"]
[Thu Sep 17 15:15:37.913358 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/old/.env"] [unique_id "aqxYeecL08BTTQixEnpeBAAAIiY"]
[Thu Sep 17 15:15:37.913895 2026] [security2:error] [pid 971102:tid 971223] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/api-backend/.env"] [unique_id "aqxYeecL08BTTQixEnpeBgAAInY"]
[Thu Sep 17 15:15:37.914008 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/node-api/.env"] [unique_id "aqxYeecL08BTTQixEnpeBQAAIgg"]
[Thu Sep 17 15:15:37.914843 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/admin-app/.env"] [unique_id "aqxYeecL08BTTQixEnpeBwAAIjI"]
[Thu Sep 17 15:15:37.961481 2026] [autoindex:error] [pid 971102:tid 971292] [client 85.204.70.96:51754] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:37.961979 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYeecL08BTTQixEnpeCAAAADo"]
[Thu Sep 17 15:15:37.994793 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxYeecL08BTTQixEnpeCQAAAAo"]
[Thu Sep 17 15:15:38.090831 2026] [security2:error] [pid 971102:tid 971111] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/public_html/.env"] [unique_id "aqxYeucL08BTTQixEnpeDgAASQc"]
[Thu Sep 17 15:15:38.102218 2026] [security2:error] [pid 971102:tid 971143] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/aws/.env"] [unique_id "aqxYeucL08BTTQixEnpeFAAASSc"]
[Thu Sep 17 15:15:38.102269 2026] [security2:error] [pid 971102:tid 971202] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/stripe/.env"] [unique_id "aqxYeucL08BTTQixEnpeFQAASWE"]
[Thu Sep 17 15:15:38.102292 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/server/backend/.env"] [unique_id "aqxYeucL08BTTQixEnpeEQAASWw"]
[Thu Sep 17 15:15:38.102309 2026] [security2:error] [pid 971102:tid 971162] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/server/api/.env"] [unique_id "aqxYeucL08BTTQixEnpeDwAASTo"]
[Thu Sep 17 15:15:38.102315 2026] [security2:error] [pid 971102:tid 971198] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/current/.env"] [unique_id "aqxYeucL08BTTQixEnpeEAAASV0"]
[Thu Sep 17 15:15:38.102347 2026] [security2:error] [pid 971102:tid 971155] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.docker/.env"] [unique_id "aqxYeucL08BTTQixEnpeEgAASTM"]
[Thu Sep 17 15:15:38.102368 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxYeucL08BTTQixEnpeEwAASRU"]
[Thu Sep 17 15:15:38.102424 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.aws/.env"] [unique_id "aqxYeucL08BTTQixEnpeFwAASWk"]
[Thu Sep 17 15:15:38.102434 2026] [security2:error] [pid 971102:tid 971127] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/v2/.env"] [unique_id "aqxYeucL08BTTQixEnpeGgAASRc"]
[Thu Sep 17 15:15:38.102442 2026] [security2:error] [pid 971102:tid 971215] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/v1/.env"] [unique_id "aqxYeucL08BTTQixEnpeGQAASW4"]
[Thu Sep 17 15:15:38.106418 2026] [security2:error] [pid 971102:tid 971177] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/v3/.env"] [unique_id "aqxYeucL08BTTQixEnpeGwAASUk"]
[Thu Sep 17 15:15:38.106516 2026] [security2:error] [pid 971102:tid 971148] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/media/.env"] [unique_id "aqxYeucL08BTTQixEnpeHAAASSw"]
[Thu Sep 17 15:15:38.111651 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/"] [unique_id "aqxYeucL08BTTQixEnpeHQAAAEU"]
[Thu Sep 17 15:15:38.144398 2026] [security2:error] [pid 971102:tid 971229] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/administrator/.env"] [unique_id "aqxYeucL08BTTQixEnpeDQAASXw"]
[Thu Sep 17 15:15:38.238125 2026] [security2:error] [pid 971102:tid 971356] [client 43.165.125.66:36070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeIgAAAHo"]
[Thu Sep 17 15:15:38.251021 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxYeucL08BTTQixEnpeJQAAABg"]
[Thu Sep 17 15:15:38.258594 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeGAAASWo"]
[Thu Sep 17 15:15:38.258768 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeFgAASUQ"]
[Thu Sep 17 15:15:38.285602 2026] [security2:error] [pid 971102:tid 971206] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.git/config.bak"] [unique_id "aqxYeucL08BTTQixEnpeMwAAbWU"]
[Thu Sep 17 15:15:38.419187 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYeucL08BTTQixEnpeJgAAAAc"]
[Thu Sep 17 15:15:38.460674 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeNgAAaRM"]
[Thu Sep 17 15:15:38.473691 2026] [security2:error] [pid 971102:tid 971181] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxYeucL08BTTQixEnpePwAAaU0"]
[Thu Sep 17 15:15:38.477968 2026] [security2:error] [pid 971102:tid 971119] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/id_rsa"] [unique_id "aqxYeucL08BTTQixEnpeRgAAaQ8"]
[Thu Sep 17 15:15:38.477971 2026] [security2:error] [pid 971102:tid 971104] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxYeucL08BTTQixEnpeRAAAaQA"]
[Thu Sep 17 15:15:38.565389 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeucL08BTTQixEnpeSQAAACs"]
[Thu Sep 17 15:15:38.565575 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeucL08BTTQixEnpeSQAAACs"]
[Thu Sep 17 15:15:38.575746 2026] [security2:error] [pid 971102:tid 971246] [client 34.95.61.66:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxYeucL08BTTQixEnpeSgAAAAw"]
[Thu Sep 17 15:15:38.605493 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpePAAAaWc"]
[Thu Sep 17 15:15:38.630807 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeRwAAaXU"]
[Thu Sep 17 15:15:38.633626 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeOgAAaS0"]
[Thu Sep 17 15:15:38.642805 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeQAAAaRs"]
[Thu Sep 17 15:15:38.648325 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeSAAAaQ4"]
[Thu Sep 17 15:15:38.656457 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeQwAAaWA"]
[Thu Sep 17 15:15:38.714283 2026] [security2:error] [pid 971102:tid 971334] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxYeucL08BTTQixEnpeWwAAAGQ"]
[Thu Sep 17 15:15:38.826841 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeucL08BTTQixEnpeYQAAAAg"]
[Thu Sep 17 15:15:38.827355 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:53509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeucL08BTTQixEnpeYQAAAAg"]
[Thu Sep 17 15:15:38.916481 2026] [security2:error] [pid 971102:tid 971269] [client 43.173.173.85:47262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.tab-funkenwerk.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxYeucL08BTTQixEnpeZwAAACM"], referer: https://www.tab-funkenwerk.org/
[Thu Sep 17 15:15:39.062566 2026] [security2:error] [pid 971102:tid 971324] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeaAAAAFo"]
[Thu Sep 17 15:15:39.154241 2026] [autoindex:error] [pid 971102:tid 971353] [client 85.204.70.96:51766] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:39.154918 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:51766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-sys/403.html"] [unique_id "aqxYe-cL08BTTQixEnpeagAAAHc"]
[Thu Sep 17 15:15:39.280576 2026] [security2:error] [pid 971102:tid 971328] [client 114.198.138.124:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebgAAAF4"]
[Thu Sep 17 15:15:39.281843 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeTQAAaRQ"]
[Thu Sep 17 15:15:39.283815 2026] [security2:error] [pid 971102:tid 971328] [client 114.198.138.124:52664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebgAAAF4"]
[Thu Sep 17 15:15:39.284581 2026] [security2:error] [pid 971102:tid 971280] [client 154.190.208.131:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebwAAAC4"]
[Thu Sep 17 15:15:39.284740 2026] [security2:error] [pid 971102:tid 971280] [client 154.190.208.131:42452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebwAAAC4"]
[Thu Sep 17 15:15:39.298201 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeUAAAaUw"]
[Thu Sep 17 15:15:39.314494 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeUQAAaXo"]
[Thu Sep 17 15:15:39.318182 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeUwAAaUo"]
[Thu Sep 17 15:15:39.318492 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeVgAAaRY"]
[Thu Sep 17 15:15:39.326501 2026] [security2:error] [pid 971102:tid 971238] [client 184.82.86.122:42128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYe-cL08BTTQixEnpebQAABFY"]
[Thu Sep 17 15:15:39.347680 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeVwAAaR0"]
[Thu Sep 17 15:15:39.348977 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeVQAAaVk"]
[Thu Sep 17 15:15:39.350050 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeWQAAaRE"]
[Thu Sep 17 15:15:39.352709 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeWAAAaUY"]
[Thu Sep 17 15:15:39.362513 2026] [security2:error] [pid 971102:tid 971284] [client 169.58.197.253:50279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeIQAAADI"], referer: binance.com
[Thu Sep 17 15:15:39.426325 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeYwAAaQw"]
[Thu Sep 17 15:15:39.438313 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeYgAAaQM"]
[Thu Sep 17 15:15:39.438532 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeXgAAaW0"]
[Thu Sep 17 15:15:39.439889 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeXwAAaWY"]
[Thu Sep 17 15:15:39.454667 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeZAAAaSo"]
[Thu Sep 17 15:15:39.478032 2026] [security2:error] [pid 971102:tid 971337] [client 169.58.197.253:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ppfc.net"] [uri "/wp-login.php"] [unique_id "aqxYe-cL08BTTQixEnpedQAAAGc"], referer: binance.com
[Thu Sep 17 15:15:39.532135 2026] [security2:error] [pid 971102:tid 971221] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config.php"] [unique_id "aqxYe-cL08BTTQixEnpeggAAUnQ"]
[Thu Sep 17 15:15:39.579686 2026] [security2:error] [pid 971102:tid 971288] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpedAAAADY"]
[Thu Sep 17 15:15:39.771773 2026] [security2:error] [pid 971102:tid 971355] [client 34.95.61.66:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYe-cL08BTTQixEnpejQAAAHk"]
[Thu Sep 17 15:15:40.038297 2026] [security2:error] [pid 971102:tid 971259] [client 34.95.61.66:52616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnpelgAAABk"]
[Thu Sep 17 15:15:40.299065 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeeAAAUn8"]
[Thu Sep 17 15:15:40.299320 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpedwAAUm8"]
[Thu Sep 17 15:15:40.315612 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeegAAUhg"]
[Thu Sep 17 15:15:40.318591 2026] [security2:error] [pid 971102:tid 971322] [client 34.95.61.66:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnpemwAAAFg"]
[Thu Sep 17 15:15:40.332871 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeewAAUng"]
[Thu Sep 17 15:15:40.340042 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpefQAAUlo"]
[Thu Sep 17 15:15:40.343563 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpefAAAUkU"]
[Thu Sep 17 15:15:40.359196 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpegQAAUls"]
[Thu Sep 17 15:15:40.361185 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpefwAAUj8"]
[Thu Sep 17 15:15:40.370088 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpegAAAUik"]
[Thu Sep 17 15:15:40.389615 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeigAAUjA"]
[Thu Sep 17 15:15:40.391490 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeiQAAUl8"]
[Thu Sep 17 15:15:40.393595 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpehgAAUiQ"]
[Thu Sep 17 15:15:40.483568 2026] [security2:error] [pid 971102:tid 971168] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/aws.php"] [unique_id "aqxYfOcL08BTTQixEnpeowAAJUA"]
[Thu Sep 17 15:15:40.518671 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/stripe.php"] [unique_id "aqxYfOcL08BTTQixEnpepQAAJVw"]
[Thu Sep 17 15:15:40.526144 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/mail.php"] [unique_id "aqxYfOcL08BTTQixEnpepwAAJUg"]
[Thu Sep 17 15:15:40.542486 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/config.inc.php"] [unique_id "aqxYfOcL08BTTQixEnpeqAAAJVE"]
[Thu Sep 17 15:15:40.555147 2026] [security2:error] [pid 971102:tid 971189] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/nexmo.php"] [unique_id "aqxYfOcL08BTTQixEnpeqwAAJVQ"]
[Thu Sep 17 15:15:40.570301 2026] [security2:error] [pid 971102:tid 971270] [client 34.95.61.66:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnperAAAACQ"]
[Thu Sep 17 15:15:40.576732 2026] [security2:error] [pid 971102:tid 971203] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/wp-config.php"] [unique_id "aqxYfOcL08BTTQixEnperwAAJWI"]
[Thu Sep 17 15:15:40.609083 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeogAAJTU"]
[Thu Sep 17 15:15:40.630143 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpepAAAJUM"]
[Thu Sep 17 15:15:40.633682 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYfOcL08BTTQixEnpesAAAJTk"]
[Thu Sep 17 15:15:40.635045 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.old"] [unique_id "aqxYfOcL08BTTQixEnpesQAAJSY"]
[Thu Sep 17 15:15:40.635046 2026] [security2:error] [pid 971102:tid 971223] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.new"] [unique_id "aqxYfOcL08BTTQixEnpesgAAJXY"]
[Thu Sep 17 15:15:40.640406 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYfOcL08BTTQixEnpeswAAJQg"]
[Thu Sep 17 15:15:40.650430 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpepgAAJS8"]
[Thu Sep 17 15:15:40.669441 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeqQAAJUc"]
[Thu Sep 17 15:15:40.700023 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnperQAAJSM"]
[Thu Sep 17 15:15:40.711338 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxYfOcL08BTTQixEnpeuwAAJWw"]
[Thu Sep 17 15:15:40.790592 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpetwAAJQc"]
[Thu Sep 17 15:15:40.818793 2026] [security2:error] [pid 971102:tid 971127] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxYfOcL08BTTQixEnpexQAAJRc"]
[Thu Sep 17 15:15:40.846247 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnpeywAAAC0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:15:40.851025 2026] [deflate:error] [pid 971102:tid 971361] (104)Connection reset by peer: [client 34.23.195.25:46434] AH10298: failed reading from PIPE bucket
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:15:41.087605 2026] [deflate:error] [pid 971102:tid 971242] (104)Connection reset by peer: [client 34.23.195.25:46438] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:15:41.103992 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.61.66:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYfecL08BTTQixEnpe1QAAADU"]
[Thu Sep 17 15:15:41.316502 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpevQAAJV0"]
[Thu Sep 17 15:15:41.333786 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpevgAAJTo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:15:41.334902 2026] [deflate:error] [pid 971102:tid 971245] (104)Connection reset by peer: [client 34.23.195.25:46440] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:15:41.353037 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpewAAAJTM"]
[Thu Sep 17 15:15:41.363020 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpewQAAJRU"]
[Thu Sep 17 15:15:41.373193 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.61.66:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYfecL08BTTQixEnpe3wAAAHc"]
[Thu Sep 17 15:15:41.408821 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpewgAAJWk"]
[Thu Sep 17 15:15:41.412602 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpezwAAJVI"]
[Thu Sep 17 15:15:41.416909 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpexAAAJW4"]
[Thu Sep 17 15:15:41.417919 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpexwAAJSw"]
[Thu Sep 17 15:15:41.418050 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpexgAAJUk"]
[Thu Sep 17 15:15:41.418094 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeyAAAJVc"]
[Thu Sep 17 15:15:41.428441 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeygAAJXI"]
[Thu Sep 17 15:15:41.456179 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpezgAAJWQ"]
[Thu Sep 17 15:15:41.462716 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpezAAAJWo"]
[Thu Sep 17 15:15:41.471637 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe0gAAJU8"]
[Thu Sep 17 15:15:41.650810 2026] [security2:error] [pid 971102:tid 971261] [client 34.95.61.66:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYfecL08BTTQixEnpe-QAAABs"]
[Thu Sep 17 15:15:41.754511 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env"] [unique_id "aqxYfecL08BTTQixEnpe_AAAADA"]
[Thu Sep 17 15:15:41.909218 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYfecL08BTTQixEnpfAQAAAAk"]
[Thu Sep 17 15:15:42.077107 2026] [security2:error] [pid 971102:tid 971222] [remote 216.73.217.142:12689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYfucL08BTTQixEnpfCAAAL3U"]
[Thu Sep 17 15:15:42.186057 2026] [security2:error] [pid 971102:tid 971308] [client 34.95.61.66:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYfucL08BTTQixEnpfEgAAAEo"]
[Thu Sep 17 15:15:42.370973 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe4AAAJTg"]
[Thu Sep 17 15:15:42.380897 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe4gAAJQs"]
[Thu Sep 17 15:15:42.395113 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe5gAAJRI"]
[Thu Sep 17 15:15:42.416088 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe7gAAJU0"]
[Thu Sep 17 15:15:42.419108 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe9wAAJRk"]
[Thu Sep 17 15:15:42.419712 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe6QAAJXM"]
[Thu Sep 17 15:15:42.419982 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe5wAAJWM"]
[Thu Sep 17 15:15:42.420086 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe6gAAJTw"]
[Thu Sep 17 15:15:42.420325 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe7QAAJQA"]
[Thu Sep 17 15:15:42.420462 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe9AAAJQY"]
[Thu Sep 17 15:15:42.423416 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe-AAAJWc"]
[Thu Sep 17 15:15:42.424251 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe6wAAJVg"]
[Thu Sep 17 15:15:42.435139 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe7AAAJRM"]
[Thu Sep 17 15:15:42.435771 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe8gAAJXA"]
[Thu Sep 17 15:15:42.477686 2026] [security2:error] [pid 971102:tid 971331] [client 34.95.61.66:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYfucL08BTTQixEnpfGwAAAGE"]
[Thu Sep 17 15:15:42.810771 2026] [security2:error] [pid 971102:tid 971283] [client 34.95.61.66:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYfucL08BTTQixEnpfMQAAADE"]
[Thu Sep 17 15:15:43.005156 2026] [security2:error] [pid 971102:tid 971121] [remote 45.157.54.43:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYfucL08BTTQixEnpfMwAAZBE"]
[Thu Sep 17 15:15:43.005370 2026] [security2:error] [pid 971102:tid 971334] [client 45.157.54.43:59543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYfucL08BTTQixEnpfMwAAZBE"]
[Thu Sep 17 15:15:43.107603 2026] [security2:error] [pid 971102:tid 971291] [client 34.95.61.66:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfNgAAADk"]
[Thu Sep 17 15:15:43.405604 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfGQAAKRs"]
[Thu Sep 17 15:15:43.405922 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfHgAAKVU"]
[Thu Sep 17 15:15:43.406009 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfKQAAKRQ"]
[Thu Sep 17 15:15:43.406159 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfGgAAKQ4"]
[Thu Sep 17 15:15:43.406270 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfJwAAKXo"]
[Thu Sep 17 15:15:43.406902 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfIgAAKXc"]
[Thu Sep 17 15:15:43.407141 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfKgAAKUw"]
[Thu Sep 17 15:15:43.407576 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfKAAAKUo"]
[Thu Sep 17 15:15:43.433770 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.61.66:52724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfPAAAAHc"]
[Thu Sep 17 15:15:43.447036 2026] [security2:error] [pid 971102:tid 971146] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfQwAAKSo"]
[Thu Sep 17 15:15:43.453742 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfMAAAKVk"]
[Thu Sep 17 15:15:43.571162 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:61522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYf-cL08BTTQixEnpfRwAAAAg"]
[Thu Sep 17 15:15:43.571304 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:61522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYf-cL08BTTQixEnpfRwAAAAg"]
[Thu Sep 17 15:15:43.589485 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/info.php"] [unique_id "aqxYf-cL08BTTQixEnpfSAAAKTc"]
[Thu Sep 17 15:15:43.604857 2026] [security2:error] [pid 971102:tid 971251] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.bak"] [unique_id "aqxYf-cL08BTTQixEnpfSQAAABE"]
[Thu Sep 17 15:15:43.659647 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.backup"] [unique_id "aqxYf-cL08BTTQixEnpfTAAAAEw"]
[Thu Sep 17 15:15:43.706269 2026] [security2:error] [pid 971102:tid 971345] [client 34.95.61.66:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfTgAAAG8"]
[Thu Sep 17 15:15:43.768500 2026] [security2:error] [pid 971102:tid 971136] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/infos.php"] [unique_id "aqxYf-cL08BTTQixEnpfUwAAKSA"]
[Thu Sep 17 15:15:43.768593 2026] [security2:error] [pid 971102:tid 971134] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/php_info.php"] [unique_id "aqxYf-cL08BTTQixEnpfUgAAKR4"]
[Thu Sep 17 15:15:43.770428 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/php-info.php"] [unique_id "aqxYf-cL08BTTQixEnpfVQAAKWs"]
[Thu Sep 17 15:15:43.770454 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/infophp.php"] [unique_id "aqxYf-cL08BTTQixEnpfVgAAKXk"]
[Thu Sep 17 15:15:43.770486 2026] [security2:error] [pid 971102:tid 971138] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfWwAAKSI"]
[Thu Sep 17 15:15:43.770514 2026] [security2:error] [pid 971102:tid 971163] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfVwAAKTs"]
[Thu Sep 17 15:15:43.770523 2026] [security2:error] [pid 971102:tid 971120] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/php.php"] [unique_id "aqxYf-cL08BTTQixEnpfVAAAKRA"]
[Thu Sep 17 15:15:43.770557 2026] [security2:error] [pid 971102:tid 971230] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfWAAAKX0"]
[Thu Sep 17 15:15:43.770568 2026] [security2:error] [pid 971102:tid 971109] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfWQAAKQU"]
[Thu Sep 17 15:15:43.828291 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.old"] [unique_id "aqxYf-cL08BTTQixEnpfXAAAAGI"]
[Thu Sep 17 15:15:43.947993 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfYAAAKUE"]
[Thu Sep 17 15:15:43.984069 2026] [security2:error] [pid 971102:tid 971290] [client 34.95.61.66:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfYQAAADg"]
[Thu Sep 17 15:15:44.129475 2026] [security2:error] [pid 971102:tid 971196] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/database.sql"] [unique_id "aqxYgOcL08BTTQixEnpfcQAAKVs"]
[Thu Sep 17 15:15:44.227343 2026] [security2:error] [pid 971102:tid 971145] [remote 45.157.54.43:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYgOcL08BTTQixEnpfeQAANik"]
[Thu Sep 17 15:15:44.227506 2026] [security2:error] [pid 971102:tid 971288] [client 45.157.54.43:61105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYgOcL08BTTQixEnpfeQAANik"]
[Thu Sep 17 15:15:44.288594 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfPQAAKW0"]
[Thu Sep 17 15:15:44.294219 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfPwAAKQw"]
[Thu Sep 17 15:15:44.294886 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfQAAAKWY"]
[Thu Sep 17 15:15:44.295023 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfPgAAKQM"]
[Thu Sep 17 15:15:44.295678 2026] [security2:error] [pid 971102:tid 971343] [client 34.95.61.66:52742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYgOcL08BTTQixEnpffAAAAG0"]
[Thu Sep 17 15:15:44.298090 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfQQAAKSU"]
[Thu Sep 17 15:15:44.301072 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfQgAAKXQ"]
[Thu Sep 17 15:15:44.410293 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfWgAAKVM"]
[Thu Sep 17 15:15:44.410415 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfawAAKW8"]
[Thu Sep 17 15:15:44.413060 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfbQAAKV4"]
[Thu Sep 17 15:15:44.413138 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfagAAKX8"]
[Thu Sep 17 15:15:44.413234 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfcAAAKVo"]
[Thu Sep 17 15:15:44.422831 2026] [security2:error] [pid 971102:tid 971316] [client 209.141.32.143:50890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gridmodita.com"] [uri "/wp-content/plugins/jetformbuilder/readme.txt"] [unique_id "aqxYgOcL08BTTQixEnpfgwAAAFI"]
[Thu Sep 17 15:15:44.427020 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfbgAAKRg"]
[Thu Sep 17 15:15:44.431026 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfcgAAKUU"]
[Thu Sep 17 15:15:44.444425 2026] [security2:error] [pid 971102:tid 971105] [remote 47.128.23.119:40140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joeledmundanderson.com"] [uri "/robots.txt"] [unique_id "aqxYgOcL08BTTQixEnpfhgAADAE"]
[Thu Sep 17 15:15:44.554760 2026] [security2:error] [pid 971102:tid 971256] [client 34.95.61.66:52756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYgOcL08BTTQixEnpfkgAAABY"]
[Thu Sep 17 15:15:44.595182 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/lib/.env"] [unique_id "aqxYgOcL08BTTQixEnpfmQAAf0s"]
[Thu Sep 17 15:15:44.607417 2026] [security2:error] [pid 971102:tid 971157] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.txt"] [unique_id "aqxYgOcL08BTTQixEnpfmwAAfzU"]
[Thu Sep 17 15:15:44.611266 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/ses/.env"] [unique_id "aqxYgOcL08BTTQixEnpfnQAAfzk"]
[Thu Sep 17 15:15:44.832220 2026] [security2:error] [pid 971102:tid 971320] [client 34.95.61.66:52762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYgOcL08BTTQixEnpfrAAAAFY"]
[Thu Sep 17 15:15:45.184896 2026] [security2:error] [pid 971102:tid 971339] [client 34.95.61.66:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYgecL08BTTQixEnpfsgAAAGk"]
[Thu Sep 17 15:15:45.278998 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfigAAf0I"]
[Thu Sep 17 15:15:45.280070 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfjAAAfz4"]
[Thu Sep 17 15:15:45.287292 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfiwAAfzY"]
[Thu Sep 17 15:15:45.287513 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfiQAAfy4"]
[Thu Sep 17 15:15:45.291287 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfjQAAf0A"]
[Thu Sep 17 15:15:45.307947 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfjgAAfw0"]
[Thu Sep 17 15:15:45.391501 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfmAAAfzQ"]
[Thu Sep 17 15:15:45.391743 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfmgAAf2I"]
[Thu Sep 17 15:15:45.392157 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfnwAAf3Y"]
[Thu Sep 17 15:15:45.392280 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfnAAAf0M"]
[Thu Sep 17 15:15:45.400858 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfpwAAfy8"]
[Thu Sep 17 15:15:45.442857 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.git/config~"] [unique_id "aqxYgecL08BTTQixEnpfugAACWw"]
[Thu Sep 17 15:15:45.449506 2026] [security2:error] [pid 971102:tid 971305] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.swp"] [unique_id "aqxYgecL08BTTQixEnpfvgAAAEc"]
[Thu Sep 17 15:15:45.507426 2026] [security2:error] [pid 971102:tid 971360] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env~"] [unique_id "aqxYgecL08BTTQixEnpfxQAAAH4"]
[Thu Sep 17 15:15:45.571418 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/sites/default/settings.php.swp"] [unique_id "aqxYgecL08BTTQixEnpfywAACWk"]
[Thu Sep 17 15:15:45.572356 2026] [security2:error] [pid 971102:tid 971209] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/yii/.env"] [unique_id "aqxYgecL08BTTQixEnpfygAACWg"]
[Thu Sep 17 15:15:45.572564 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/www.bak"] [unique_id "aqxYgecL08BTTQixEnpfyQAACRU"]
[Thu Sep 17 15:15:45.589207 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfuwAACQc"]
[Thu Sep 17 15:15:45.594861 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfvQAACRc"]
[Thu Sep 17 15:15:45.598528 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfuQAACWE"]
[Thu Sep 17 15:15:45.603023 2026] [security2:error] [pid 971102:tid 971292] [client 34.95.61.66:52778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYgecL08BTTQixEnpfzwAAADo"]
[Thu Sep 17 15:15:45.610283 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfwQAACUQ"]
[Thu Sep 17 15:15:45.612840 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfvwAACQQ"]
[Thu Sep 17 15:15:45.613281 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfwAAACXw"]
[Thu Sep 17 15:15:45.618906 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfwwAACU4"]
[Thu Sep 17 15:15:45.631773 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfxAAACTo"]
[Thu Sep 17 15:15:45.926451 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:52794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYgecL08BTTQixEnpf3AAAABM"]
[Thu Sep 17 15:15:45.935219 2026] [security2:error] [pid 971102:tid 971315] [client 5.189.145.112:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxYgecL08BTTQixEnpf3QAAAFE"], referer: binance.com
[Thu Sep 17 15:15:46.228161 2026] [security2:error] [pid 971102:tid 971257] [client 34.95.61.66:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYgucL08BTTQixEnpf7QAAABc"]
[Thu Sep 17 15:15:46.345988 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfzAAACVI"]
[Thu Sep 17 15:15:46.352405 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfzQAACW4"]
[Thu Sep 17 15:15:46.368468 2026] [security2:error] [pid 971102:tid 971353] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/app/.env"] [unique_id "aqxYgucL08BTTQixEnpf8QAAAHc"]
[Thu Sep 17 15:15:46.404876 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpf0AAACSw"]
[Thu Sep 17 15:15:46.434795 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/apps/.env"] [unique_id "aqxYgucL08BTTQixEnpf8wAAAFo"]
[Thu Sep 17 15:15:46.499650 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/.env"] [unique_id "aqxYgucL08BTTQixEnpf9AAAAAs"]
[Thu Sep 17 15:15:46.529803 2026] [security2:error] [pid 971102:tid 971283] [client 34.95.61.66:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYgucL08BTTQixEnpf9wAAADE"]
[Thu Sep 17 15:15:46.582346 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/web/.env"] [unique_id "aqxYgucL08BTTQixEnpf-AAAACg"]
[Thu Sep 17 15:15:46.644933 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/site/.env"] [unique_id "aqxYgucL08BTTQixEnpf-wAAAG8"]
[Thu Sep 17 15:15:46.708578 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/public/.env"] [unique_id "aqxYgucL08BTTQixEnpf_QAAACs"]
[Thu Sep 17 15:15:46.824345 2026] [security2:error] [pid 971102:tid 971261] [client 34.95.61.66:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYgucL08BTTQixEnpgAgAAABs"]
[Thu Sep 17 15:15:46.895303 2026] [security2:error] [pid 971102:tid 971348] [client 185.55.149.49:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYgucL08BTTQixEnpgBAAAAHI"]
[Thu Sep 17 15:15:46.896752 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/backend/.env"] [unique_id "aqxYgucL08BTTQixEnpgAwAAAD4"]
[Thu Sep 17 15:15:46.900983 2026] [security2:error] [pid 971102:tid 971348] [client 185.55.149.49:65398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYgucL08BTTQixEnpgBAAAAHI"]
[Thu Sep 17 15:15:46.905140 2026] [security2:error] [pid 971102:tid 971284] [client 60.243.209.155:49584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYgucL08BTTQixEnpgAAAAMmQ"]
[Thu Sep 17 15:15:46.954522 2026] [security2:error] [pid 971102:tid 971349] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/server/.env"] [unique_id "aqxYgucL08BTTQixEnpgBQAAAHM"]
[Thu Sep 17 15:15:47.012276 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/frontend/.env"] [unique_id "aqxYg-cL08BTTQixEnpgBgAAABQ"]
[Thu Sep 17 15:15:47.077426 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/src/.env"] [unique_id "aqxYg-cL08BTTQixEnpgCQAAAFg"]
[Thu Sep 17 15:15:47.133462 2026] [security2:error] [pid 971102:tid 971360] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/core/.env"] [unique_id "aqxYg-cL08BTTQixEnpgDQAAAH4"]
[Thu Sep 17 15:15:47.193721 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/core/app/.env"] [unique_id "aqxYg-cL08BTTQixEnpgEgAAAFU"]
[Thu Sep 17 15:15:47.249588 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/config/.env"] [unique_id "aqxYg-cL08BTTQixEnpgFAAAAHE"]
[Thu Sep 17 15:15:47.311168 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/private/.env"] [unique_id "aqxYg-cL08BTTQixEnpgFgAAAGU"]
[Thu Sep 17 15:15:47.369225 2026] [security2:error] [pid 971102:tid 971294] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/application/.env"] [unique_id "aqxYg-cL08BTTQixEnpgGQAAADw"]
[Thu Sep 17 15:15:47.434414 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/bootstrap/.env"] [unique_id "aqxYg-cL08BTTQixEnpgHQAAAB8"]
[Thu Sep 17 15:15:47.494100 2026] [security2:error] [pid 971102:tid 971352] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/database/.env"] [unique_id "aqxYg-cL08BTTQixEnpgIQAAAHY"]
[Thu Sep 17 15:15:47.554767 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/storage/.env"] [unique_id "aqxYg-cL08BTTQixEnpgJAAAAE4"]
[Thu Sep 17 15:15:47.564453 2026] [security2:error] [pid 971102:tid 971328] [client 169.58.197.253:50944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxYg-cL08BTTQixEnpgHwAAAF4"], referer: binance.com
[Thu Sep 17 15:15:47.610562 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/var/www/.env"] [unique_id "aqxYg-cL08BTTQixEnpgJwAAAFI"]
[Thu Sep 17 15:15:47.674821 2026] [security2:error] [pid 971102:tid 971293] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/var/www/html/.env"] [unique_id "aqxYg-cL08BTTQixEnpgLgAAADs"]
[Thu Sep 17 15:15:47.733394 2026] [security2:error] [pid 971102:tid 971252] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/current/.env"] [unique_id "aqxYg-cL08BTTQixEnpgMQAAABI"]
[Thu Sep 17 15:15:47.774945 2026] [security2:error] [pid 971102:tid 971270] [client 186.105.232.15:65534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYg-cL08BTTQixEnpgMwAAACQ"]
[Thu Sep 17 15:15:47.777512 2026] [security2:error] [pid 971102:tid 971270] [client 186.105.232.15:65534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYg-cL08BTTQixEnpgMwAAACQ"]
[Thu Sep 17 15:15:47.788153 2026] [security2:error] [pid 971102:tid 971346] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/release/.env"] [unique_id "aqxYg-cL08BTTQixEnpgNAAAAHA"]
[Thu Sep 17 15:15:47.844839 2026] [security2:error] [pid 971102:tid 971304] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/releases/.env"] [unique_id "aqxYg-cL08BTTQixEnpgNQAAAEY"]
[Thu Sep 17 15:15:47.902397 2026] [security2:error] [pid 971102:tid 971325] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/shared/.env"] [unique_id "aqxYg-cL08BTTQixEnpgNwAAAFs"]
[Thu Sep 17 15:15:47.959624 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/deploy/.env"] [unique_id "aqxYg-cL08BTTQixEnpgOQAAAG4"]
[Thu Sep 17 15:15:48.013668 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/build/.env"] [unique_id "aqxYhOcL08BTTQixEnpgOwAAAEw"]
[Thu Sep 17 15:15:48.068900 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/dist/.env"] [unique_id "aqxYhOcL08BTTQixEnpgPQAAAEE"]
[Thu Sep 17 15:15:48.123008 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/public_html/.env"] [unique_id "aqxYhOcL08BTTQixEnpgPwAAAFY"]
[Thu Sep 17 15:15:48.177922 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/htdocs/.env"] [unique_id "aqxYhOcL08BTTQixEnpgQgAAAEI"]
[Thu Sep 17 15:15:48.232988 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/www/.env"] [unique_id "aqxYhOcL08BTTQixEnpgRQAAADE"]
[Thu Sep 17 15:15:48.251305 2026] [security2:error] [pid 971102:tid 971160] [remote 45.157.54.43:63797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhOcL08BTTQixEnpgRgAAZzg"]
[Thu Sep 17 15:15:48.251471 2026] [security2:error] [pid 971102:tid 971337] [client 45.157.54.43:63797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhOcL08BTTQixEnpgRgAAZzg"]
[Thu Sep 17 15:15:48.287030 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/html/.env"] [unique_id "aqxYhOcL08BTTQixEnpgRwAAAGo"]
[Thu Sep 17 15:15:48.341074 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/live/.env"] [unique_id "aqxYhOcL08BTTQixEnpgSQAAAC4"]
[Thu Sep 17 15:15:48.397032 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/prod/.env"] [unique_id "aqxYhOcL08BTTQixEnpgSwAAAB4"]
[Thu Sep 17 15:15:48.457008 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/dev/.env"] [unique_id "aqxYhOcL08BTTQixEnpgTAAAAGk"]
[Thu Sep 17 15:15:48.511570 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/staging/.env"] [unique_id "aqxYhOcL08BTTQixEnpgTQAAAEg"]
[Thu Sep 17 15:15:48.580237 2026] [security2:error] [pid 971102:tid 971242] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/opt/.env"] [unique_id "aqxYhOcL08BTTQixEnpgTgAAAAg"]
[Thu Sep 17 15:15:48.639724 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/laravel/.env"] [unique_id "aqxYhOcL08BTTQixEnpgUQAAAD4"]
[Thu Sep 17 15:15:48.701332 2026] [security2:error] [pid 971102:tid 971361] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/symfony/.env"] [unique_id "aqxYhOcL08BTTQixEnpgVgAAAH8"]
[Thu Sep 17 15:15:48.765099 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/wordpress/.env"] [unique_id "aqxYhOcL08BTTQixEnpgWQAAAAY"]
[Thu Sep 17 15:15:48.819833 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/wp/.env"] [unique_id "aqxYhOcL08BTTQixEnpgWgAAAFA"]
[Thu Sep 17 15:15:48.874971 2026] [security2:error] [pid 971102:tid 971286] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cms/.env"] [unique_id "aqxYhOcL08BTTQixEnpgWwAAADQ"]
[Thu Sep 17 15:15:48.933371 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/drupal/.env"] [unique_id "aqxYhOcL08BTTQixEnpgXQAAAHE"]
[Thu Sep 17 15:15:49.108396 2026] [security2:error] [pid 971102:tid 971327] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/joomla/.env"] [unique_id "aqxYhecL08BTTQixEnpgYAAAAF0"]
[Thu Sep 17 15:15:49.166073 2026] [security2:error] [pid 971102:tid 971352] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/magento/.env"] [unique_id "aqxYhecL08BTTQixEnpgZAAAAHY"]
[Thu Sep 17 15:15:49.227372 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/shopify/.env"] [unique_id "aqxYhecL08BTTQixEnpgZQAAAE4"]
[Thu Sep 17 15:15:49.282803 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/prestashop/.env"] [unique_id "aqxYhecL08BTTQixEnpgZwAAAF4"]
[Thu Sep 17 15:15:49.311177 2026] [security2:error] [pid 971102:tid 971281] [client 45.169.98.18:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgaAAAAC8"]
[Thu Sep 17 15:15:49.311269 2026] [security2:error] [pid 971102:tid 971281] [client 45.169.98.18:54066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgaAAAAC8"]
[Thu Sep 17 15:15:49.340905 2026] [security2:error] [pid 971102:tid 971247] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/codeigniter/.env"] [unique_id "aqxYhecL08BTTQixEnpgaQAAAA0"]
[Thu Sep 17 15:15:49.396465 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cakephp/.env"] [unique_id "aqxYhecL08BTTQixEnpgagAAAFM"]
[Thu Sep 17 15:15:49.451325 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/zend/.env"] [unique_id "aqxYhecL08BTTQixEnpgawAAAEo"]
[Thu Sep 17 15:15:49.511531 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/yii/.env"] [unique_id "aqxYhecL08BTTQixEnpgbgAAADk"]
[Thu Sep 17 15:15:49.567607 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/laravel5/.env"] [unique_id "aqxYhecL08BTTQixEnpgcQAAADU"]
[Thu Sep 17 15:15:49.586434 2026] [security2:error] [pid 971102:tid 971269] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "radtechresourcesgroup.com"] [uri "/index.php"] [unique_id "aqxYgucL08BTTQixEnpf7gAAACM"]
[Thu Sep 17 15:15:49.622587 2026] [security2:error] [pid 971102:tid 971356] [client 186.209.201.184:12023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYhecL08BTTQixEnpgbQAAenM"]
[Thu Sep 17 15:15:49.627386 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/v1/.env"] [unique_id "aqxYhecL08BTTQixEnpgcgAAACQ"]
[Thu Sep 17 15:15:49.696115 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/v2/.env"] [unique_id "aqxYhecL08BTTQixEnpgdgAAACk"]
[Thu Sep 17 15:15:49.754704 2026] [security2:error] [pid 971102:tid 971343] [client 154.190.208.131:41734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgeAAAAG0"]
[Thu Sep 17 15:15:49.754872 2026] [security2:error] [pid 971102:tid 971343] [client 154.190.208.131:41734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgeAAAAG0"]
[Thu Sep 17 15:15:49.761458 2026] [security2:error] [pid 971102:tid 971272] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/v3/.env"] [unique_id "aqxYhecL08BTTQixEnpgeQAAACY"]
[Thu Sep 17 15:15:49.823855 2026] [security2:error] [pid 971102:tid 971325] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/v1/.env"] [unique_id "aqxYhecL08BTTQixEnpgewAAAFs"]
[Thu Sep 17 15:15:49.887869 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/v2/.env"] [unique_id "aqxYhecL08BTTQixEnpgfQAAAHg"]
[Thu Sep 17 15:15:49.889463 2026] [security2:error] [pid 971102:tid 971273] [client 114.198.138.124:53302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgfAAAACc"]
[Thu Sep 17 15:15:49.889561 2026] [security2:error] [pid 971102:tid 971273] [client 114.198.138.124:53302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgfAAAACc"]
[Thu Sep 17 15:15:49.946495 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/rest/.env"] [unique_id "aqxYhecL08BTTQixEnpgfwAAAFw"]
[Thu Sep 17 15:15:50.013234 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/graphql/.env"] [unique_id "aqxYhucL08BTTQixEnpgggAAAEI"]
[Thu Sep 17 15:15:50.077399 2026] [security2:error] [pid 971102:tid 971301] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/gateway/.env"] [unique_id "aqxYhucL08BTTQixEnpggwAAAEM"]
[Thu Sep 17 15:15:50.142424 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/microservice/.env"] [unique_id "aqxYhucL08BTTQixEnpghgAAAG8"]
[Thu Sep 17 15:15:50.208244 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/service/.env"] [unique_id "aqxYhucL08BTTQixEnpgiwAAADY"]
[Thu Sep 17 15:15:50.269938 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/v3/.env"] [unique_id "aqxYhucL08BTTQixEnpgjAAAAEk"]
[Thu Sep 17 15:15:50.333452 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/dev/.env"] [unique_id "aqxYhucL08BTTQixEnpgkQAAAHQ"]
[Thu Sep 17 15:15:50.392365 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/staging/.env"] [unique_id "aqxYhucL08BTTQixEnpglAAAAAE"]
[Thu Sep 17 15:15:50.457830 2026] [security2:error] [pid 971102:tid 971242] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/vendor/.env"] [unique_id "aqxYhucL08BTTQixEnpglwAAAAg"]
[Thu Sep 17 15:15:50.524085 2026] [security2:error] [pid 971102:tid 971361] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/lib/.env"] [unique_id "aqxYhucL08BTTQixEnpgmgAAAH8"]
[Thu Sep 17 15:15:50.583320 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/resources/.env"] [unique_id "aqxYhucL08BTTQixEnpgnAAAAA8"]
[Thu Sep 17 15:15:50.637650 2026] [security2:error] [pid 971102:tid 971259] [client 5.189.145.112:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxYhucL08BTTQixEnpgnwAAABk"], referer: binance.com
[Thu Sep 17 15:15:50.640469 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/assets/.env"] [unique_id "aqxYhucL08BTTQixEnpgoAAAAD0"]
[Thu Sep 17 15:15:50.697481 2026] [security2:error] [pid 971102:tid 971292] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/uploads/.env"] [unique_id "aqxYhucL08BTTQixEnpgowAAADo"]
[Thu Sep 17 15:15:50.764281 2026] [security2:error] [pid 971102:tid 971355] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/internal/.env"] [unique_id "aqxYhucL08BTTQixEnpgpgAAAHk"]
[Thu Sep 17 15:15:50.778581 2026] [security2:error] [pid 971102:tid 971244] [client 45.115.26.203:56124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/ta/index.php"] [unique_id "aqxYhucL08BTTQixEnpgqQAAAAo"]
[Thu Sep 17 15:15:50.824184 2026] [security2:error] [pid 971102:tid 971357] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/tools/.env"] [unique_id "aqxYhucL08BTTQixEnpgrQAAAHs"]
[Thu Sep 17 15:15:50.881738 2026] [security2:error] [pid 971102:tid 971309] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/scripts/.env"] [unique_id "aqxYhucL08BTTQixEnpgrgAAAEs"]
[Thu Sep 17 15:15:50.938929 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/bin/.env"] [unique_id "aqxYhucL08BTTQixEnpgrwAAAF4"]
[Thu Sep 17 15:15:50.994450 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sbin/.env"] [unique_id "aqxYhucL08BTTQixEnpgsgAAAE8"]
[Thu Sep 17 15:15:51.053602 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/local/.env"] [unique_id "aqxYh-cL08BTTQixEnpgtAAAAFM"]
[Thu Sep 17 15:15:51.059455 2026] [security2:error] [pid 971102:tid 971304] [client 103.131.71.44:53455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "airmacinc.com"] [uri "/index.php"] [unique_id "aqxYhecL08BTTQixEnpggQAAAEY"]
[Thu Sep 17 15:15:51.115544 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/portal/.env"] [unique_id "aqxYh-cL08BTTQixEnpgtQAAACA"]
[Thu Sep 17 15:15:51.175091 2026] [security2:error] [pid 971102:tid 971331] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/dashboard/.env"] [unique_id "aqxYh-cL08BTTQixEnpgugAAAGE"]
[Thu Sep 17 15:15:51.233919 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpguwAAADU"]
[Thu Sep 17 15:15:51.301929 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/crm/.env"] [unique_id "aqxYh-cL08BTTQixEnpgvQAAAAA"]
[Thu Sep 17 15:15:51.323486 2026] [cgid:error] [pid 971102:tid 971121] [remote 82.90.231.111:50634] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:15:51.362741 2026] [security2:error] [pid 971102:tid 971356] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/erp/.env"] [unique_id "aqxYh-cL08BTTQixEnpgvwAAAHo"]
[Thu Sep 17 15:15:51.418446 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/shop/.env"] [unique_id "aqxYh-cL08BTTQixEnpgwQAAACk"]
[Thu Sep 17 15:15:51.479796 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/store/.env"] [unique_id "aqxYh-cL08BTTQixEnpgwgAAAH0"]
[Thu Sep 17 15:15:51.535953 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/saas/.env"] [unique_id "aqxYh-cL08BTTQixEnpgwwAAAHg"]
[Thu Sep 17 15:15:51.595394 2026] [security2:error] [pid 971102:tid 971255] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/client/.env"] [unique_id "aqxYh-cL08BTTQixEnpgxAAAABU"]
[Thu Sep 17 15:15:51.649795 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/project/.env"] [unique_id "aqxYh-cL08BTTQixEnpgyAAAAG4"]
[Thu Sep 17 15:15:51.704281 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/admin-panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpgygAAAFw"]
[Thu Sep 17 15:15:51.762421 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/control-panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpgzQAAADY"]
[Thu Sep 17 15:15:51.825869 2026] [security2:error] [pid 971102:tid 971302] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/user-panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpgzgAAAEQ"]
[Thu Sep 17 15:15:51.883524 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/node/.env"] [unique_id "aqxYh-cL08BTTQixEnpg0QAAAFY"]
[Thu Sep 17 15:15:51.942111 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/express/.env"] [unique_id "aqxYh-cL08BTTQixEnpg0gAAAAE"]
[Thu Sep 17 15:15:52.003141 2026] [security2:error] [pid 971102:tid 971238] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/next/.env"] [unique_id "aqxYiOcL08BTTQixEnpg0wAAAAQ"]
[Thu Sep 17 15:15:52.061599 2026] [security2:error] [pid 971102:tid 971243] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/nuxt/.env"] [unique_id "aqxYiOcL08BTTQixEnpg1QAAAAk"]
[Thu Sep 17 15:15:52.075254 2026] [security2:error] [pid 971102:tid 971106] [remote 216.73.217.142:19084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYiOcL08BTTQixEnpg1gAABgI"]
[Thu Sep 17 15:15:52.093450 2026] [security2:error] [pid 971102:tid 971137] [remote 45.157.54.43:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiOcL08BTTQixEnpg2QAAYCE"]
[Thu Sep 17 15:15:52.093558 2026] [security2:error] [pid 971102:tid 971330] [client 45.157.54.43:11840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiOcL08BTTQixEnpg2QAAYCE"]
[Thu Sep 17 15:15:52.121157 2026] [security2:error] [pid 971102:tid 971261] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/nest/.env"] [unique_id "aqxYiOcL08BTTQixEnpg2gAAABs"]
[Thu Sep 17 15:15:52.186067 2026] [security2:error] [pid 971102:tid 971348] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/react/.env"] [unique_id "aqxYiOcL08BTTQixEnpg4QAAAHI"]
[Thu Sep 17 15:15:52.243968 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/vue/.env"] [unique_id "aqxYiOcL08BTTQixEnpg4gAAACs"]
[Thu Sep 17 15:15:52.300195 2026] [security2:error] [pid 971102:tid 971267] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/angular/.env"] [unique_id "aqxYiOcL08BTTQixEnpg4wAAACE"]
[Thu Sep 17 15:15:52.356501 2026] [security2:error] [pid 971102:tid 971250] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/svelte/.env"] [unique_id "aqxYiOcL08BTTQixEnpg5wAAABA"]
[Thu Sep 17 15:15:52.417771 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/vite/.env"] [unique_id "aqxYiOcL08BTTQixEnpg6AAAABQ"]
[Thu Sep 17 15:15:52.448020 2026] [security2:error] [pid 971102:tid 971339] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxYiOcL08BTTQixEnpg5gAAAGk"]
[Thu Sep 17 15:15:52.473643 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/backup/.env"] [unique_id "aqxYiOcL08BTTQixEnpg6QAAAEU"]
[Thu Sep 17 15:15:52.529365 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/backups/.env"] [unique_id "aqxYiOcL08BTTQixEnpg6gAAABM"]
[Thu Sep 17 15:15:52.564510 2026] [security2:error] [pid 971102:tid 971360] [client 212.28.179.189:34514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cpanel-box5305.bluehost.com"] [uri "/___proxy_subdomain_webmail/.azure/.env"] [unique_id "aqxYiOcL08BTTQixEnpg7gAAAH4"]
[Thu Sep 17 15:15:52.587460 2026] [security2:error] [pid 971102:tid 971352] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/old/.env"] [unique_id "aqxYiOcL08BTTQixEnpg8QAAAHY"]
[Thu Sep 17 15:15:52.646785 2026] [security2:error] [pid 971102:tid 971281] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/tmp/.env"] [unique_id "aqxYiOcL08BTTQixEnpg9AAAAC8"]
[Thu Sep 17 15:15:52.708404 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/temp/.env"] [unique_id "aqxYiOcL08BTTQixEnpg-QAAADM"]
[Thu Sep 17 15:15:52.768631 2026] [security2:error] [pid 971102:tid 971304] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/lab/.env"] [unique_id "aqxYiOcL08BTTQixEnpg-gAAAEY"]
[Thu Sep 17 15:15:52.824982 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cronlab/.env"] [unique_id "aqxYiOcL08BTTQixEnpg-wAAABc"]
[Thu Sep 17 15:15:52.890879 2026] [security2:error] [pid 971102:tid 971258] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cron/.env"] [unique_id "aqxYiOcL08BTTQixEnpg_AAAABg"]
[Thu Sep 17 15:15:52.953367 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/en/.env"] [unique_id "aqxYiOcL08BTTQixEnpg_gAAAAA"]
[Thu Sep 17 15:15:53.066979 2026] [security2:error] [pid 971102:tid 971246] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/administrator/.env"] [unique_id "aqxYiecL08BTTQixEnpg_wAAAAw"]
[Thu Sep 17 15:15:53.126731 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/psnlink/.env"] [unique_id "aqxYiecL08BTTQixEnphBAAAACk"]
[Thu Sep 17 15:15:53.185688 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/exapi/.env"] [unique_id "aqxYiecL08BTTQixEnphBgAAAGQ"]
[Thu Sep 17 15:15:53.241922 2026] [security2:error] [pid 971102:tid 971343] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sitemaps/.env"] [unique_id "aqxYiecL08BTTQixEnphCAAAAG0"]
[Thu Sep 17 15:15:53.380520 2026] [security2:error] [pid 971102:tid 971355] [client 170.83.212.197:62992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYiecL08BTTQixEnphCQAAAHk"]
[Thu Sep 17 15:15:53.502374 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/logs/.env"] [unique_id "aqxYiecL08BTTQixEnphFAAAAEw"]
[Thu Sep 17 15:15:53.575011 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cache/.env"] [unique_id "aqxYiecL08BTTQixEnphFgAAAHQ"]
[Thu Sep 17 15:15:53.588970 2026] [security2:error] [pid 971102:tid 971302] [client 74.7.175.133:51312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-02c52488.qat.qby.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYiecL08BTTQixEnphFwAARHc"]
[Thu Sep 17 15:15:53.634627 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailer/.env"] [unique_id "aqxYiecL08BTTQixEnphGQAAAB4"]
[Thu Sep 17 15:15:53.706130 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mail/.env"] [unique_id "aqxYiecL08BTTQixEnphGgAAAGo"]
[Thu Sep 17 15:15:53.776564 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/email/.env"] [unique_id "aqxYiecL08BTTQixEnphHwAAAEg"]
[Thu Sep 17 15:15:53.822370 2026] [security2:error] [pid 971102:tid 971330] [client 5.189.145.112:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxYiecL08BTTQixEnphIAAAAGA"], referer: binance.com
[Thu Sep 17 15:15:53.885633 2026] [core:error] [pid 971102:tid 971267] [client 74.7.244.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:53.885655 2026] [core:error] [pid 971102:tid 971267] [client 74.7.244.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:53.885806 2026] [security2:error] [pid 971102:tid 971267] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxYiecL08BTTQixEnphJgAAACE"]
[Thu Sep 17 15:15:53.896641 2026] [security2:error] [pid 971102:tid 971261] [client 74.7.244.49:57860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxYiecL08BTTQixEnphIQAAGyo"]
[Thu Sep 17 15:15:53.963259 2026] [security2:error] [pid 971102:tid 971320] [client 212.28.179.189:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cpanel-box5305.bluehost.com"] [uri "/___proxy_subdomain_webmail/backend/api/.env"] [unique_id "aqxYiecL08BTTQixEnphKQAAAFY"]
[Thu Sep 17 15:15:53.988475 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/smtp/.env"] [unique_id "aqxYiecL08BTTQixEnphKgAAAGg"]
[Thu Sep 17 15:15:54.052666 2026] [security2:error] [pid 971102:tid 971284] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailing/.env"] [unique_id "aqxYiucL08BTTQixEnphLQAAADI"]
[Thu Sep 17 15:15:54.072119 2026] [security2:error] [pid 971102:tid 971243] [client 172.239.147.162:51794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxYiecL08BTTQixEnphJwAAAAk"], referer: binance.com
[Thu Sep 17 15:15:54.112597 2026] [security2:error] [pid 971102:tid 971357] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/notifications/.env"] [unique_id "aqxYiucL08BTTQixEnphMAAAAHs"]
[Thu Sep 17 15:15:54.113092 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiucL08BTTQixEnphMQAAAAg"]
[Thu Sep 17 15:15:54.114418 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:62130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiucL08BTTQixEnphMQAAAAg"]
[Thu Sep 17 15:15:54.177472 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/notify/.env"] [unique_id "aqxYiucL08BTTQixEnphNQAAAF4"]
[Thu Sep 17 15:15:54.240338 2026] [security2:error] [pid 971102:tid 971305] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sender/.env"] [unique_id "aqxYiucL08BTTQixEnphNwAAAEc"]
[Thu Sep 17 15:15:54.307936 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/campaign/.env"] [unique_id "aqxYiucL08BTTQixEnphOAAAADM"]
[Thu Sep 17 15:15:54.374038 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/newsletter/.env"] [unique_id "aqxYiucL08BTTQixEnphOgAAAAs"]
[Thu Sep 17 15:15:54.438600 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/ses/.env"] [unique_id "aqxYiucL08BTTQixEnphPQAAAFg"]
[Thu Sep 17 15:15:54.501556 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sendgrid/.env"] [unique_id "aqxYiucL08BTTQixEnphPwAAAAA"]
[Thu Sep 17 15:15:54.562333 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sparkpost/.env"] [unique_id "aqxYiucL08BTTQixEnphQAAAAGs"]
[Thu Sep 17 15:15:54.641785 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/postmark/.env"] [unique_id "aqxYiucL08BTTQixEnphRAAAAEo"]
[Thu Sep 17 15:15:54.720166 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailgun/.env"] [unique_id "aqxYiucL08BTTQixEnphRwAAACk"]
[Thu Sep 17 15:15:54.782285 2026] [security2:error] [pid 971102:tid 971271] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mandrill/.env"] [unique_id "aqxYiucL08BTTQixEnphSQAAACU"]
[Thu Sep 17 15:15:54.845690 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailjet/.env"] [unique_id "aqxYiucL08BTTQixEnphSgAAAGQ"]
[Thu Sep 17 15:15:54.922306 2026] [security2:error] [pid 971102:tid 971325] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/brevo/.env"] [unique_id "aqxYiucL08BTTQixEnphTAAAAFs"]
[Thu Sep 17 15:15:54.989968 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/transactional/.env"] [unique_id "aqxYiucL08BTTQixEnphTQAAACQ"]
[Thu Sep 17 15:15:55.051496 2026] [security2:error] [pid 971102:tid 971353] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/bulk/.env"] [unique_id "aqxYi-cL08BTTQixEnphTwAAAHc"]
[Thu Sep 17 15:15:55.113863 2026] [security2:error] [pid 971102:tid 971355] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/aws/.env"] [unique_id "aqxYi-cL08BTTQixEnphUgAAAHk"]
[Thu Sep 17 15:15:55.168111 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/azure/.env"] [unique_id "aqxYi-cL08BTTQixEnphVwAAACw"]
[Thu Sep 17 15:15:55.227031 2026] [security2:error] [pid 971102:tid 971247] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/gcp/.env"] [unique_id "aqxYi-cL08BTTQixEnphWAAAAA0"]
[Thu Sep 17 15:15:55.294268 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cloud/.env"] [unique_id "aqxYi-cL08BTTQixEnphWgAAABo"]
[Thu Sep 17 15:15:55.349041 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/infrastructure/.env"] [unique_id "aqxYi-cL08BTTQixEnphXAAAAHQ"]
[Thu Sep 17 15:15:55.404446 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/docker/.env"] [unique_id "aqxYi-cL08BTTQixEnphXgAAAGo"]
[Thu Sep 17 15:15:55.436585 2026] [security2:error] [pid 971102:tid 971337] [client 172.239.147.162:64189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxYi-cL08BTTQixEnphXQAAAGc"], referer: binance.com
[Thu Sep 17 15:15:55.466063 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/k8s/.env"] [unique_id "aqxYi-cL08BTTQixEnphYAAAAEg"]
[Thu Sep 17 15:15:55.523310 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/kubernetes/.env"] [unique_id "aqxYi-cL08BTTQixEnphYgAAAAY"]
[Thu Sep 17 15:15:55.537843 2026] [security2:error] [pid 971102:tid 971344] [client 212.28.179.189:55462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cpanel-box5305.bluehost.com"] [uri "/___proxy_subdomain_webmail/backend/app/.env"] [unique_id "aqxYi-cL08BTTQixEnphZAAAAG4"]
[Thu Sep 17 15:15:55.578769 2026] [security2:error] [pid 971102:tid 971342] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/terraform/.env"] [unique_id "aqxYi-cL08BTTQixEnphZQAAAGw"]
[Thu Sep 17 15:15:55.638978 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/ansible/.env"] [unique_id "aqxYi-cL08BTTQixEnphawAAAD0"]
[Thu Sep 17 15:15:55.700243 2026] [security2:error] [pid 971102:tid 971289] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.git/.env"] [unique_id "aqxYi-cL08BTTQixEnphbgAAADc"]
[Thu Sep 17 15:15:55.760516 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/ci/.env"] [unique_id "aqxYi-cL08BTTQixEnphcAAAAGk"]
[Thu Sep 17 15:15:55.815965 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cd/.env"] [unique_id "aqxYi-cL08BTTQixEnphcQAAABQ"]
[Thu Sep 17 15:15:55.879083 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/jenkins/.env"] [unique_id "aqxYi-cL08BTTQixEnphcgAAAFU"]
[Thu Sep 17 15:15:55.953870 2026] [security2:error] [pid 971102:tid 971305] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/gitlab/.env"] [unique_id "aqxYi-cL08BTTQixEnphcwAAAEc"]
[Thu Sep 17 15:15:56.016682 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/github/.env"] [unique_id "aqxYjOcL08BTTQixEnphdAAAAFo"]
[Thu Sep 17 15:15:56.077942 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/actions/.env"] [unique_id "aqxYjOcL08BTTQixEnphdQAAAFM"]
[Thu Sep 17 15:15:56.147174 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/circleci/.env"] [unique_id "aqxYjOcL08BTTQixEnphdwAAAAs"]
[Thu Sep 17 15:15:56.206460 2026] [security2:error] [pid 971102:tid 971290] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/travis/.env"] [unique_id "aqxYjOcL08BTTQixEnphegAAADg"]
[Thu Sep 17 15:15:56.272963 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/buildkite/.env"] [unique_id "aqxYjOcL08BTTQixEnphfAAAAGU"]
[Thu Sep 17 15:15:56.334648 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mysql/.env"] [unique_id "aqxYjOcL08BTTQixEnphfQAAAFE"]
[Thu Sep 17 15:15:56.393529 2026] [security2:error] [pid 971102:tid 971327] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/postgres/.env"] [unique_id "aqxYjOcL08BTTQixEnphfgAAAF0"]
[Thu Sep 17 15:15:56.454416 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mongodb/.env"] [unique_id "aqxYjOcL08BTTQixEnphgAAAAGs"]
[Thu Sep 17 15:15:56.532760 2026] [security2:error] [pid 971102:tid 971293] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/redis/.env"] [unique_id "aqxYjOcL08BTTQixEnphhAAAADs"]
[Thu Sep 17 15:15:56.596653 2026] [security2:error] [pid 971102:tid 971271] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/elasticsearch/.env"] [unique_id "aqxYjOcL08BTTQixEnphhQAAACU"]
[Thu Sep 17 15:15:56.660216 2026] [security2:error] [pid 971102:tid 971333] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/rabbitmq/.env"] [unique_id "aqxYjOcL08BTTQixEnphiAAAAGM"]
[Thu Sep 17 15:15:56.718619 2026] [security2:error] [pid 971102:tid 971358] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/kafka/.env"] [unique_id "aqxYjOcL08BTTQixEnphigAAAHw"]
[Thu Sep 17 15:15:56.775506 2026] [security2:error] [pid 971102:tid 971276] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/queue/.env"] [unique_id "aqxYjOcL08BTTQixEnphiwAAACo"]
[Thu Sep 17 15:15:56.843979 2026] [security2:error] [pid 971102:tid 971356] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/worker/.env"] [unique_id "aqxYjOcL08BTTQixEnphjQAAAHo"]
[Thu Sep 17 15:15:56.904992 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/job/.env"] [unique_id "aqxYjOcL08BTTQixEnphkQAAAFI"]
[Thu Sep 17 15:15:56.964436 2026] [security2:error] [pid 971102:tid 971272] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/test/.env"] [unique_id "aqxYjOcL08BTTQixEnphlAAAACY"]
[Thu Sep 17 15:15:56.982840 2026] [security2:error] [pid 971102:tid 971336] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYiucL08BTTQixEnphSwAAZms"], referer: http://vagabondhiker.com/wordpress/
[Thu Sep 17 15:15:57.012511 2026] [security2:error] [pid 971102:tid 971247] [client 24.10.245.213:35123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYjOcL08BTTQixEnphkAAADVs"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:15:57.024789 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.80.249:60764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxYjecL08BTTQixEnphlQAAADY"]
[Thu Sep 17 15:15:57.028022 2026] [security2:error] [pid 971102:tid 971279] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/qa/.env"] [unique_id "aqxYjecL08BTTQixEnphlgAAAC0"]
[Thu Sep 17 15:15:57.083710 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/preview/.env"] [unique_id "aqxYjecL08BTTQixEnphmQAAAEI"]
[Thu Sep 17 15:15:57.125455 2026] [security2:error] [pid 971102:tid 971294] [client 104.28.198.244:22828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphmwAAADw"]
[Thu Sep 17 15:15:57.125626 2026] [security2:error] [pid 971102:tid 971294] [client 104.28.198.244:22828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphmwAAADw"]
[Thu Sep 17 15:15:57.152090 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/beta/.env"] [unique_id "aqxYjecL08BTTQixEnphnAAAAD4"]
[Thu Sep 17 15:15:57.224512 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/uat/.env"] [unique_id "aqxYjecL08BTTQixEnphogAAACs"]
[Thu Sep 17 15:15:57.268266 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.80.249:60770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxYjecL08BTTQixEnphpgAAAAE"]
[Thu Sep 17 15:15:57.278968 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/stage/.env"] [unique_id "aqxYjecL08BTTQixEnphpwAAAFY"]
[Thu Sep 17 15:15:57.350335 2026] [security2:error] [pid 971102:tid 971244] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/development/.env"] [unique_id "aqxYjecL08BTTQixEnphqAAAAAo"]
[Thu Sep 17 15:15:57.407874 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/production/.env"] [unique_id "aqxYjecL08BTTQixEnphqgAAAGg"]
[Thu Sep 17 15:15:57.458713 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.80.249:60784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxYjecL08BTTQixEnphqwAAACg"]
[Thu Sep 17 15:15:57.483202 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/config/app/.env"] [unique_id "aqxYjecL08BTTQixEnphrAAAAEU"]
[Thu Sep 17 15:15:57.530947 2026] [security2:error] [pid 971102:tid 971351] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYjecL08BTTQixEnphrQAAdWY"], referer: https://vagabondhiker.com/wordpress/
[Thu Sep 17 15:15:57.538720 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.195.25:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php"] [unique_id "aqxYjecL08BTTQixEnphrwAAABM"]
[Thu Sep 17 15:15:57.651204 2026] [security2:error] [pid 971102:tid 971323] [client 185.55.149.49:54977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphsgAAAFk"]
[Thu Sep 17 15:15:57.651315 2026] [security2:error] [pid 971102:tid 971323] [client 185.55.149.49:54977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphsgAAAFk"]
[Thu Sep 17 15:15:57.713371 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.195.25:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/info.php"] [unique_id "aqxYjecL08BTTQixEnphuAAAADM"]
[Thu Sep 17 15:15:57.750447 2026] [security2:error] [pid 971102:tid 971331] [client 34.23.80.249:60792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/"] [unique_id "aqxYjecL08BTTQixEnphuQAAAGE"]
[Thu Sep 17 15:15:57.897359 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.195.25:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/php.php"] [unique_id "aqxYjecL08BTTQixEnphvQAAAGU"]
[Thu Sep 17 15:15:57.946461 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env"] [unique_id "aqxYjecL08BTTQixEnphwAAAABc"]
[Thu Sep 17 15:15:57.973248 2026] [security2:error] [pid 971102:tid 971251] [client 24.10.245.213:34591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYjecL08BTTQixEnphvwAAETA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818054740&hideanons=1&hideminor=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:15:58.065973 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.195.25:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/i.php"] [unique_id "aqxYjucL08BTTQixEnphxAAAACA"]
[Thu Sep 17 15:15:58.243645 2026] [security2:error] [pid 971102:tid 971255] [client 34.23.195.25:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/pi.php"] [unique_id "aqxYjucL08BTTQixEnphzgAAABU"]
[Thu Sep 17 15:15:58.439579 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:51068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/pinfo.php"] [unique_id "aqxYjucL08BTTQixEnph2AAAAEI"]
[Thu Sep 17 15:15:58.641936 2026] [security2:error] [pid 971102:tid 971318] [client 34.23.195.25:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/test.php"] [unique_id "aqxYjucL08BTTQixEnph4AAAAFQ"]
[Thu Sep 17 15:15:58.686839 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.bak"] [unique_id "aqxYjucL08BTTQixEnph4wAAAHE"]
[Thu Sep 17 15:15:58.727465 2026] [security2:error] [pid 971102:tid 971337] [client 186.105.232.15:49741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjucL08BTTQixEnph5gAAAGc"]
[Thu Sep 17 15:15:58.727585 2026] [security2:error] [pid 971102:tid 971337] [client 186.105.232.15:49741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjucL08BTTQixEnph5gAAAGc"]
[Thu Sep 17 15:15:58.741248 2026] [security2:error] [pid 971102:tid 971258] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.backup"] [unique_id "aqxYjucL08BTTQixEnph5wAAABg"]
[Thu Sep 17 15:15:58.884247 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.old"] [unique_id "aqxYjucL08BTTQixEnph7gAAAB8"]
[Thu Sep 17 15:15:58.895342 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.195.25:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/p.php"] [unique_id "aqxYjucL08BTTQixEnph8AAAAE4"]
[Thu Sep 17 15:15:59.081248 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.195.25:51108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/debug.php"] [unique_id "aqxYj-cL08BTTQixEnpiAAAAABc"]
[Thu Sep 17 15:15:59.204155 2026] [security2:error] [pid 971102:tid 971311] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiBgAATUU"], referer: http://vagabondhiker.com/backup/
[Thu Sep 17 15:15:59.281765 2026] [security2:error] [pid 971102:tid 971348] [client 34.23.195.25:51116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiCQAAAHI"]
[Thu Sep 17 15:15:59.416127 2026] [security2:error] [pid 971102:tid 971260] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiDQAAGgE"], referer: https://vagabondhiker.com/backup/
[Thu Sep 17 15:15:59.420445 2026] [security2:error] [pid 971102:tid 971336] [client 162.241.226.11:46670] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxYj-cL08BTTQixEnpiDwAAAGY"]
[Thu Sep 17 15:15:59.463864 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.195.25:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/test/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiEgAAAEk"]
[Thu Sep 17 15:15:59.679061 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiGgAAACs"]
[Thu Sep 17 15:15:59.781469 2026] [security2:error] [pid 971102:tid 971345] [client 45.169.98.18:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYj-cL08BTTQixEnpiHwAAAG8"]
[Thu Sep 17 15:15:59.781586 2026] [security2:error] [pid 971102:tid 971345] [client 45.169.98.18:54630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYj-cL08BTTQixEnpiHwAAAG8"]
[Thu Sep 17 15:15:59.788565 2026] [security2:error] [pid 971102:tid 971295] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiHQAAPVw"], referer: http://vagabondhiker.com/new/
[Thu Sep 17 15:15:59.798571 2026] [security2:error] [pid 971102:tid 971344] [client 111.172.6.214:62807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5305.bluehost.com"] [uri "/index.cgi"] [unique_id "aqxYj-cL08BTTQixEnpiHgAAAG4"]
[Thu Sep 17 15:15:59.879530 2026] [security2:error] [pid 971102:tid 971250] [client 34.23.195.25:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/old/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiIwAAABA"]
[Thu Sep 17 15:15:59.995249 2026] [security2:error] [pid 971102:tid 971253] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiJQAAE0s"], referer: https://vagabondhiker.com/new/
[Thu Sep 17 15:16:00.048735 2026] [security2:error] [pid 971102:tid 971337] [client 34.23.195.25:51174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYkOcL08BTTQixEnpiKAAAAGc"]
[Thu Sep 17 15:16:00.247473 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.195.25:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYkOcL08BTTQixEnpiMQAAACg"]
[Thu Sep 17 15:16:00.330926 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiOAAAAGg"]
[Thu Sep 17 15:16:00.331046 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiOAAAAGg"]
[Thu Sep 17 15:16:00.366964 2026] [security2:error] [pid 971102:tid 971302] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkOcL08BTTQixEnpiNwAARDk"], referer: http://vagabondhiker.com/wp/
[Thu Sep 17 15:16:00.475643 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.swp"] [unique_id "aqxYkOcL08BTTQixEnpiPwAAAFA"]
[Thu Sep 17 15:16:00.510790 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.195.25:51190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/php-info.php"] [unique_id "aqxYkOcL08BTTQixEnpiQAAAAHU"]
[Thu Sep 17 15:16:00.543593 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiQwAAAF0"]
[Thu Sep 17 15:16:00.543733 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:53950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiQwAAAF0"]
[Thu Sep 17 15:16:00.545286 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env~"] [unique_id "aqxYkOcL08BTTQixEnpiQgAAADA"]
[Thu Sep 17 15:16:00.574424 2026] [security2:error] [pid 971102:tid 971311] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkOcL08BTTQixEnpiQQAATSQ"], referer: https://vagabondhiker.com/wp/
[Thu Sep 17 15:16:00.697883 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:39408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpversion.php"] [unique_id "aqxYkOcL08BTTQixEnpiUgAAAFI"]
[Thu Sep 17 15:16:00.745685 2026] [security2:error] [pid 971102:tid 971235] [client 5.189.145.112:53240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxYkOcL08BTTQixEnpiWAAAAAE"], referer: binance.com
[Thu Sep 17 15:16:00.877152 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.195.25:39414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/_phpinfo.php"] [unique_id "aqxYkOcL08BTTQixEnpiZAAAAD0"]
[Thu Sep 17 15:16:00.929749 2026] [security2:error] [pid 971102:tid 971361] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkOcL08BTTQixEnpiZgAAf1Q"], referer: http://vagabondhiker.com/blog/
[Thu Sep 17 15:16:01.031925 2026] [security2:error] [pid 971102:tid 971274] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxYkecL08BTTQixEnpicgAAACg"]
[Thu Sep 17 15:16:01.056564 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.195.25:39422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/old_phpinfo.php"] [unique_id "aqxYkecL08BTTQixEnpidQAAABY"]
[Thu Sep 17 15:16:01.134519 2026] [security2:error] [pid 971102:tid 971287] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkecL08BTTQixEnpidwAANUc"], referer: https://vagabondhiker.com/blog/
[Thu Sep 17 15:16:01.223550 2026] [security2:error] [pid 971102:tid 971251] [client 34.23.195.25:39432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/server-info.php"] [unique_id "aqxYkecL08BTTQixEnpihgAAABE"]
[Thu Sep 17 15:16:01.296845 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/app/.env"] [unique_id "aqxYkecL08BTTQixEnpijwAAAHg"]
[Thu Sep 17 15:16:01.357747 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/apps/.env"] [unique_id "aqxYkecL08BTTQixEnpikgAAAEU"]
[Thu Sep 17 15:16:01.402409 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.195.25:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/server-status.php"] [unique_id "aqxYkecL08BTTQixEnpilgAAAFo"]
[Thu Sep 17 15:16:01.415531 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/.env"] [unique_id "aqxYkecL08BTTQixEnpilwAAAGs"]
[Thu Sep 17 15:16:01.473453 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxYkecL08BTTQixEnpinQAAAC4"]
[Thu Sep 17 15:16:01.475618 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/web/.env"] [unique_id "aqxYkecL08BTTQixEnpingAAAAY"]
[Thu Sep 17 15:16:01.491437 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxYkecL08BTTQixEnpinwAAAEM"]
[Thu Sep 17 15:16:01.501795 2026] [security2:error] [pid 971102:tid 971286] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkecL08BTTQixEnpimwAANEI"], referer: http://vagabondhiker.com/old/
[Thu Sep 17 15:16:01.534708 2026] [security2:error] [pid 971102:tid 971279] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/site/.env"] [unique_id "aqxYkecL08BTTQixEnpiogAAAC0"]
[Thu Sep 17 15:16:01.580285 2026] [security2:error] [pid 971102:tid 971318] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxYkecL08BTTQixEnpipQAAAFQ"]
[Thu Sep 17 15:16:01.598724 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/public/.env"] [unique_id "aqxYkecL08BTTQixEnpiqAAAAEI"]
[Thu Sep 17 15:16:01.710755 2026] [security2:error] [pid 971102:tid 971347] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkecL08BTTQixEnpisAAAcTY"], referer: https://vagabondhiker.com/old/
[Thu Sep 17 15:16:01.802473 2026] [security2:error] [pid 971102:tid 971241] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/backend/.env"] [unique_id "aqxYkecL08BTTQixEnpiuwAAAAc"]
[Thu Sep 17 15:16:01.860943 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/server/.env"] [unique_id "aqxYkecL08BTTQixEnpivwAAADU"]
[Thu Sep 17 15:16:01.895778 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.195.25:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYkecL08BTTQixEnpiwQAAAFA"]
[Thu Sep 17 15:16:01.920185 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/frontend/.env"] [unique_id "aqxYkecL08BTTQixEnpiwgAAADA"]
[Thu Sep 17 15:16:01.981336 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/src/.env"] [unique_id "aqxYkecL08BTTQixEnpixgAAAF8"]
[Thu Sep 17 15:16:02.042091 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/core/.env"] [unique_id "aqxYkucL08BTTQixEnpiywAAAFg"]
[Thu Sep 17 15:16:02.081555 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.195.25:39464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi0AAAAH0"]
[Thu Sep 17 15:16:02.107492 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/core/app/.env"] [unique_id "aqxYkucL08BTTQixEnpi0wAAAB0"]
[Thu Sep 17 15:16:02.166511 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/config/.env"] [unique_id "aqxYkucL08BTTQixEnpi2wAAAGs"]
[Thu Sep 17 15:16:02.225213 2026] [security2:error] [pid 971102:tid 971268] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/private/.env"] [unique_id "aqxYkucL08BTTQixEnpi3QAAACI"]
[Thu Sep 17 15:16:02.255739 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.195.25:39472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi4QAAADE"]
[Thu Sep 17 15:16:02.284020 2026] [security2:error] [pid 971102:tid 971271] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/application/.env"] [unique_id "aqxYkucL08BTTQixEnpi5QAAACU"]
[Thu Sep 17 15:16:02.322983 2026] [security2:error] [pid 971102:tid 971316] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYkucL08BTTQixEnpi2QAAUg0"], referer: http://www.radtechresourcegroup.com/backup/
[Thu Sep 17 15:16:02.344725 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/bootstrap/.env"] [unique_id "aqxYkucL08BTTQixEnpi6QAAAAU"]
[Thu Sep 17 15:16:02.417557 2026] [security2:error] [pid 971102:tid 971318] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/database/.env"] [unique_id "aqxYkucL08BTTQixEnpi6wAAAFQ"]
[Thu Sep 17 15:16:02.446040 2026] [security2:error] [pid 971102:tid 971244] [client 34.23.195.25:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi7QAAAAo"]
[Thu Sep 17 15:16:02.477898 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/storage/.env"] [unique_id "aqxYkucL08BTTQixEnpi8AAAAAM"]
[Thu Sep 17 15:16:02.507184 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxYkucL08BTTQixEnpi8gAAAH8"]
[Thu Sep 17 15:16:02.523067 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxYkucL08BTTQixEnpi8wAAAGk"]
[Thu Sep 17 15:16:02.537384 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/var/www/.env"] [unique_id "aqxYkucL08BTTQixEnpi9AAAAFU"]
[Thu Sep 17 15:16:02.596386 2026] [security2:error] [pid 971102:tid 971360] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/var/www/html/.env"] [unique_id "aqxYkucL08BTTQixEnpi-AAAAH4"]
[Thu Sep 17 15:16:02.622393 2026] [security2:error] [pid 971102:tid 971356] [client 34.23.195.25:39490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi-wAAAHo"]
[Thu Sep 17 15:16:02.655723 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/current/.env"] [unique_id "aqxYkucL08BTTQixEnpi_wAAADk"]
[Thu Sep 17 15:16:02.721162 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/release/.env"] [unique_id "aqxYkucL08BTTQixEnpjBQAAAFE"]
[Thu Sep 17 15:16:02.785704 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/releases/.env"] [unique_id "aqxYkucL08BTTQixEnpjBwAAADU"]
[Thu Sep 17 15:16:02.787763 2026] [security2:error] [pid 971102:tid 971241] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYkucL08BTTQixEnpi_gAABzQ"], referer: http://www.radtechresourcegroup.com/new/
[Thu Sep 17 15:16:02.835128 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.195.25:39502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpjCwAAABY"]
[Thu Sep 17 15:16:02.847123 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/shared/.env"] [unique_id "aqxYkucL08BTTQixEnpjDAAAAEo"]
[Thu Sep 17 15:16:02.910984 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/deploy/.env"] [unique_id "aqxYkucL08BTTQixEnpjDQAAAHU"]
[Thu Sep 17 15:16:02.977878 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/build/.env"] [unique_id "aqxYkucL08BTTQixEnpjEQAAAF8"]
[Thu Sep 17 15:16:03.003090 2026] [security2:error] [pid 971102:tid 971276] [client 34.23.195.25:39506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxYk-cL08BTTQixEnpjEwAAACo"]
[Thu Sep 17 15:16:03.037715 2026] [security2:error] [pid 971102:tid 971261] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/dist/.env"] [unique_id "aqxYk-cL08BTTQixEnpjFQAAABs"]
[Thu Sep 17 15:16:03.092691 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/public_html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjHAAAAGo"]
[Thu Sep 17 15:16:03.112681 2026] [security2:error] [pid 971102:tid 971336] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxYk-cL08BTTQixEnpjHgAAAGY"]
[Thu Sep 17 15:16:03.133102 2026] [security2:error] [pid 971102:tid 971262] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxYk-cL08BTTQixEnpjIAAAABw"]
[Thu Sep 17 15:16:03.140112 2026] [authz_core:error] [pid 971102:tid 971343] [client 172.239.147.162:62345] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:03.147418 2026] [security2:error] [pid 971102:tid 971267] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxYk-cL08BTTQixEnpjIgAAACE"]
[Thu Sep 17 15:16:03.150228 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/htdocs/.env"] [unique_id "aqxYk-cL08BTTQixEnpjIwAAAA8"]
[Thu Sep 17 15:16:03.163810 2026] [security2:error] [pid 971102:tid 971273] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxYk-cL08BTTQixEnpjJAAAACc"]
[Thu Sep 17 15:16:03.184997 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxYk-cL08BTTQixEnpjJQAAAEg"]
[Thu Sep 17 15:16:03.186387 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:39520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php.old"] [unique_id "aqxYk-cL08BTTQixEnpjJgAAACk"]
[Thu Sep 17 15:16:03.200244 2026] [security2:error] [pid 971102:tid 971268] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxYk-cL08BTTQixEnpjJwAAACI"]
[Thu Sep 17 15:16:03.207793 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/www/.env"] [unique_id "aqxYk-cL08BTTQixEnpjKAAAADE"]
[Thu Sep 17 15:16:03.247903 2026] [security2:error] [pid 971102:tid 971272] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYk-cL08BTTQixEnpjGgAAJkM"], referer: http://www.radtechresourcegroup.com/wordpress/
[Thu Sep 17 15:16:03.268270 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjLQAAAC4"]
[Thu Sep 17 15:16:03.282390 2026] [security2:error] [pid 971102:tid 971288] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxYk-cL08BTTQixEnpjLgAAADY"]
[Thu Sep 17 15:16:03.296045 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxYk-cL08BTTQixEnpjLwAAAEM"]
[Thu Sep 17 15:16:03.316529 2026] [security2:error] [pid 971102:tid 971264] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxYk-cL08BTTQixEnpjMAAAAB4"]
[Thu Sep 17 15:16:03.327906 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/live/.env"] [unique_id "aqxYk-cL08BTTQixEnpjMgAAAAU"]
[Thu Sep 17 15:16:03.329709 2026] [security2:error] [pid 971102:tid 971330] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxYk-cL08BTTQixEnpjMwAAAGA"]
[Thu Sep 17 15:16:03.343051 2026] [security2:error] [pid 971102:tid 971318] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxYk-cL08BTTQixEnpjNgAAAFQ"]
[Thu Sep 17 15:16:03.355267 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php~"] [unique_id "aqxYk-cL08BTTQixEnpjNwAAAFI"]
[Thu Sep 17 15:16:03.376959 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxYk-cL08BTTQixEnpjOQAAAD4"]
[Thu Sep 17 15:16:03.386617 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/prod/.env"] [unique_id "aqxYk-cL08BTTQixEnpjOgAAAD0"]
[Thu Sep 17 15:16:03.408343 2026] [security2:error] [pid 971102:tid 971244] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxYk-cL08BTTQixEnpjPAAAAAo"]
[Thu Sep 17 15:16:03.444446 2026] [security2:error] [pid 971102:tid 971237] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxYk-cL08BTTQixEnpjPQAAAAM"]
[Thu Sep 17 15:16:03.446282 2026] [security2:error] [pid 971102:tid 971250] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/dev/.env"] [unique_id "aqxYk-cL08BTTQixEnpjPgAAABA"]
[Thu Sep 17 15:16:03.477615 2026] [authz_core:error] [pid 971102:tid 971240] [client 172.239.147.162:56593] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:03.480933 2026] [security2:error] [pid 971102:tid 971337] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQAAAAGc"]
[Thu Sep 17 15:16:03.495060 2026] [security2:error] [pid 971102:tid 971305] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQQAAAEc"]
[Thu Sep 17 15:16:03.513403 2026] [security2:error] [pid 971102:tid 971299] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQgAAAEE"]
[Thu Sep 17 15:16:03.514959 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/staging/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQwAAABQ"]
[Thu Sep 17 15:16:03.529910 2026] [security2:error] [pid 971102:tid 971285] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxYk-cL08BTTQixEnpjRAAAADM"]
[Thu Sep 17 15:16:03.535929 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.195.25:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/info.php.bak"] [unique_id "aqxYk-cL08BTTQixEnpjRQAAAGQ"]
[Thu Sep 17 15:16:03.545340 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxYk-cL08BTTQixEnpjRgAAAGk"]
[Thu Sep 17 15:16:03.560404 2026] [security2:error] [pid 971102:tid 971258] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSAAAABg"]
[Thu Sep 17 15:16:03.576473 2026] [security2:error] [pid 971102:tid 971323] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSQAAAFk"]
[Thu Sep 17 15:16:03.577560 2026] [security2:error] [pid 971102:tid 971304] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/opt/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSgAAAEY"]
[Thu Sep 17 15:16:03.592609 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSwAAAHE"]
[Thu Sep 17 15:16:03.607734 2026] [security2:error] [pid 971102:tid 971289] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxYk-cL08BTTQixEnpjTAAAADc"]
[Thu Sep 17 15:16:03.623232 2026] [security2:error] [pid 971102:tid 971356] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxYk-cL08BTTQixEnpjTQAAAHo"]
[Thu Sep 17 15:16:03.637884 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/laravel/.env"] [unique_id "aqxYk-cL08BTTQixEnpjTwAAADk"]
[Thu Sep 17 15:16:03.641403 2026] [security2:error] [pid 971102:tid 971342] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxYk-cL08BTTQixEnpjUAAAAGw"]
[Thu Sep 17 15:16:03.664641 2026] [security2:error] [pid 971102:tid 971313] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxYk-cL08BTTQixEnpjUgAAAE8"]
[Thu Sep 17 15:16:03.687735 2026] [security2:error] [pid 971102:tid 971242] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxYk-cL08BTTQixEnpjVAAAAAg"]
[Thu Sep 17 15:16:03.698158 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/symfony/.env"] [unique_id "aqxYk-cL08BTTQixEnpjVQAAAFE"]
[Thu Sep 17 15:16:03.711787 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.195.25:39540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php.save"] [unique_id "aqxYk-cL08BTTQixEnpjVgAAACQ"]
[Thu Sep 17 15:16:03.713770 2026] [security2:error] [pid 971102:tid 971319] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYk-cL08BTTQixEnpjRwAAVTI"], referer: http://www.radtechresourcegroup.com/blog/
[Thu Sep 17 15:16:03.719145 2026] [security2:error] [pid 971102:tid 971287] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjVwAAADU"]
[Thu Sep 17 15:16:03.744417 2026] [security2:error] [pid 971102:tid 971332] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxYk-cL08BTTQixEnpjWAAAAGI"]
[Thu Sep 17 15:16:03.760807 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/wordpress/.env"] [unique_id "aqxYk-cL08BTTQixEnpjWgAAAGU"]
[Thu Sep 17 15:16:03.762508 2026] [security2:error] [pid 971102:tid 971293] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxYk-cL08BTTQixEnpjWwAAADs"]
[Thu Sep 17 15:16:03.790787 2026] [security2:error] [pid 971102:tid 971256] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXAAAABY"]
[Thu Sep 17 15:16:03.809503 2026] [security2:error] [pid 971102:tid 971308] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXQAAAEo"]
[Thu Sep 17 15:16:03.822486 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/wp/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXgAAAFA"]
[Thu Sep 17 15:16:03.826493 2026] [security2:error] [pid 971102:tid 971351] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXwAAAHU"]
[Thu Sep 17 15:16:03.841346 2026] [security2:error] [pid 971102:tid 971355] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxYk-cL08BTTQixEnpjYAAAAHk"]
[Thu Sep 17 15:16:03.863065 2026] [security2:error] [pid 971102:tid 971251] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxYk-cL08BTTQixEnpjYQAAABE"]
[Thu Sep 17 15:16:03.876566 2026] [security2:error] [pid 971102:tid 971327] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxYk-cL08BTTQixEnpjYwAAAF0"]
[Thu Sep 17 15:16:03.883160 2026] [security2:error] [pid 971102:tid 971331] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cms/.env"] [unique_id "aqxYk-cL08BTTQixEnpjZAAAAGE"]
[Thu Sep 17 15:16:03.885267 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.195.25:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxYk-cL08BTTQixEnpjZQAAADA"]
[Thu Sep 17 15:16:03.897562 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxYk-cL08BTTQixEnpjZgAAAHM"]
[Thu Sep 17 15:16:03.922557 2026] [security2:error] [pid 971102:tid 971257] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxYk-cL08BTTQixEnpjZwAAABc"]
[Thu Sep 17 15:16:03.946841 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/drupal/.env"] [unique_id "aqxYk-cL08BTTQixEnpjaAAAAF8"]
[Thu Sep 17 15:16:04.014103 2026] [security2:error] [pid 971102:tid 971348] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/joomla/.env"] [unique_id "aqxYlOcL08BTTQixEnpjagAAAHI"]
[Thu Sep 17 15:16:04.025496 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxYlOcL08BTTQixEnpjbAAAACA"]
[Thu Sep 17 15:16:04.050806 2026] [security2:error] [pid 971102:tid 971353] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxYlOcL08BTTQixEnpjbQAAAHc"]
[Thu Sep 17 15:16:04.060469 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjbgAAAAA"]
[Thu Sep 17 15:16:04.074775 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/magento/.env"] [unique_id "aqxYlOcL08BTTQixEnpjcAAAAB0"]
[Thu Sep 17 15:16:04.075314 2026] [security2:error] [pid 971102:tid 971260] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxYlOcL08BTTQixEnpjbwAAABo"]
[Thu Sep 17 15:16:04.096969 2026] [security2:error] [pid 971102:tid 971346] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxYlOcL08BTTQixEnpjcQAAAHA"]
[Thu Sep 17 15:16:04.130673 2026] [security2:error] [pid 971102:tid 971359] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxYlOcL08BTTQixEnpjcgAAAH0"]
[Thu Sep 17 15:16:04.169901 2026] [security2:error] [pid 971102:tid 971345] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxYlOcL08BTTQixEnpjdgAAAG8"]
[Thu Sep 17 15:16:04.172898 2026] [security2:error] [pid 971102:tid 971322] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYlOcL08BTTQixEnpjawAAWGU"], referer: http://www.radtechresourcegroup.com/old/
[Thu Sep 17 15:16:04.197748 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxYlOcL08BTTQixEnpjdwAAAEk"]
[Thu Sep 17 15:16:04.227297 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxYlOcL08BTTQixEnpjeQAAAEg"]
[Thu Sep 17 15:16:04.250804 2026] [security2:error] [pid 971102:tid 971268] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxYlOcL08BTTQixEnpjegAAACI"]
[Thu Sep 17 15:16:04.254055 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.195.25:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjewAAAA8"]
[Thu Sep 17 15:16:04.273159 2026] [security2:error] [pid 971102:tid 971283] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxYlOcL08BTTQixEnpjfAAAADE"]
[Thu Sep 17 15:16:04.281567 2026] [security2:error] [pid 971102:tid 971273] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/shopify/.env"] [unique_id "aqxYlOcL08BTTQixEnpjfgAAACc"]
[Thu Sep 17 15:16:04.296474 2026] [security2:error] [pid 971102:tid 971290] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxYlOcL08BTTQixEnpjfwAAADg"]
[Thu Sep 17 15:16:04.318111 2026] [security2:error] [pid 971102:tid 971277] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxYlOcL08BTTQixEnpjgQAAACs"]
[Thu Sep 17 15:16:04.339972 2026] [security2:error] [pid 971102:tid 971344] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxYlOcL08BTTQixEnpjgwAAAG4"]
[Thu Sep 17 15:16:04.340772 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/prestashop/.env"] [unique_id "aqxYlOcL08BTTQixEnpjhAAAACw"]
[Thu Sep 17 15:16:04.363026 2026] [security2:error] [pid 971102:tid 971321] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjhQAAAFc"]
[Thu Sep 17 15:16:04.396898 2026] [security2:error] [pid 971102:tid 971350] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjhgAAAHQ"]
[Thu Sep 17 15:16:04.404976 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/codeigniter/.env"] [unique_id "aqxYlOcL08BTTQixEnpjiAAAAFo"]
[Thu Sep 17 15:16:04.416533 2026] [security2:error] [pid 971102:tid 971341] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxYlOcL08BTTQixEnpjiQAAAGs"]
[Thu Sep 17 15:16:04.436981 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjigAAAEM"]
[Thu Sep 17 15:16:04.443942 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.195.25:39574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjiwAAAAE"]
[Thu Sep 17 15:16:04.458561 2026] [security2:error] [pid 971102:tid 971239] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjjAAAAAU"]
[Thu Sep 17 15:16:04.468595 2026] [security2:error] [pid 971102:tid 971318] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cakephp/.env"] [unique_id "aqxYlOcL08BTTQixEnpjjQAAAFQ"]
[Thu Sep 17 15:16:04.481492 2026] [security2:error] [pid 971102:tid 971316] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxYlOcL08BTTQixEnpjjgAAAFI"]
[Thu Sep 17 15:16:04.509207 2026] [security2:error] [pid 971102:tid 971286] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkAAAADQ"]
[Thu Sep 17 15:16:04.530997 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/zend/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkQAAAF4"]
[Thu Sep 17 15:16:04.537065 2026] [security2:error] [pid 971102:tid 971237] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkgAAAAM"]
[Thu Sep 17 15:16:04.559360 2026] [security2:error] [pid 971102:tid 971250] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkwAAABA"]
[Thu Sep 17 15:16:04.584670 2026] [security2:error] [pid 971102:tid 971305] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxYlOcL08BTTQixEnpjlAAAAEc"]
[Thu Sep 17 15:16:04.590523 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/yii/.env"] [unique_id "aqxYlOcL08BTTQixEnpjlQAAAEE"]
[Thu Sep 17 15:16:04.591461 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:62733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYlOcL08BTTQixEnpjlgAAAAs"]
[Thu Sep 17 15:16:04.592840 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:62733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYlOcL08BTTQixEnpjlgAAAAs"]
[Thu Sep 17 15:16:04.608811 2026] [security2:error] [pid 971102:tid 971254] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxYlOcL08BTTQixEnpjlwAAABQ"]
[Thu Sep 17 15:16:04.633380 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxYlOcL08BTTQixEnpjmAAAAH8"]
[Thu Sep 17 15:16:04.635869 2026] [security2:error] [pid 971102:tid 971337] [client 34.23.195.25:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjmQAAAGc"]
[Thu Sep 17 15:16:04.649019 2026] [security2:error] [pid 971102:tid 971296] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYlOcL08BTTQixEnpjjwAAPhc"], referer: http://www.radtechresourcegroup.com/wp/
[Thu Sep 17 15:16:04.650131 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/laravel5/.env"] [unique_id "aqxYlOcL08BTTQixEnpjmwAAAGQ"]
[Thu Sep 17 15:16:04.653072 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxYlOcL08BTTQixEnpjnAAAAGk"]
[Thu Sep 17 15:16:04.678529 2026] [security2:error] [pid 971102:tid 971323] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxYlOcL08BTTQixEnpjoAAAAFk"]
[Thu Sep 17 15:16:04.703339 2026] [authz_core:error] [pid 971102:tid 971330] [client 172.239.147.162:51894] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:04.712107 2026] [security2:error] [pid 971102:tid 971243] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxYlOcL08BTTQixEnpjogAAAAk"]
[Thu Sep 17 15:16:04.712107 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjoQAAAHE"]
[Thu Sep 17 15:16:04.739301 2026] [security2:error] [pid 971102:tid 971289] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxYlOcL08BTTQixEnpjowAAADc"]
[Thu Sep 17 15:16:04.760347 2026] [security2:error] [pid 971102:tid 971356] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxYlOcL08BTTQixEnpjpAAAAHo"]
[Thu Sep 17 15:16:04.766984 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjpQAAADk"]
[Thu Sep 17 15:16:04.788822 2026] [security2:error] [pid 971102:tid 971342] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxYlOcL08BTTQixEnpjpgAAAGw"]
[Thu Sep 17 15:16:04.814420 2026] [security2:error] [pid 971102:tid 971313] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxYlOcL08BTTQixEnpjqAAAAE8"]
[Thu Sep 17 15:16:04.830444 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/v3/.env"] [unique_id "aqxYlOcL08BTTQixEnpjqgAAAAY"]
[Thu Sep 17 15:16:04.838324 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.195.25:39596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/www/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjqwAAABM"]
[Thu Sep 17 15:16:04.847424 2026] [security2:error] [pid 971102:tid 971360] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrAAAAH4"]
[Thu Sep 17 15:16:04.868810 2026] [security2:error] [pid 971102:tid 971242] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrQAAAAg"]
[Thu Sep 17 15:16:04.891366 2026] [security2:error] [pid 971102:tid 971312] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrgAAAE4"]
[Thu Sep 17 15:16:04.892490 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrwAAAFE"]
[Thu Sep 17 15:16:04.918405 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxYlOcL08BTTQixEnpjsAAAACQ"]
[Thu Sep 17 15:16:04.947804 2026] [security2:error] [pid 971102:tid 971319] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxYlOcL08BTTQixEnpjsQAAAFU"]
[Thu Sep 17 15:16:04.951957 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjsgAAADU"]
[Thu Sep 17 15:16:04.971470 2026] [security2:error] [pid 971102:tid 971293] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxYlOcL08BTTQixEnpjtAAAADs"]
[Thu Sep 17 15:16:04.989967 2026] [security2:error] [pid 971102:tid 971265] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxYlOcL08BTTQixEnpjtQAAAB8"]
[Thu Sep 17 15:16:05.005463 2026] [security2:error] [pid 971102:tid 971252] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/rest/.env"] [unique_id "aqxYlecL08BTTQixEnpjtgAAABI"]
[Thu Sep 17 15:16:05.011259 2026] [security2:error] [pid 971102:tid 971308] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjtwAAAEo"]
[Thu Sep 17 15:16:05.015927 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.195.25:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpjuAAAAGI"]
[Thu Sep 17 15:16:05.031500 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxYlecL08BTTQixEnpjuQAAAFA"]
[Thu Sep 17 15:16:05.055600 2026] [security2:error] [pid 971102:tid 971351] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxYlecL08BTTQixEnpjugAAAHU"]
[Thu Sep 17 15:16:05.067831 2026] [security2:error] [pid 971102:tid 971355] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/graphql/.env"] [unique_id "aqxYlecL08BTTQixEnpjuwAAAHk"]
[Thu Sep 17 15:16:05.082223 2026] [security2:error] [pid 971102:tid 971327] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxYlecL08BTTQixEnpjvAAAAF0"]
[Thu Sep 17 15:16:05.107767 2026] [security2:error] [pid 971102:tid 971311] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxYlecL08BTTQixEnpjvQAAAE0"]
[Thu Sep 17 15:16:05.122630 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/gateway/.env"] [unique_id "aqxYlecL08BTTQixEnpjvwAAADA"]
[Thu Sep 17 15:16:05.123690 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxYlecL08BTTQixEnpjwAAAAHM"]
[Thu Sep 17 15:16:05.128606 2026] [cgid:error] [pid 971102:tid 971331] [client 66.132.172.221:5310] AH01265: stderr from /home3/sportsg2/public_html/website_3f56e26b/cgi-bin/: attempt to invoke directory as script, referer: http://mail.katcornetta.com:80/cgi-bin
[Thu Sep 17 15:16:05.143387 2026] [security2:error] [pid 971102:tid 971338] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxYlecL08BTTQixEnpjwgAAAGg"]
[Thu Sep 17 15:16:05.175946 2026] [security2:error] [pid 971102:tid 971269] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxYlecL08BTTQixEnpjxQAAACM"]
[Thu Sep 17 15:16:05.180280 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/microservice/.env"] [unique_id "aqxYlecL08BTTQixEnpjxgAAAF8"]
[Thu Sep 17 15:16:05.191264 2026] [security2:error] [pid 971102:tid 971241] [client 34.23.195.25:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpjxwAAAAc"]
[Thu Sep 17 15:16:05.206552 2026] [security2:error] [pid 971102:tid 971261] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjyQAAABs"]
[Thu Sep 17 15:16:05.224948 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjzQAAACA"]
[Thu Sep 17 15:16:05.233912 2026] [security2:error] [pid 971102:tid 971255] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/service/.env"] [unique_id "aqxYlecL08BTTQixEnpjzgAAABU"]
[Thu Sep 17 15:16:05.235682 2026] [authz_core:error] [pid 971102:tid 971251] [client 172.239.147.162:64138] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:05.244959 2026] [security2:error] [pid 971102:tid 971340] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjzwAAAGo"]
[Thu Sep 17 15:16:05.264619 2026] [security2:error] [pid 971102:tid 971260] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxYlecL08BTTQixEnpj0gAAABo"]
[Thu Sep 17 15:16:05.281374 2026] [security2:error] [pid 971102:tid 971292] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxYlecL08BTTQixEnpj1AAAADo"]
[Thu Sep 17 15:16:05.288252 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/v3/.env"] [unique_id "aqxYlecL08BTTQixEnpj1QAAAEw"]
[Thu Sep 17 15:16:05.299510 2026] [security2:error] [pid 971102:tid 971359] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxYlecL08BTTQixEnpj1gAAAH0"]
[Thu Sep 17 15:16:05.328864 2026] [security2:error] [pid 971102:tid 971322] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxYlecL08BTTQixEnpj1wAAAFg"]
[Thu Sep 17 15:16:05.349214 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxYlecL08BTTQixEnpj2AAAAEk"]
[Thu Sep 17 15:16:05.350728 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/dev/.env"] [unique_id "aqxYlecL08BTTQixEnpj2QAAAEg"]
[Thu Sep 17 15:16:05.366236 2026] [security2:error] [pid 971102:tid 971268] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxYlecL08BTTQixEnpj2gAAACI"]
[Thu Sep 17 15:16:05.378496 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.195.25:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/site/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpj2wAAAG8"]
[Thu Sep 17 15:16:05.398410 2026] [security2:error] [pid 971102:tid 971275] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxYlecL08BTTQixEnpj3AAAACk"]
[Thu Sep 17 15:16:05.414092 2026] [security2:error] [pid 971102:tid 971273] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/staging/.env"] [unique_id "aqxYlecL08BTTQixEnpj3QAAACc"]
[Thu Sep 17 15:16:05.418150 2026] [security2:error] [pid 971102:tid 971290] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxYlecL08BTTQixEnpj3gAAADg"]
[Thu Sep 17 15:16:05.443240 2026] [security2:error] [pid 971102:tid 971272] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxYlecL08BTTQixEnpj3wAAACY"]
[Thu Sep 17 15:16:05.468005 2026] [security2:error] [pid 971102:tid 971358] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxYlecL08BTTQixEnpj4AAAAHw"]
[Thu Sep 17 15:16:05.468498 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/vendor/.env"] [unique_id "aqxYlecL08BTTQixEnpj4QAAACs"]
[Thu Sep 17 15:16:05.486505 2026] [security2:error] [pid 971102:tid 971344] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxYlecL08BTTQixEnpj4gAAAG4"]
[Thu Sep 17 15:16:05.517845 2026] [security2:error] [pid 971102:tid 971294] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxYlecL08BTTQixEnpj4wAAADw"]
[Thu Sep 17 15:16:05.523931 2026] [security2:error] [pid 971102:tid 971321] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/lib/.env"] [unique_id "aqxYlecL08BTTQixEnpj5AAAAFc"]
[Thu Sep 17 15:16:05.536085 2026] [security2:error] [pid 971102:tid 971238] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxYlecL08BTTQixEnpj5gAAAAQ"]
[Thu Sep 17 15:16:05.563154 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.195.25:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpj6AAAACw"]
[Thu Sep 17 15:16:05.565164 2026] [security2:error] [pid 971102:tid 971262] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxYlecL08BTTQixEnpj6QAAABw"]
[Thu Sep 17 15:16:05.581842 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/resources/.env"] [unique_id "aqxYlecL08BTTQixEnpj6gAAAHQ"]
[Thu Sep 17 15:16:05.601637 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxYlecL08BTTQixEnpj6wAAAC4"]
[Thu Sep 17 15:16:05.623066 2026] [security2:error] [pid 971102:tid 971324] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxYlecL08BTTQixEnpj7AAAAFo"]
[Thu Sep 17 15:16:05.634919 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/assets/.env"] [unique_id "aqxYlecL08BTTQixEnpj8AAAAAE"]
[Thu Sep 17 15:16:05.645930 2026] [security2:error] [pid 971102:tid 971318] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxYlecL08BTTQixEnpj8QAAAFQ"]
[Thu Sep 17 15:16:05.662677 2026] [security2:error] [pid 971102:tid 971295] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxYlecL08BTTQixEnpj8wAAAD0"]
[Thu Sep 17 15:16:05.678463 2026] [security2:error] [pid 971102:tid 971244] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxYlecL08BTTQixEnpj9AAAAAo"]
[Thu Sep 17 15:16:05.688311 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/uploads/.env"] [unique_id "aqxYlecL08BTTQixEnpj9gAAAF4"]
[Thu Sep 17 15:16:05.722501 2026] [security2:error] [pid 971102:tid 971250] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxYlecL08BTTQixEnpj9wAAABA"]
[Thu Sep 17 15:16:05.745252 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/internal/.env"] [unique_id "aqxYlecL08BTTQixEnpj-AAAAEE"]
[Thu Sep 17 15:16:05.748597 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.195.25:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpj-QAAAAM"]
[Thu Sep 17 15:16:05.751985 2026] [security2:error] [pid 971102:tid 971245] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxYlecL08BTTQixEnpj-gAAAAs"]
[Thu Sep 17 15:16:05.776448 2026] [security2:error] [pid 971102:tid 971254] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxYlecL08BTTQixEnpj-wAAABQ"]
[Thu Sep 17 15:16:05.797402 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxYlecL08BTTQixEnpj_AAAAH8"]
[Thu Sep 17 15:16:05.809998 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/tools/.env"] [unique_id "aqxYlecL08BTTQixEnpj_QAAAD4"]
[Thu Sep 17 15:16:05.886697 2026] [security2:error] [pid 971102:tid 971342] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/scripts/.env"] [unique_id "aqxYlecL08BTTQixEnpkAgAAAGw"]
[Thu Sep 17 15:16:05.934430 2026] [security2:error] [pid 971102:tid 971302] [client 34.23.195.25:39658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpkBgAAAEQ"]
[Thu Sep 17 15:16:05.952240 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/bin/.env"] [unique_id "aqxYlecL08BTTQixEnpkBwAAAFw"]
[Thu Sep 17 15:16:05.952550 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxYlecL08BTTQixEnpkCAAAACQ"]
[Thu Sep 17 15:16:06.006954 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sbin/.env"] [unique_id "aqxYlucL08BTTQixEnpkCQAAAB8"]
[Thu Sep 17 15:16:06.026948 2026] [security2:error] [pid 971102:tid 971293] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxYlucL08BTTQixEnpkCgAAADs"]
[Thu Sep 17 15:16:06.052755 2026] [security2:error] [pid 971102:tid 971325] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxYlucL08BTTQixEnpkCwAAAFs"]
[Thu Sep 17 15:16:06.112749 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/local/.env"] [unique_id "aqxYlucL08BTTQixEnpkDAAAADM"]
[Thu Sep 17 15:16:06.116425 2026] [security2:error] [pid 971102:tid 971256] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxYlucL08BTTQixEnpkDQAAABY"]
[Thu Sep 17 15:16:06.129388 2026] [security2:error] [pid 971102:tid 971258] [client 34.23.195.25:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/core/phpinfo.php"] [unique_id "aqxYlucL08BTTQixEnpkDgAAABg"]
[Thu Sep 17 15:16:06.132550 2026] [security2:error] [pid 971102:tid 971252] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxYlucL08BTTQixEnpkDwAAABI"]
[Thu Sep 17 15:16:06.147910 2026] [security2:error] [pid 971102:tid 971332] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxYlucL08BTTQixEnpkEQAAAGI"]
[Thu Sep 17 15:16:06.163450 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxYlucL08BTTQixEnpkEgAAAFA"]
[Thu Sep 17 15:16:06.165914 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/portal/.env"] [unique_id "aqxYlucL08BTTQixEnpkEwAAAHU"]
[Thu Sep 17 15:16:06.179762 2026] [security2:error] [pid 971102:tid 971355] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxYlucL08BTTQixEnpkFAAAAHk"]
[Thu Sep 17 15:16:06.197426 2026] [security2:error] [pid 971102:tid 971282] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxYlucL08BTTQixEnpkFwAAADA"]
[Thu Sep 17 15:16:06.211821 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxYlucL08BTTQixEnpkGAAAAHM"]
[Thu Sep 17 15:16:06.224732 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/dashboard/.env"] [unique_id "aqxYlucL08BTTQixEnpkGQAAAGg"]
[Thu Sep 17 15:16:06.235646 2026] [security2:error] [pid 971102:tid 971335] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxYlucL08BTTQixEnpkGgAAAGU"]
[Thu Sep 17 15:16:06.260987 2026] [security2:error] [pid 971102:tid 971241] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxYlucL08BTTQixEnpkHAAAAAc"]
[Thu Sep 17 15:16:06.286937 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkHQAAACA"]
[Thu Sep 17 15:16:06.289480 2026] [security2:error] [pid 971102:tid 971255] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxYlucL08BTTQixEnpkHgAAABU"]
[Thu Sep 17 15:16:06.298039 2026] [security2:error] [pid 971102:tid 971269] [client 34.23.195.25:39684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxYlucL08BTTQixEnpkIAAAACM"]
[Thu Sep 17 15:16:06.306953 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxYlucL08BTTQixEnpkIQAAAAA"]
[Thu Sep 17 15:16:06.327140 2026] [security2:error] [pid 971102:tid 971260] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxYlucL08BTTQixEnpkIgAAABo"]
[Thu Sep 17 15:16:06.344159 2026] [security2:error] [pid 971102:tid 971310] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxYlucL08BTTQixEnpkJAAAAEw"]
[Thu Sep 17 15:16:06.348110 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/crm/.env"] [unique_id "aqxYlucL08BTTQixEnpkJQAAAH0"]
[Thu Sep 17 15:16:06.364142 2026] [security2:error] [pid 971102:tid 971336] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxYlucL08BTTQixEnpkJgAAAGY"]
[Thu Sep 17 15:16:06.387897 2026] [security2:error] [pid 971102:tid 971257] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxYlucL08BTTQixEnpkJwAAABc"]
[Thu Sep 17 15:16:06.415314 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxYlucL08BTTQixEnpkKAAAAEk"]
[Thu Sep 17 15:16:06.415462 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/erp/.env"] [unique_id "aqxYlucL08BTTQixEnpkKQAAAEg"]
[Thu Sep 17 15:16:06.442450 2026] [security2:error] [pid 971102:tid 971249] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxYlucL08BTTQixEnpkKgAAAA8"]
[Thu Sep 17 15:16:06.465648 2026] [security2:error] [pid 971102:tid 971283] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxYlucL08BTTQixEnpkKwAAADE"]
[Thu Sep 17 15:16:06.467418 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.121:35398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxYlucL08BTTQixEnpkLAAAAG8"]
[Thu Sep 17 15:16:06.480954 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/shop/.env"] [unique_id "aqxYlucL08BTTQixEnpkLgAAACk"]
[Thu Sep 17 15:16:06.483075 2026] [security2:error] [pid 971102:tid 971273] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxYlucL08BTTQixEnpkLwAAACc"]
[Thu Sep 17 15:16:06.505924 2026] [security2:error] [pid 971102:tid 971272] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxYlucL08BTTQixEnpkMgAAACY"]
[Thu Sep 17 15:16:06.521707 2026] [security2:error] [pid 971102:tid 971277] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxYlucL08BTTQixEnpkMwAAACs"]
[Thu Sep 17 15:16:06.535837 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/store/.env"] [unique_id "aqxYlucL08BTTQixEnpkNAAAAG4"]
[Thu Sep 17 15:16:06.538809 2026] [security2:error] [pid 971102:tid 971294] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxYlucL08BTTQixEnpkNQAAADw"]
[Thu Sep 17 15:16:06.555419 2026] [security2:error] [pid 971102:tid 971238] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxYlucL08BTTQixEnpkNwAAAAQ"]
[Thu Sep 17 15:16:06.603046 2026] [security2:error] [pid 971102:tid 971288] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxYlucL08BTTQixEnpkOAAAADY"]
[Thu Sep 17 15:16:06.604827 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/saas/.env"] [unique_id "aqxYlucL08BTTQixEnpkOQAAAFY"]
[Thu Sep 17 15:16:06.631067 2026] [security2:error] [pid 971102:tid 971350] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxYlucL08BTTQixEnpkPQAAAHQ"]
[Thu Sep 17 15:16:06.658515 2026] [security2:error] [pid 971102:tid 971341] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxYlucL08BTTQixEnpkQAAAAGs"]
[Thu Sep 17 15:16:06.675374 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/client/.env"] [unique_id "aqxYlucL08BTTQixEnpkQgAAAB0"]
[Thu Sep 17 15:16:06.701791 2026] [security2:error] [pid 971102:tid 971353] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxYlucL08BTTQixEnpkRQAAAHc"]
[Thu Sep 17 15:16:06.723542 2026] [security2:error] [pid 971102:tid 971316] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxYlucL08BTTQixEnpkSAAAAFI"]
[Thu Sep 17 15:16:06.748343 2026] [security2:error] [pid 971102:tid 971286] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxYlucL08BTTQixEnpkSgAAADQ"]
[Thu Sep 17 15:16:06.750882 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/project/.env"] [unique_id "aqxYlucL08BTTQixEnpkSwAAAF4"]
[Thu Sep 17 15:16:06.769588 2026] [security2:error] [pid 971102:tid 971250] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxYlucL08BTTQixEnpkTAAAABA"]
[Thu Sep 17 15:16:06.792471 2026] [security2:error] [pid 971102:tid 971237] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxYlucL08BTTQixEnpkTgAAAAM"]
[Thu Sep 17 15:16:06.803858 2026] [security2:error] [pid 971102:tid 971361] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/admin-panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkUAAAAH8"]
[Thu Sep 17 15:16:06.819952 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxYlucL08BTTQixEnpkUQAAAD4"]
[Thu Sep 17 15:16:06.831513 2026] [security2:error] [pid 971102:tid 971337] [client 143.244.57.121:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seattleboating.interlinck.com"] [uri "/xmlrpc.php"] [unique_id "aqxYlucL08BTTQixEnpkUgAAAGc"]
[Thu Sep 17 15:16:06.840481 2026] [security2:error] [pid 971102:tid 971239] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxYlucL08BTTQixEnpkUwAAAAU"]
[Thu Sep 17 15:16:06.857786 2026] [security2:error] [pid 971102:tid 971334] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxYlucL08BTTQixEnpkVQAAAGQ"]
[Thu Sep 17 15:16:06.857786 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/control-panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkVAAAAGk"]
[Thu Sep 17 15:16:06.883652 2026] [security2:error] [pid 971102:tid 971243] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxYlucL08BTTQixEnpkWgAAAAk"]
[Thu Sep 17 15:16:06.904890 2026] [security2:error] [pid 971102:tid 971357] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxYlucL08BTTQixEnpkXAAAAHs"]
[Thu Sep 17 15:16:06.919684 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/user-panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkXwAAABM"]
[Thu Sep 17 15:16:06.921433 2026] [security2:error] [pid 971102:tid 971360] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxYlucL08BTTQixEnpkYAAAAH4"]
[Thu Sep 17 15:16:06.951455 2026] [security2:error] [pid 971102:tid 971312] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxYlucL08BTTQixEnpkYQAAAE4"]
[Thu Sep 17 15:16:06.975334 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/node/.env"] [unique_id "aqxYlucL08BTTQixEnpkYwAAAFw"]
[Thu Sep 17 15:16:06.985805 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxYlucL08BTTQixEnpkZAAAACQ"]
[Thu Sep 17 15:16:07.025403 2026] [security2:error] [pid 971102:tid 971287] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxYl-cL08BTTQixEnpkZgAAADU"]
[Thu Sep 17 15:16:07.028675 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/express/.env"] [unique_id "aqxYl-cL08BTTQixEnpkZwAAAEI"]
[Thu Sep 17 15:16:07.055761 2026] [security2:error] [pid 971102:tid 971325] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxYl-cL08BTTQixEnpkawAAAFs"]
[Thu Sep 17 15:16:07.076156 2026] [security2:error] [pid 971102:tid 971256] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxYl-cL08BTTQixEnpkbQAAABY"]
[Thu Sep 17 15:16:07.081810 2026] [security2:error] [pid 971102:tid 971252] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/next/.env"] [unique_id "aqxYl-cL08BTTQixEnpkbwAAABI"]
[Thu Sep 17 15:16:07.103545 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxYl-cL08BTTQixEnpkcgAAAFA"]
[Thu Sep 17 15:16:07.120812 2026] [security2:error] [pid 971102:tid 971259] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxYl-cL08BTTQixEnpkdAAAABk"]
[Thu Sep 17 15:16:07.140919 2026] [security2:error] [pid 971102:tid 971335] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxYl-cL08BTTQixEnpkeAAAAGU"]
[Thu Sep 17 15:16:07.140920 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/nuxt/.env"] [unique_id "aqxYl-cL08BTTQixEnpkdwAAAGg"]
[Thu Sep 17 15:16:07.158175 2026] [security2:error] [pid 971102:tid 971340] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxYl-cL08BTTQixEnpkfAAAAGo"]
[Thu Sep 17 15:16:07.182783 2026] [security2:error] [pid 971102:tid 971269] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxYl-cL08BTTQixEnpkfQAAACM"]
[Thu Sep 17 15:16:07.195389 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/nest/.env"] [unique_id "aqxYl-cL08BTTQixEnpkfgAAAAA"]
[Thu Sep 17 15:16:07.205791 2026] [security2:error] [pid 971102:tid 971261] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxYl-cL08BTTQixEnpkgAAAABs"]
[Thu Sep 17 15:16:07.228344 2026] [security2:error] [pid 971102:tid 971310] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxYl-cL08BTTQixEnpkggAAAEw"]
[Thu Sep 17 15:16:07.252359 2026] [security2:error] [pid 971102:tid 971274] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxYl-cL08BTTQixEnpkhAAAACg"]
[Thu Sep 17 15:16:07.255590 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/react/.env"] [unique_id "aqxYl-cL08BTTQixEnpkhgAAABc"]
[Thu Sep 17 15:16:07.267174 2026] [security2:error] [pid 971102:tid 971311] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxYl-cL08BTTQixEnpkiAAAAE0"]
[Thu Sep 17 15:16:07.268149 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.121:35412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxYl-cL08BTTQixEnpkiQAAAAw"]
[Thu Sep 17 15:16:07.284040 2026] [security2:error] [pid 971102:tid 971322] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxYl-cL08BTTQixEnpkigAAAFg"]
[Thu Sep 17 15:16:07.313859 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/vue/.env"] [unique_id "aqxYl-cL08BTTQixEnpkiwAAAEk"]
[Thu Sep 17 15:16:07.314183 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjAAAAEg"]
[Thu Sep 17 15:16:07.342029 2026] [security2:error] [pid 971102:tid 971345] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjQAAAG8"]
[Thu Sep 17 15:16:07.367548 2026] [security2:error] [pid 971102:tid 971275] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjgAAACk"]
[Thu Sep 17 15:16:07.371061 2026] [security2:error] [pid 971102:tid 971273] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/angular/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjwAAACc"]
[Thu Sep 17 15:16:07.383312 2026] [security2:error] [pid 971102:tid 971251] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkAAAABE"]
[Thu Sep 17 15:16:07.407946 2026] [security2:error] [pid 971102:tid 971272] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkQAAACY"]
[Thu Sep 17 15:16:07.425611 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/svelte/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkgAAAG4"]
[Thu Sep 17 15:16:07.427358 2026] [security2:error] [pid 971102:tid 971294] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkwAAADw"]
[Thu Sep 17 15:16:07.466843 2026] [security2:error] [pid 971102:tid 971238] [client 34.94.22.173:41858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php"] [unique_id "aqxYl-cL08BTTQixEnpklgAAAAQ"]
[Thu Sep 17 15:16:07.480215 2026] [security2:error] [pid 971102:tid 971301] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/vite/.env"] [unique_id "aqxYl-cL08BTTQixEnpkmAAAAEM"]
[Thu Sep 17 15:16:07.534908 2026] [security2:error] [pid 971102:tid 971244] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/backup/.env"] [unique_id "aqxYl-cL08BTTQixEnpkmgAAAAo"]
[Thu Sep 17 15:16:07.542963 2026] [security2:error] [pid 971102:tid 971263] [client 34.94.22.173:41864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/info.php"] [unique_id "aqxYl-cL08BTTQixEnpkngAAAB0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:16:07.606160 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/backups/.env"] [unique_id "aqxYl-cL08BTTQixEnpkoAAAAAs"]
[Thu Sep 17 15:16:07.636116 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.121:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxYl-cL08BTTQixEnpkpAAAAD4"]
[Thu Sep 17 15:16:07.649723 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:41872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/php.php"] [unique_id "aqxYl-cL08BTTQixEnpkpwAAAH8"]
[Thu Sep 17 15:16:07.659359 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/old/.env"] [unique_id "aqxYl-cL08BTTQixEnpkqQAAAGQ"]
[Thu Sep 17 15:16:07.715222 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.22.173:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/i.php"] [unique_id "aqxYl-cL08BTTQixEnpkqgAAAHE"]
[Thu Sep 17 15:16:07.723200 2026] [security2:error] [pid 971102:tid 971346] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/tmp/.env"] [unique_id "aqxYl-cL08BTTQixEnpkqwAAAHA"]
[Thu Sep 17 15:16:07.778534 2026] [security2:error] [pid 971102:tid 971247] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/temp/.env"] [unique_id "aqxYl-cL08BTTQixEnpkrQAAAA0"]
[Thu Sep 17 15:16:07.800796 2026] [security2:error] [pid 971102:tid 971235] [client 34.94.22.173:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/pi.php"] [unique_id "aqxYl-cL08BTTQixEnpkrgAAAAE"]
[Thu Sep 17 15:16:07.834630 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/lab/.env"] [unique_id "aqxYl-cL08BTTQixEnpkrwAAAAY"]
[Thu Sep 17 15:16:07.860918 2026] [security2:error] [pid 971102:tid 971289] [client 172.239.147.162:63903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxYl-cL08BTTQixEnpksAAAADc"], referer: binance.com
[Thu Sep 17 15:16:07.895020 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cronlab/.env"] [unique_id "aqxYl-cL08BTTQixEnpksQAAAE4"]
[Thu Sep 17 15:16:07.900195 2026] [security2:error] [pid 971102:tid 971279] [client 34.94.22.173:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/pinfo.php"] [unique_id "aqxYl-cL08BTTQixEnpksgAAAC0"]
[Thu Sep 17 15:16:07.912752 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.121:35428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxYl-cL08BTTQixEnpkswAAAEQ"]
[Thu Sep 17 15:16:07.951065 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cron/.env"] [unique_id "aqxYl-cL08BTTQixEnpktQAAADU"]
[Thu Sep 17 15:16:07.979988 2026] [security2:error] [pid 971102:tid 971319] [client 34.94.22.173:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/test.php"] [unique_id "aqxYl-cL08BTTQixEnpktgAAAFU"]
[Thu Sep 17 15:16:08.006387 2026] [security2:error] [pid 971102:tid 971293] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/en/.env"] [unique_id "aqxYmOcL08BTTQixEnpktwAAADs"]
[Thu Sep 17 15:16:08.093861 2026] [security2:error] [pid 971102:tid 971269] [client 34.94.22.173:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/p.php"] [unique_id "aqxYmOcL08BTTQixEnpkwQAAACM"]
[Thu Sep 17 15:16:08.118395 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/administrator/.env"] [unique_id "aqxYmOcL08BTTQixEnpkuwAAAGI"]
[Thu Sep 17 15:16:08.174814 2026] [security2:error] [pid 971102:tid 971359] [client 34.94.22.173:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/debug.php"] [unique_id "aqxYmOcL08BTTQixEnpkxgAAAH0"]
[Thu Sep 17 15:16:08.179593 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/psnlink/.env"] [unique_id "aqxYmOcL08BTTQixEnpkxwAAABc"]
[Thu Sep 17 15:16:08.206551 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.121:35436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmOcL08BTTQixEnpkyAAAAE0"]
[Thu Sep 17 15:16:08.236287 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/exapi/.env"] [unique_id "aqxYmOcL08BTTQixEnpkyQAAAB8"]
[Thu Sep 17 15:16:08.244635 2026] [security2:error] [pid 971102:tid 971246] [client 34.94.22.173:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpkygAAAAw"]
[Thu Sep 17 15:16:08.290893 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sitemaps/.env"] [unique_id "aqxYmOcL08BTTQixEnpkywAAAFg"]
[Thu Sep 17 15:16:08.295633 2026] [security2:error] [pid 971102:tid 971340] [client 185.55.149.49:55636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpkzAAAAGo"]
[Thu Sep 17 15:16:08.295732 2026] [security2:error] [pid 971102:tid 971340] [client 185.55.149.49:55636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpkzAAAAGo"]
[Thu Sep 17 15:16:08.364197 2026] [security2:error] [pid 971102:tid 971295] [client 34.94.22.173:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/test/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk0AAAAD0"]
[Thu Sep 17 15:16:08.461386 2026] [security2:error] [pid 971102:tid 971343] [client 34.94.22.173:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/dev/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk1AAAAG0"]
[Thu Sep 17 15:16:08.499953 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.121:35448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmOcL08BTTQixEnpk1wAAAAQ"]
[Thu Sep 17 15:16:08.537611 2026] [security2:error] [pid 971102:tid 971356] [client 162.241.226.11:56808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "caninecompanionsltd.org"] [uri "/index.php"] [unique_id "aqxYmOcL08BTTQixEnpkzQAAAHo"]
[Thu Sep 17 15:16:08.540565 2026] [security2:error] [pid 971102:tid 971320] [client 34.94.22.173:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/old/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk2AAAAFY"]
[Thu Sep 17 15:16:08.607502 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:22735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpk2wAAACg"]
[Thu Sep 17 15:16:08.607682 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:22735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpk2wAAACg"]
[Thu Sep 17 15:16:08.621824 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/logs/.env"] [unique_id "aqxYmOcL08BTTQixEnpk3AAAAB4"]
[Thu Sep 17 15:16:08.626528 2026] [security2:error] [pid 971102:tid 971351] [client 34.94.22.173:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk3QAAAHU"]
[Thu Sep 17 15:16:08.682634 2026] [security2:error] [pid 971102:tid 971331] [client 20.244.34.24:50883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "airmacinc.com"] [uri "/index.php"] [unique_id "aqxYmOcL08BTTQixEnpk3gAAAGE"], referer: binance.com
[Thu Sep 17 15:16:08.684914 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cache/.env"] [unique_id "aqxYmOcL08BTTQixEnpk4QAAAB0"]
[Thu Sep 17 15:16:08.704248 2026] [security2:error] [pid 971102:tid 971329] [client 34.94.22.173:41968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/public/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk4wAAAF8"]
[Thu Sep 17 15:16:08.748005 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailer/.env"] [unique_id "aqxYmOcL08BTTQixEnpk5AAAAFo"]
[Thu Sep 17 15:16:08.765117 2026] [security2:error] [pid 971102:tid 971341] [client 162.241.226.11:56824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "caninecompanionsltd.org"] [uri "/index.php"] [unique_id "aqxYmOcL08BTTQixEnpk2gAAAGs"]
[Thu Sep 17 15:16:08.807135 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.121:35450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmOcL08BTTQixEnpk5wAAAD4"]
[Thu Sep 17 15:16:08.809934 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mail/.env"] [unique_id "aqxYmOcL08BTTQixEnpk6AAAAAM"]
[Thu Sep 17 15:16:08.879809 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/email/.env"] [unique_id "aqxYmOcL08BTTQixEnpk6gAAAC4"]
[Thu Sep 17 15:16:08.881328 2026] [security2:error] [pid 971102:tid 971284] [client 34.94.22.173:41984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/php-info.php"] [unique_id "aqxYmOcL08BTTQixEnpk6wAAADI"]
[Thu Sep 17 15:16:08.895132 2026] [security2:error] [pid 971102:tid 971291] [client 157.85.210.148:3962] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.sqlerudition.com"] [uri "/wp-content/plugins/give/readme.txt"] [unique_id "aqxYmOcL08BTTQixEnpk7AAAADk"]
[Thu Sep 17 15:16:08.944339 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/smtp/.env"] [unique_id "aqxYmOcL08BTTQixEnpk7wAAAAE"]
[Thu Sep 17 15:16:08.951854 2026] [security2:error] [pid 971102:tid 971247] [client 34.94.22.173:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpversion.php"] [unique_id "aqxYmOcL08BTTQixEnpk8AAAAA0"]
[Thu Sep 17 15:16:08.985151 2026] [security2:error] [pid 971102:tid 971240] [client 5.189.145.112:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxYmOcL08BTTQixEnpk8gAAAAY"], referer: binance.com
[Thu Sep 17 15:16:08.999217 2026] [security2:error] [pid 971102:tid 971271] [client 34.94.22.173:42006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/_phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk8wAAACU"]
[Thu Sep 17 15:16:09.007035 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailing/.env"] [unique_id "aqxYmecL08BTTQixEnpk9AAAAE8"]
[Thu Sep 17 15:16:09.066896 2026] [security2:error] [pid 971102:tid 971289] [client 34.94.22.173:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/old_phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnpk9QAAADc"]
[Thu Sep 17 15:16:09.078269 2026] [security2:error] [pid 971102:tid 971268] [client 102.178.123.34:36558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYmOcL08BTTQixEnpk8QAAIk8"]
[Thu Sep 17 15:16:09.103236 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.121:35466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmecL08BTTQixEnpk9gAAAEQ"]
[Thu Sep 17 15:16:09.164713 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:42038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/server-info.php"] [unique_id "aqxYmecL08BTTQixEnpk-QAAACQ"]
[Thu Sep 17 15:16:09.243437 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/notifications/.env"] [unique_id "aqxYmecL08BTTQixEnpk-gAAAFU"]
[Thu Sep 17 15:16:09.247097 2026] [security2:error] [pid 971102:tid 971252] [client 34.94.22.173:42048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/server-status.php"] [unique_id "aqxYmecL08BTTQixEnpk-wAAABI"]
[Thu Sep 17 15:16:09.278332 2026] [security2:error] [pid 971102:tid 971242] [client 172.239.147.162:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxYmecL08BTTQixEnpk_AAAAAg"], referer: binance.com
[Thu Sep 17 15:16:09.297596 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/notify/.env"] [unique_id "aqxYmecL08BTTQixEnpk_gAAAGg"]
[Thu Sep 17 15:16:09.369238 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sender/.env"] [unique_id "aqxYmecL08BTTQixEnpk_wAAABo"]
[Thu Sep 17 15:16:09.413483 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.121:35472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmecL08BTTQixEnplAwAAABc"]
[Thu Sep 17 15:16:09.445820 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/campaign/.env"] [unique_id "aqxYmecL08BTTQixEnplBQAAADE"]
[Thu Sep 17 15:16:09.459753 2026] [security2:error] [pid 971102:tid 971265] [client 157.85.210.148:6520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.210.85.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/wp-content/plugins/give/give.php"] [unique_id "aqxYmecL08BTTQixEnplBgAAAB8"]
[Thu Sep 17 15:16:09.512276 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/newsletter/.env"] [unique_id "aqxYmecL08BTTQixEnplCgAAAEg"]
[Thu Sep 17 15:16:09.517558 2026] [security2:error] [pid 971102:tid 971261] [client 34.94.22.173:42050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYmecL08BTTQixEnplCwAAABs"]
[Thu Sep 17 15:16:09.568147 2026] [security2:error] [pid 971102:tid 971321] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/ses/.env"] [unique_id "aqxYmecL08BTTQixEnplDAAAAFc"]
[Thu Sep 17 15:16:09.616239 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.22.173:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/mail/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplDwAAAD4"]
[Thu Sep 17 15:16:09.630949 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sendgrid/.env"] [unique_id "aqxYmecL08BTTQixEnplEAAAACs"]
[Thu Sep 17 15:16:09.688894 2026] [security2:error] [pid 971102:tid 971249] [client 45.115.26.203:48766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env"] [unique_id "aqxYmecL08BTTQixEnplFgAAAA8"]
[Thu Sep 17 15:16:09.689040 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sparkpost/.env"] [unique_id "aqxYmecL08BTTQixEnplFwAAAHE"]
[Thu Sep 17 15:16:09.689600 2026] [security2:error] [pid 971102:tid 971323] [client 34.94.22.173:42068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplGAAAAFk"]
[Thu Sep 17 15:16:09.710564 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.121:35488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmecL08BTTQixEnplHAAAAHA"]
[Thu Sep 17 15:16:09.730669 2026] [security2:error] [pid 971102:tid 971275] [client 45.115.26.203:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplIQAAACk"]
[Thu Sep 17 15:16:09.730687 2026] [security2:error] [pid 971102:tid 971294] [client 45.115.26.203:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/_phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplHQAAADw"]
[Thu Sep 17 15:16:09.730726 2026] [security2:error] [pid 971102:tid 971292] [client 45.115.26.203:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/i.php"] [unique_id "aqxYmecL08BTTQixEnplHwAAADo"]
[Thu Sep 17 15:16:09.730752 2026] [security2:error] [pid 971102:tid 971272] [client 45.115.26.203:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/php_info.php"] [unique_id "aqxYmecL08BTTQixEnplIwAAACY"]
[Thu Sep 17 15:16:09.731845 2026] [security2:error] [pid 971102:tid 971345] [client 45.115.26.203:48970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/app/.env"] [unique_id "aqxYmecL08BTTQixEnplIgAAAG8"]
[Thu Sep 17 15:16:09.732021 2026] [security2:error] [pid 971102:tid 971266] [client 45.115.26.203:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/info.php"] [unique_id "aqxYmecL08BTTQixEnplJQAAACA"]
[Thu Sep 17 15:16:09.732313 2026] [security2:error] [pid 971102:tid 971290] [client 45.115.26.203:48954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/backend/.env"] [unique_id "aqxYmecL08BTTQixEnplJgAAADg"]
[Thu Sep 17 15:16:09.735169 2026] [security2:error] [pid 971102:tid 971344] [client 45.115.26.203:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/pi.php"] [unique_id "aqxYmecL08BTTQixEnplKAAAAG4"]
[Thu Sep 17 15:16:09.735762 2026] [security2:error] [pid 971102:tid 971295] [client 45.115.26.203:48900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.backup"] [unique_id "aqxYmecL08BTTQixEnplKQAAAD0"]
[Thu Sep 17 15:16:09.743577 2026] [security2:error] [pid 971102:tid 971250] [client 45.115.26.203:48966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/api/.env"] [unique_id "aqxYmecL08BTTQixEnplMgAAABA"]
[Thu Sep 17 15:16:09.743692 2026] [security2:error] [pid 971102:tid 971288] [client 45.115.26.203:48974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/src/.env"] [unique_id "aqxYmecL08BTTQixEnplOAAAADY"]
[Thu Sep 17 15:16:09.743813 2026] [security2:error] [pid 971102:tid 971301] [client 45.115.26.203:48790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env"] [unique_id "aqxYmecL08BTTQixEnplNgAAAEM"]
[Thu Sep 17 15:16:09.744037 2026] [security2:error] [pid 971102:tid 971308] [client 45.115.26.203:48938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.swp"] [unique_id "aqxYmecL08BTTQixEnplNwAAAEo"]
[Thu Sep 17 15:16:09.744161 2026] [security2:error] [pid 971102:tid 971351] [client 45.115.26.203:48934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env~"] [unique_id "aqxYmecL08BTTQixEnplOgAAAHU"]
[Thu Sep 17 15:16:09.744203 2026] [security2:error] [pid 971102:tid 971263] [client 45.115.26.203:48906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.bak"] [unique_id "aqxYmecL08BTTQixEnplNQAAAB0"]
[Thu Sep 17 15:16:09.746206 2026] [security2:error] [pid 971102:tid 971264] [client 45.115.26.203:48912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.old"] [unique_id "aqxYmecL08BTTQixEnplOwAAAB4"]
[Thu Sep 17 15:16:09.750841 2026] [security2:error] [pid 971102:tid 971353] [client 34.94.22.173:42080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplPgAAAHc"]
[Thu Sep 17 15:16:09.758787 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/postmark/.env"] [unique_id "aqxYmecL08BTTQixEnplPwAAAHg"]
[Thu Sep 17 15:16:09.785511 2026] [security2:error] [pid 971102:tid 971361] [client 45.115.26.203:49058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/test.php"] [unique_id "aqxYmecL08BTTQixEnplQQAAAH8"]
[Thu Sep 17 15:16:09.788472 2026] [security2:error] [pid 971102:tid 971358] [client 45.115.26.203:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/php-info.php"] [unique_id "aqxYmecL08BTTQixEnplQgAAAHw"]
[Thu Sep 17 15:16:09.806346 2026] [security2:error] [pid 971102:tid 971237] [client 172.239.147.162:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxYmecL08BTTQixEnplQwAAAAM"], referer: binance.com
[Thu Sep 17 15:16:09.819296 2026] [security2:error] [pid 971102:tid 971247] [client 34.94.22.173:42088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplRAAAAA0"]
[Thu Sep 17 15:16:09.824862 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailgun/.env"] [unique_id "aqxYmecL08BTTQixEnplRQAAAAY"]
[Thu Sep 17 15:16:09.888496 2026] [security2:error] [pid 971102:tid 971302] [client 34.94.22.173:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplSQAAAEQ"]
[Thu Sep 17 15:16:09.889342 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mandrill/.env"] [unique_id "aqxYmecL08BTTQixEnplSAAAAFA"]
[Thu Sep 17 15:16:09.946176 2026] [security2:error] [pid 971102:tid 971276] [client 34.94.22.173:42108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php.bak"] [unique_id "aqxYmecL08BTTQixEnplTAAAACo"]
[Thu Sep 17 15:16:09.949355 2026] [security2:error] [pid 971102:tid 971323] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailjet/.env"] [unique_id "aqxYmecL08BTTQixEnplTQAAAFk"]
[Thu Sep 17 15:16:09.955856 2026] [security2:error] [pid 971102:tid 971322] [client 186.105.232.15:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmecL08BTTQixEnplSwAAAFg"]
[Thu Sep 17 15:16:09.955957 2026] [security2:error] [pid 971102:tid 971322] [client 186.105.232.15:50326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmecL08BTTQixEnplSwAAAFg"]
[Thu Sep 17 15:16:10.001560 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.121:35504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplUQAAADo"]
[Thu Sep 17 15:16:10.005513 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.22.173:42120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php.old"] [unique_id "aqxYmucL08BTTQixEnplUgAAAC4"]
[Thu Sep 17 15:16:10.014915 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/brevo/.env"] [unique_id "aqxYmucL08BTTQixEnplUwAAACk"]
[Thu Sep 17 15:16:10.076852 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/transactional/.env"] [unique_id "aqxYmucL08BTTQixEnplVQAAAG8"]
[Thu Sep 17 15:16:10.089592 2026] [security2:error] [pid 971102:tid 971284] [client 34.94.22.173:42128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php~"] [unique_id "aqxYmucL08BTTQixEnplVgAAADI"]
[Thu Sep 17 15:16:10.139117 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/bulk/.env"] [unique_id "aqxYmucL08BTTQixEnplVwAAAFY"]
[Thu Sep 17 15:16:10.158583 2026] [access_compat:error] [pid 971102:tid 971350] [client 45.115.26.203:49114] AH01797: client denied by server configuration: /home3/mikemil2/public_html/server-status
[Thu Sep 17 15:16:10.183173 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/info.php.bak"] [unique_id "aqxYmucL08BTTQixEnplXQAAAHM"]
[Thu Sep 17 15:16:10.196005 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/aws/.env"] [unique_id "aqxYmucL08BTTQixEnplXgAAAFM"]
[Thu Sep 17 15:16:10.252305 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/azure/.env"] [unique_id "aqxYmucL08BTTQixEnplXwAAAEo"]
[Thu Sep 17 15:16:10.260775 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:42156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php.save"] [unique_id "aqxYmucL08BTTQixEnplYAAAAEM"]
[Thu Sep 17 15:16:10.278814 2026] [security2:error] [pid 971102:tid 971344] [client 45.169.98.18:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmucL08BTTQixEnplYQAAAG4"]
[Thu Sep 17 15:16:10.278906 2026] [security2:error] [pid 971102:tid 971344] [client 45.169.98.18:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmucL08BTTQixEnplYQAAAG4"]
[Thu Sep 17 15:16:10.310494 2026] [security2:error] [pid 971102:tid 971331] [client 143.244.57.121:43626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplYgAAAGE"]
[Thu Sep 17 15:16:10.320918 2026] [security2:error] [pid 971102:tid 971262] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/gcp/.env"] [unique_id "aqxYmucL08BTTQixEnplYwAAABw"]
[Thu Sep 17 15:16:10.342458 2026] [security2:error] [pid 971102:tid 971264] [client 34.94.22.173:42162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/staging/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplZQAAAB4"]
[Thu Sep 17 15:16:10.393306 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cloud/.env"] [unique_id "aqxYmucL08BTTQixEnplaQAAABY"]
[Thu Sep 17 15:16:10.409270 2026] [security2:error] [pid 971102:tid 971358] [client 34.94.22.173:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/beta/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplagAAAHw"]
[Thu Sep 17 15:16:10.450179 2026] [security2:error] [pid 971102:tid 971240] [client 192.178.6.3:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYmucL08BTTQixEnplawAAAAY"]
[Thu Sep 17 15:16:10.458151 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/infrastructure/.env"] [unique_id "aqxYmucL08BTTQixEnplbAAAAE8"]
[Thu Sep 17 15:16:10.468654 2026] [security2:error] [pid 971102:tid 971271] [client 34.94.22.173:42176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/uat/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplbgAAACU"]
[Thu Sep 17 15:16:10.529713 2026] [security2:error] [pid 971102:tid 971289] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/docker/.env"] [unique_id "aqxYmucL08BTTQixEnplbwAAADc"]
[Thu Sep 17 15:16:10.565897 2026] [security2:error] [pid 971102:tid 971303] [client 34.94.22.173:42178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/qa/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplcAAAAEU"]
[Thu Sep 17 15:16:10.589161 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/k8s/.env"] [unique_id "aqxYmucL08BTTQixEnplcQAAAE4"]
[Thu Sep 17 15:16:10.615986 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.121:43636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplcwAAAEI"]
[Thu Sep 17 15:16:10.654961 2026] [security2:error] [pid 971102:tid 971242] [client 34.94.22.173:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/preview/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnpleAAAAAg"]
[Thu Sep 17 15:16:10.678788 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/kubernetes/.env"] [unique_id "aqxYmucL08BTTQixEnplewAAABo"]
[Thu Sep 17 15:16:10.739186 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/terraform/.env"] [unique_id "aqxYmucL08BTTQixEnplfAAAAGI"]
[Thu Sep 17 15:16:10.753061 2026] [security2:error] [pid 971102:tid 971254] [client 34.94.22.173:42198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/www/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplfQAAABQ"]
[Thu Sep 17 15:16:10.804215 2026] [security2:error] [pid 971102:tid 971327] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/ansible/.env"] [unique_id "aqxYmucL08BTTQixEnplfgAAAF0"]
[Thu Sep 17 15:16:10.841216 2026] [security2:error] [pid 971102:tid 971283] [client 34.94.22.173:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplfwAAADE"]
[Thu Sep 17 15:16:10.894207 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.git/.env"] [unique_id "aqxYmucL08BTTQixEnplgwAAAFE"]
[Thu Sep 17 15:16:10.916813 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.121:43644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplhQAAAEg"]
[Thu Sep 17 15:16:10.930186 2026] [security2:error] [pid 971102:tid 971246] [client 34.94.22.173:42218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplhgAAAAw"]
[Thu Sep 17 15:16:10.959019 2026] [security2:error] [pid 971102:tid 971281] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/ci/.env"] [unique_id "aqxYmucL08BTTQixEnplhwAAAC8"]
[Thu Sep 17 15:16:11.012149 2026] [security2:error] [pid 971102:tid 971321] [client 34.94.22.173:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/site/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnpliAAAAFc"]
[Thu Sep 17 15:16:11.018295 2026] [security2:error] [pid 971102:tid 971328] [client 172.239.147.162:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxYm-cL08BTTQixEnpliQAAAF4"], referer: binance.com
[Thu Sep 17 15:16:11.019794 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cd/.env"] [unique_id "aqxYm-cL08BTTQixEnpligAAAGQ"]
[Thu Sep 17 15:16:11.082554 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/jenkins/.env"] [unique_id "aqxYm-cL08BTTQixEnpliwAAAA8"]
[Thu Sep 17 15:16:11.122037 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.22.173:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/docs/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnpljAAAAHE"]
[Thu Sep 17 15:16:11.141501 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/gitlab/.env"] [unique_id "aqxYm-cL08BTTQixEnpljwAAAFg"]
[Thu Sep 17 15:16:11.172780 2026] [security2:error] [pid 971102:tid 971343] [client 114.198.138.124:54587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplkQAAAG0"]
[Thu Sep 17 15:16:11.172873 2026] [security2:error] [pid 971102:tid 971343] [client 114.198.138.124:54587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplkQAAAG0"]
[Thu Sep 17 15:16:11.210038 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.121:43652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxYm-cL08BTTQixEnplkgAAADo"]
[Thu Sep 17 15:16:11.211979 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/github/.env"] [unique_id "aqxYm-cL08BTTQixEnplkwAAAC4"]
[Thu Sep 17 15:16:11.216766 2026] [security2:error] [pid 971102:tid 971243] [client 34.94.22.173:42252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnpllQAAAAk"]
[Thu Sep 17 15:16:11.274161 2026] [security2:error] [pid 971102:tid 971284] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/actions/.env"] [unique_id "aqxYm-cL08BTTQixEnpllgAAADI"]
[Thu Sep 17 15:16:11.295501 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.22.173:42266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnplmAAAACA"]
[Thu Sep 17 15:16:11.335099 2026] [security2:error] [pid 971102:tid 971310] [client 154.190.208.131:41682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplmQAAAEw"]
[Thu Sep 17 15:16:11.339521 2026] [security2:error] [pid 971102:tid 971310] [client 154.190.208.131:41682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplmQAAAEw"]
[Thu Sep 17 15:16:11.340469 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/circleci/.env"] [unique_id "aqxYm-cL08BTTQixEnplmwAAAHQ"]
[Thu Sep 17 15:16:11.373326 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:42278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/core/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnplnAAAAHM"]
[Thu Sep 17 15:16:11.399298 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/travis/.env"] [unique_id "aqxYm-cL08BTTQixEnplnQAAADY"]
[Thu Sep 17 15:16:11.444300 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.22.173:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/includes/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnploQAAAAA"]
[Thu Sep 17 15:16:11.464727 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/buildkite/.env"] [unique_id "aqxYm-cL08BTTQixEnplowAAAHU"]
[Thu Sep 17 15:16:11.500614 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.121:43660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxYm-cL08BTTQixEnplpAAAAHc"]
[Thu Sep 17 15:16:11.523223 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mysql/.env"] [unique_id "aqxYm-cL08BTTQixEnplpwAAACw"]
[Thu Sep 17 15:16:11.602949 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/postgres/.env"] [unique_id "aqxYm-cL08BTTQixEnplrAAAABY"]
[Thu Sep 17 15:16:11.671363 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mongodb/.env"] [unique_id "aqxYm-cL08BTTQixEnplsQAAAAM"]
[Thu Sep 17 15:16:11.760112 2026] [security2:error] [pid 971102:tid 971289] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/redis/.env"] [unique_id "aqxYm-cL08BTTQixEnpltwAAADc"]
[Thu Sep 17 15:16:11.845416 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/elasticsearch/.env"] [unique_id "aqxYm-cL08BTTQixEnplvgAAACQ"]
[Thu Sep 17 15:16:11.886023 2026] [security2:error] [pid 971102:tid 971303] [client 91.73.4.138:58849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYm-cL08BTTQixEnpluQAARWA"]
[Thu Sep 17 15:16:11.911863 2026] [security2:error] [pid 971102:tid 971286] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/rabbitmq/.env"] [unique_id "aqxYm-cL08BTTQixEnplwQAAADQ"]
[Thu Sep 17 15:16:11.977640 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/kafka/.env"] [unique_id "aqxYm-cL08BTTQixEnplwgAAAH0"]
[Thu Sep 17 15:16:12.058814 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/queue/.env"] [unique_id "aqxYnOcL08BTTQixEnplxQAAABQ"]
[Thu Sep 17 15:16:12.121789 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/worker/.env"] [unique_id "aqxYnOcL08BTTQixEnplzAAAAGo"]
[Thu Sep 17 15:16:12.166393 2026] [security2:error] [pid 971102:tid 971258] [client 169.58.197.253:52315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ppfc.net"] [uri "/wp-login.php"] [unique_id "aqxYnOcL08BTTQixEnpl0AAAABg"], referer: binance.com
[Thu Sep 17 15:16:12.195373 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/job/.env"] [unique_id "aqxYnOcL08BTTQixEnpl1QAAAD4"]
[Thu Sep 17 15:16:12.259451 2026] [security2:error] [pid 971102:tid 971321] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/test/.env"] [unique_id "aqxYnOcL08BTTQixEnpl1wAAAFc"]
[Thu Sep 17 15:16:12.325951 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/qa/.env"] [unique_id "aqxYnOcL08BTTQixEnpl2AAAAGQ"]
[Thu Sep 17 15:16:12.341857 2026] [security2:error] [pid 971102:tid 971293] [client 172.239.147.162:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxYnOcL08BTTQixEnpl2QAAADs"], referer: binance.com
[Thu Sep 17 15:16:12.390601 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/preview/.env"] [unique_id "aqxYnOcL08BTTQixEnpl3QAAAA8"]
[Thu Sep 17 15:16:12.455265 2026] [security2:error] [pid 971102:tid 971343] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/beta/.env"] [unique_id "aqxYnOcL08BTTQixEnpl3gAAAG0"]
[Thu Sep 17 15:16:12.527570 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/uat/.env"] [unique_id "aqxYnOcL08BTTQixEnpl3wAAAC4"]
[Thu Sep 17 15:16:12.606343 2026] [security2:error] [pid 971102:tid 971243] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/stage/.env"] [unique_id "aqxYnOcL08BTTQixEnpl4QAAAAk"]
[Thu Sep 17 15:16:12.611821 2026] [security2:error] [pid 971102:tid 971328] [client 172.239.147.162:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxYnOcL08BTTQixEnpl4gAAAF4"], referer: binance.com
[Thu Sep 17 15:16:12.679545 2026] [security2:error] [pid 971102:tid 971284] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/development/.env"] [unique_id "aqxYnOcL08BTTQixEnpl5QAAADI"]
[Thu Sep 17 15:16:12.742005 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/production/.env"] [unique_id "aqxYnOcL08BTTQixEnpl6QAAAFY"]
[Thu Sep 17 15:16:12.822517 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/config/app/.env"] [unique_id "aqxYnOcL08BTTQixEnpl7QAAADk"]
[Thu Sep 17 15:16:12.835670 2026] [security2:error] [pid 971102:tid 971355] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYm-cL08BTTQixEnplsAAAeUY"], referer: http://sharlotbott.com/wordpress/
[Thu Sep 17 15:16:12.896747 2026] [security2:error] [pid 971102:tid 971272] [client 34.23.80.249:58066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php"] [unique_id "aqxYnOcL08BTTQixEnpl7gAAACY"]
[Thu Sep 17 15:16:13.005846 2026] [security2:error] [pid 971102:tid 971234] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnOcL08BTTQixEnpl8AAAABQ"], referer: http://sharlotbott.com/old/
[Thu Sep 17 15:16:13.099446 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:58104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/info.php"] [unique_id "aqxYnecL08BTTQixEnpl8wAAAGs"]
[Thu Sep 17 15:16:13.177630 2026] [security2:error] [pid 971102:tid 971247] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpl9gAADXo"], referer: http://sharlotbott.com/new/
[Thu Sep 17 15:16:13.309743 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.80.249:58120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/php.php"] [unique_id "aqxYnecL08BTTQixEnpl_AAAACw"]
[Thu Sep 17 15:16:13.561722 2026] [security2:error] [pid 971102:tid 971330] [client 34.23.80.249:58122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/i.php"] [unique_id "aqxYnecL08BTTQixEnpmAAAAAGA"]
[Thu Sep 17 15:16:13.659360 2026] [security2:error] [pid 971102:tid 971275] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmAQAAKVk"], referer: http://sharlotbott.com/backup/
[Thu Sep 17 15:16:13.792726 2026] [security2:error] [pid 971102:tid 971268] [client 34.23.80.249:58126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/pi.php"] [unique_id "aqxYnecL08BTTQixEnpmCQAAACI"]
[Thu Sep 17 15:16:13.831075 2026] [security2:error] [pid 971102:tid 971270] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmCgAAJCA"], referer: http://sharlotbott.com/blog/
[Thu Sep 17 15:16:14.014968 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/pinfo.php"] [unique_id "aqxYnucL08BTTQixEnpmFAAAAAU"]
[Thu Sep 17 15:16:14.019371 2026] [security2:error] [pid 971102:tid 971254] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmEQAAFBA"], referer: http://sharlotbott.com/wp/
[Thu Sep 17 15:16:14.166268 2026] [security2:error] [pid 971102:tid 971242] [client 172.239.147.162:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxYnucL08BTTQixEnpmFQAAAAg"], referer: binance.com
[Thu Sep 17 15:16:14.239071 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/test.php"] [unique_id "aqxYnucL08BTTQixEnpmHAAAAFE"]
[Thu Sep 17 15:16:14.322375 2026] [security2:error] [pid 971102:tid 971323] [client 169.58.197.253:52400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxYnucL08BTTQixEnpmGQAAAFk"], referer: binance.com
[Thu Sep 17 15:16:14.507845 2026] [security2:error] [pid 971102:tid 971321] [client 172.239.147.162:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxYnucL08BTTQixEnpmJAAAAFc"], referer: binance.com
[Thu Sep 17 15:16:14.593165 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.80.249:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/p.php"] [unique_id "aqxYnucL08BTTQixEnpmJwAAAEw"]
[Thu Sep 17 15:16:14.763544 2026] [security2:error] [pid 971102:tid 971261] [client 20.244.34.24:55491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.airmacinc.com"] [uri "/index.php"] [unique_id "aqxYnucL08BTTQixEnpmLgAAABs"], referer: binance.com
[Thu Sep 17 15:16:14.800933 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.80.249:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/debug.php"] [unique_id "aqxYnucL08BTTQixEnpmMwAAACg"]
[Thu Sep 17 15:16:14.863636 2026] [security2:error] [pid 971102:tid 971305] [client 123.26.183.108:57546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYnucL08BTTQixEnpmMAAAR20"]
[Thu Sep 17 15:16:15.001456 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.80.249:58164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmNQAAAB4"]
[Thu Sep 17 15:16:15.137454 2026] [security2:error] [pid 971102:tid 971234] [client 156.192.234.52:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYn-cL08BTTQixEnpmOAAAAAA"]
[Thu Sep 17 15:16:15.139640 2026] [security2:error] [pid 971102:tid 971234] [client 156.192.234.52:63346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYn-cL08BTTQixEnpmOAAAAAA"]
[Thu Sep 17 15:16:15.213320 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/test/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmOgAAAAY"]
[Thu Sep 17 15:16:15.441353 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.80.249:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmPgAAAEU"]
[Thu Sep 17 15:16:15.645168 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.80.249:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/old/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmRQAAABo"]
[Thu Sep 17 15:16:15.815003 2026] [security2:error] [pid 971102:tid 971242] [client 172.239.147.162:54405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxYn-cL08BTTQixEnpmSAAAAAg"], referer: binance.com
[Thu Sep 17 15:16:15.861134 2026] [security2:error] [pid 971102:tid 971323] [client 34.23.80.249:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmSQAAAFk"]
[Thu Sep 17 15:16:16.082527 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYoOcL08BTTQixEnpmTAAAABc"]
[Thu Sep 17 15:16:16.379497 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.80.249:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/php-info.php"] [unique_id "aqxYoOcL08BTTQixEnpmVgAAACA"]
[Thu Sep 17 15:16:16.416448 2026] [security2:error] [pid 971102:tid 971255] [client 172.239.147.162:50485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxYoOcL08BTTQixEnpmVwAAABU"], referer: binance.com
[Thu Sep 17 15:16:16.488903 2026] [security2:error] [pid 971102:tid 971334] [client 158.140.173.55:37244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYoOcL08BTTQixEnpmVQAAZF4"]
[Thu Sep 17 15:16:16.555669 2026] [security2:error] [pid 971102:tid 971250] [client 5.189.145.112:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxYoOcL08BTTQixEnpmWwAAABA"], referer: binance.com
[Thu Sep 17 15:16:16.560154 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.80.249:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpversion.php"] [unique_id "aqxYoOcL08BTTQixEnpmXAAAAHQ"]
[Thu Sep 17 15:16:16.774720 2026] [security2:error] [pid 971102:tid 971279] [client 209.38.197.191:54488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.recessionnews.org"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmCAAAAC0"]
[Thu Sep 17 15:16:16.795956 2026] [security2:error] [pid 971102:tid 971336] [client 34.23.80.249:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/_phpinfo.php"] [unique_id "aqxYoOcL08BTTQixEnpmYgAAAGY"]
[Thu Sep 17 15:16:17.015155 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:58240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/old_phpinfo.php"] [unique_id "aqxYoecL08BTTQixEnpmZwAAAF8"]
[Thu Sep 17 15:16:17.200784 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/server-info.php"] [unique_id "aqxYoecL08BTTQixEnpmcAAAAFU"]
[Thu Sep 17 15:16:17.229811 2026] [security2:error] [pid 971102:tid 971278] [client 209.38.197.191:54500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recessionnews.org"] [uri "/index.php"] [unique_id "aqxYoecL08BTTQixEnpmawAAACw"], referer: http://www.recessionnews.org/backup/
[Thu Sep 17 15:16:17.373061 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.80.249:58252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/server-status.php"] [unique_id "aqxYoecL08BTTQixEnpmdQAAACk"]
[Thu Sep 17 15:16:17.620717 2026] [security2:error] [pid 971102:tid 971289] [client 209.38.197.191:54488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.recessionnews.org"] [uri "/index.php"] [unique_id "aqxYoecL08BTTQixEnpmdgAAADc"]
[Thu Sep 17 15:16:18.043750 2026] [security2:error] [pid 971102:tid 971257] [client 172.239.147.162:65278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxYoucL08BTTQixEnpmjwAAABc"], referer: binance.com
[Thu Sep 17 15:16:18.044842 2026] [security2:error] [pid 971102:tid 971276] [client 34.23.80.249:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYoucL08BTTQixEnpmkAAAACo"]
[Thu Sep 17 15:16:18.239098 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:58272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmmgAAAFA"]
[Thu Sep 17 15:16:18.307239 2026] [security2:error] [pid 971102:tid 971285] [client 172.239.147.162:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxYoucL08BTTQixEnpmnQAAADM"], referer: binance.com
[Thu Sep 17 15:16:18.432484 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.80.249:58274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmngAAAFM"]
[Thu Sep 17 15:16:18.627475 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.80.249:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmoAAAAHg"]
[Thu Sep 17 15:16:18.799678 2026] [security2:error] [pid 971102:tid 971246] [client 34.23.80.249:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmpgAAAAw"]
[Thu Sep 17 15:16:18.989094 2026] [security2:error] [pid 971102:tid 971301] [client 34.23.80.249:58308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmqwAAAEM"]
[Thu Sep 17 15:16:19.177288 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.80.249:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxYo-cL08BTTQixEnpmrAAAAE8"]
[Thu Sep 17 15:16:19.216829 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:56449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYo-cL08BTTQixEnpmsAAAAAM"]
[Thu Sep 17 15:16:19.216941 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:56449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYo-cL08BTTQixEnpmsAAAAAM"]
[Thu Sep 17 15:16:19.239703 2026] [security2:error] [pid 971102:tid 971335] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tcc.anl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYoucL08BTTQixEnpmkgAAAGU"]
[Thu Sep 17 15:16:19.249328 2026] [security2:error] [pid 971102:tid 971306] [client 74.7.230.1:48596] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tcc.anl.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYoecL08BTTQixEnpmjAAASFE"]
[Thu Sep 17 15:16:19.352441 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.80.249:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php.old"] [unique_id "aqxYo-cL08BTTQixEnpmtAAAAEE"]
[Thu Sep 17 15:16:19.546784 2026] [security2:error] [pid 971102:tid 971323] [client 34.23.80.249:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php~"] [unique_id "aqxYo-cL08BTTQixEnpmtwAAAFk"]
[Thu Sep 17 15:16:19.752131 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.80.249:58366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/info.php.bak"] [unique_id "aqxYo-cL08BTTQixEnpmuwAAAGI"]
[Thu Sep 17 15:16:19.958353 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.80.249:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php.save"] [unique_id "aqxYo-cL08BTTQixEnpmvQAAACA"]
[Thu Sep 17 15:16:20.003089 2026] [cgid:error] [pid 971102:tid 971168] [remote 200.231.6.3:52494] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:16:20.086131 2026] [security2:error] [pid 971102:tid 971245] [client 172.239.147.162:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxYpOcL08BTTQixEnpmxQAAAAs"], referer: binance.com
[Thu Sep 17 15:16:20.169527 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.80.249:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpmyQAAAEo"]
[Thu Sep 17 15:16:20.245307 2026] [security2:error] [pid 971102:tid 971250] [client 57.141.14.74:20444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYpOcL08BTTQixEnpmwwAAEDQ"]
[Thu Sep 17 15:16:20.268482 2026] [security2:error] [pid 971102:tid 971279] [client 172.239.147.162:59827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxYpOcL08BTTQixEnpmzQAAAC0"], referer: binance.com
[Thu Sep 17 15:16:20.330701 2026] [security2:error] [pid 971102:tid 971330] [client 178.20.44.82:52490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYpOcL08BTTQixEnpmygAAAGA"], referer: https://joeledmundanderson.com/understanding-genesis-11-the-tower-of-babel-and-yet-one-more-genealogy/
[Thu Sep 17 15:16:20.383903 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpmzwAAAGs"]
[Thu Sep 17 15:16:20.607532 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.80.249:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpm0QAAAG4"]
[Thu Sep 17 15:16:20.785283 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.80.249:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpm1QAAAEk"]
[Thu Sep 17 15:16:20.803652 2026] [security2:error] [pid 971102:tid 971356] [client 45.169.98.18:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpOcL08BTTQixEnpm1gAAAHo"]
[Thu Sep 17 15:16:20.803803 2026] [security2:error] [pid 971102:tid 971356] [client 45.169.98.18:55752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpOcL08BTTQixEnpm1gAAAHo"]
[Thu Sep 17 15:16:20.966451 2026] [security2:error] [pid 971102:tid 971346] [client 34.23.80.249:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpm2gAAAHA"]
[Thu Sep 17 15:16:21.047396 2026] [security2:error] [pid 971102:tid 971319] [client 186.105.232.15:50912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm3QAAAFU"]
[Thu Sep 17 15:16:21.047570 2026] [security2:error] [pid 971102:tid 971319] [client 186.105.232.15:50912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm3QAAAFU"]
[Thu Sep 17 15:16:21.208709 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.80.249:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/www/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm4QAAAB4"]
[Thu Sep 17 15:16:21.422871 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:58428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm5AAAAAU"]
[Thu Sep 17 15:16:21.601935 2026] [security2:error] [pid 971102:tid 971209] [remote 111.225.149.173:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/friedrich-nietzsche-the-enlightenment-christianity-and-the-philosopher-of-the-hammer/"] [unique_id "aqxYpecL08BTTQixEnpm7AAAf2g"]
[Thu Sep 17 15:16:21.622929 2026] [security2:error] [pid 971102:tid 971281] [client 34.23.80.249:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm7QAAAC8"]
[Thu Sep 17 15:16:21.768755 2026] [security2:error] [pid 971102:tid 971254] [client 154.190.208.131:42317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm9QAAABQ"]
[Thu Sep 17 15:16:21.771566 2026] [security2:error] [pid 971102:tid 971254] [client 154.190.208.131:42317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm9QAAABQ"]
[Thu Sep 17 15:16:21.839589 2026] [security2:error] [pid 971102:tid 971302] [client 34.23.80.249:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/site/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm9gAAAEQ"]
[Thu Sep 17 15:16:21.944948 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm-gAAAGo"]
[Thu Sep 17 15:16:21.945080 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:55227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm-gAAAGo"]
[Thu Sep 17 15:16:22.020980 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:49418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpm_AAAAHU"]
[Thu Sep 17 15:16:22.133313 2026] [security2:error] [pid 971102:tid 971308] [client 35.238.4.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYpecL08BTTQixEnpm-QAAAEo"]
[Thu Sep 17 15:16:22.163207 2026] [security2:error] [pid 971102:tid 971320] [client 74.7.241.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cfbpp.org"] [uri "/index.php"] [unique_id "aqxYoucL08BTTQixEnpmjgAAAFY"]
[Thu Sep 17 15:16:22.176603 2026] [security2:error] [pid 971102:tid 971318] [client 74.7.241.148:36676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cfbpp.org"] [uri "/robots.txt"] [unique_id "aqxYoecL08BTTQixEnpmggAAVDk"]
[Thu Sep 17 15:16:22.199917 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.80.249:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnAgAAAGk"]
[Thu Sep 17 15:16:22.396763 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.80.249:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnDgAAAEI"]
[Thu Sep 17 15:16:22.597296 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:49440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/core/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnEQAAAFU"]
[Thu Sep 17 15:16:22.657112 2026] [security2:error] [pid 971102:tid 971271] [client 172.239.147.162:61788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxYpucL08BTTQixEnpnFQAAACU"], referer: binance.com
[Thu Sep 17 15:16:22.663824 2026] [security2:error] [pid 971102:tid 971268] [client 172.239.147.162:58585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxYpucL08BTTQixEnpnFgAAACI"], referer: binance.com
[Thu Sep 17 15:16:22.816482 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.80.249:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnGQAAAD4"]
[Thu Sep 17 15:16:23.726264 2026] [security2:error] [pid 971102:tid 971235] [client 20.244.34.24:62980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "airmacinc.com"] [uri "/index.php"] [unique_id "aqxYp-cL08BTTQixEnpnNwAAAAE"], referer: binance.com
[Thu Sep 17 15:16:23.932281 2026] [autoindex:error] [pid 971102:tid 971353] [client 40.87.20.23:3638] AH01276: Cannot serve directory /home1/ditkuemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:16:23.981737 2026] [security2:error] [pid 971102:tid 971305] [client 5.189.145.112:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxYp-cL08BTTQixEnpnQwAAAEc"], referer: binance.com
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:16:25.534110 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:55039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxYqecL08BTTQixEnpndgAAABY"], referer: binance.com
[Thu Sep 17 15:16:25.546357 2026] [security2:error] [pid 971102:tid 971346] [client 172.239.147.162:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxYqecL08BTTQixEnpndwAAAHA"], referer: binance.com
[Thu Sep 17 15:16:25.673853 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:63985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYqecL08BTTQixEnpnewAAAFc"]
[Thu Sep 17 15:16:25.674038 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:63985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYqecL08BTTQixEnpnewAAAFc"]
[Thu Sep 17 15:16:26.242925 2026] [security2:error] [pid 971102:tid 971277] [client 24.10.29.245:34919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYqucL08BTTQixEnpniAAAKxA"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:16:26.932142 2026] [security2:error] [pid 971102:tid 971358] [client 172.239.147.162:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxYqucL08BTTQixEnpnlQAAAHw"], referer: binance.com
[Thu Sep 17 15:16:26.976890 2026] [security2:error] [pid 971102:tid 971228] [remote 47.128.115.43:56524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "endless-chronicles.com"] [uri "/robots.txt"] [unique_id "aqxYqucL08BTTQixEnpnlgAAL3s"]
[Thu Sep 17 15:16:27.532036 2026] [security2:error] [pid 971102:tid 971237] [client 172.239.147.162:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxYq-cL08BTTQixEnpnqQAAAAM"], referer: binance.com
[Thu Sep 17 15:16:27.830016 2026] [security2:error] [pid 971102:tid 971256] [client 24.10.29.245:58489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYq-cL08BTTQixEnpnrAAAFkE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818153512&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:16:28.708896 2026] [security2:error] [pid 971102:tid 971239] [client 172.239.147.162:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxYrOcL08BTTQixEnpnvAAAAAU"], referer: binance.com
[Thu Sep 17 15:16:29.105738 2026] [security2:error] [pid 971102:tid 971302] [client 172.239.147.162:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxYrecL08BTTQixEnpnyAAAAEQ"], referer: binance.com
[Thu Sep 17 15:16:30.004650 2026] [security2:error] [pid 971102:tid 971349] [client 185.55.149.49:64900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYrucL08BTTQixEnpn1AAAAHM"]
[Thu Sep 17 15:16:30.004770 2026] [security2:error] [pid 971102:tid 971349] [client 185.55.149.49:64900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYrucL08BTTQixEnpn1AAAAHM"]
[Thu Sep 17 15:16:30.696872 2026] [security2:error] [pid 971102:tid 971283] [client 172.239.147.162:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxYrucL08BTTQixEnpn5AAAADE"], referer: binance.com
[Thu Sep 17 15:16:31.243110 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYr-cL08BTTQixEnpn7gAAACY"]
[Thu Sep 17 15:16:31.243265 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYr-cL08BTTQixEnpn7gAAACY"]
[Thu Sep 17 15:16:31.314401 2026] [security2:error] [pid 971102:tid 971255] [client 5.189.145.112:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxYr-cL08BTTQixEnpn7wAAABU"], referer: binance.com
[Thu Sep 17 15:16:31.352724 2026] [security2:error] [pid 971102:tid 971267] [client 172.239.147.162:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxYr-cL08BTTQixEnpn8gAAACE"], referer: binance.com
[Thu Sep 17 15:16:31.858930 2026] [core:error] [pid 971102:tid 971250] [client 162.55.55.199:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:31.858956 2026] [core:error] [pid 971102:tid 971250] [client 162.55.55.199:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:32.144035 2026] [security2:error] [pid 971102:tid 971280] [client 186.105.232.15:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoAQAAAC4"]
[Thu Sep 17 15:16:32.144184 2026] [security2:error] [pid 971102:tid 971280] [client 186.105.232.15:51512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoAQAAAC4"]
[Thu Sep 17 15:16:32.253621 2026] [security2:error] [pid 971102:tid 971336] [client 154.190.208.131:42633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoBQAAAGY"]
[Thu Sep 17 15:16:32.253780 2026] [security2:error] [pid 971102:tid 971336] [client 154.190.208.131:42633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoBQAAAGY"]
[Thu Sep 17 15:16:32.477087 2026] [security2:error] [pid 971102:tid 971234] [client 172.239.147.162:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxYsOcL08BTTQixEnpoEQAAAAA"], referer: binance.com
[Thu Sep 17 15:16:32.557171 2026] [security2:error] [pid 971102:tid 971357] [client 114.198.138.124:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoFwAAAHs"]
[Thu Sep 17 15:16:32.557341 2026] [security2:error] [pid 971102:tid 971357] [client 114.198.138.124:55864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoFwAAAHs"]
[Thu Sep 17 15:16:32.970015 2026] [security2:error] [pid 971102:tid 971139] [remote 182.10.99.112:1396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYsOcL08BTTQixEnpoHwAAJCM"]
[Thu Sep 17 15:16:33.515017 2026] [security2:error] [pid 971102:tid 971261] [client 172.239.147.162:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxYsecL08BTTQixEnpoKQAAABs"], referer: binance.com
[Thu Sep 17 15:16:33.653042 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:38438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYsecL08BTTQixEnpoLAAAAAI"]
[Thu Sep 17 15:16:33.657219 2026] [security2:error] [pid 971102:tid 971361] [client 103.131.71.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxYsOcL08BTTQixEnpoFQAAAH8"]
[Thu Sep 17 15:16:33.810103 2026] [security2:error] [pid 971102:tid 971323] [client 172.239.147.162:50797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxYsecL08BTTQixEnpoLgAAAFk"], referer: binance.com
[Thu Sep 17 15:16:33.893861 2026] [security2:error] [pid 971102:tid 971237] [client 162.241.226.11:33296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxYsOcL08BTTQixEnpoGgAAAAM"]
[Thu Sep 17 15:16:34.050794 2026] [security2:error] [pid 971102:tid 971310] [client 34.97.30.29:58432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoNgAAAEw"]
[Thu Sep 17 15:16:34.063142 2026] [security2:error] [pid 971102:tid 971171] [remote 173.239.211.244:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edmagik.com"] [uri "/wp-login.php"] [unique_id "aqxYsucL08BTTQixEnpoNAAAZEM"]
[Thu Sep 17 15:16:34.080804 2026] [security2:error] [pid 971102:tid 971257] [client 189.63.146.109:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.146.63.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavilladesantaclaus.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsecL08BTTQixEnpoMgAAABc"]
[Thu Sep 17 15:16:34.080985 2026] [security2:error] [pid 971102:tid 971257] [client 189.63.146.109:56306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lavilladesantaclaus.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsecL08BTTQixEnpoMgAAABc"]
[Thu Sep 17 15:16:34.104335 2026] [security2:error] [pid 971102:tid 971151] [remote 45.92.229.1:26727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/wp-login.php"] [unique_id "aqxYsucL08BTTQixEnpoNwAAOC8"]
[Thu Sep 17 15:16:34.357709 2026] [security2:error] [pid 971102:tid 971246] [client 139.99.25.135:62042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoOgAAAAw"]
[Thu Sep 17 15:16:34.421459 2026] [security2:error] [pid 971102:tid 971278] [client 34.97.30.29:58436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoPAAAACw"]
[Thu Sep 17 15:16:34.798367 2026] [security2:error] [pid 971102:tid 971307] [client 139.99.25.135:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoRgAAAEk"]
[Thu Sep 17 15:16:34.943310 2026] [security2:error] [pid 971102:tid 971247] [client 172.239.147.162:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxYsucL08BTTQixEnpoTAAAAA0"], referer: binance.com
[Thu Sep 17 15:16:34.960022 2026] [security2:error] [pid 971102:tid 971234] [client 162.241.226.11:33310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxYsecL08BTTQixEnpoMQAAAAA"]
[Thu Sep 17 15:16:35.058022 2026] [security2:error] [pid 971102:tid 971325] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYsucL08BTTQixEnpoSwAAAFs"]
[Thu Sep 17 15:16:35.314458 2026] [security2:error] [pid 971102:tid 971254] [client 34.97.30.29:58442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYs-cL08BTTQixEnpoUQAAABQ"]
[Thu Sep 17 15:16:35.444806 2026] [security2:error] [pid 971102:tid 971358] [client 20.255.75.24:1033] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tesselessetbooks.com"] [uri "/1.php"] [unique_id "aqxYs-cL08BTTQixEnpoWAAAAHw"]
[Thu Sep 17 15:16:35.444923 2026] [security2:error] [pid 971102:tid 971358] [client 20.255.75.24:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/1.php"] [unique_id "aqxYs-cL08BTTQixEnpoWAAAAHw"]
[Thu Sep 17 15:16:35.627413 2026] [security2:error] [pid 971102:tid 971250] [client 139.99.25.135:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYs-cL08BTTQixEnpoWgAAABA"]
[Thu Sep 17 15:16:35.683095 2026] [security2:error] [pid 971102:tid 971276] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env"] [unique_id "aqxYs-cL08BTTQixEnpoWwAAACo"]
[Thu Sep 17 15:16:35.808641 2026] [core:error] [pid 971102:tid 971251] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:35.808685 2026] [core:error] [pid 971102:tid 971251] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:35.926757 2026] [security2:error] [pid 971102:tid 971361] [client 20.255.75.24:1364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/new.php"] [unique_id "aqxYs-cL08BTTQixEnpoZgAAAH8"]
[Thu Sep 17 15:16:35.943497 2026] [security2:error] [pid 971102:tid 971350] [client 172.239.147.162:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxYs-cL08BTTQixEnpoaAAAAHQ"], referer: binance.com
[Thu Sep 17 15:16:35.958110 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYs-cL08BTTQixEnpoYgAAAA8"]
[Thu Sep 17 15:16:36.065889 2026] [security2:error] [pid 971102:tid 971284] [client 139.99.25.135:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYtOcL08BTTQixEnpobAAAADI"]
[Thu Sep 17 15:16:36.211934 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:64627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYtOcL08BTTQixEnpocQAAAFA"]
[Thu Sep 17 15:16:36.213143 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:64627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYtOcL08BTTQixEnpocQAAAFA"]
[Thu Sep 17 15:16:36.413742 2026] [security2:error] [pid 971102:tid 971296] [client 20.255.75.24:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/num.php"] [unique_id "aqxYtOcL08BTTQixEnpoewAAAD4"]
[Thu Sep 17 15:16:36.418101 2026] [security2:error] [pid 971102:tid 971315] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtOcL08BTTQixEnpodAAAAFE"]
[Thu Sep 17 15:16:36.491026 2026] [security2:error] [pid 971102:tid 971316] [client 139.99.25.135:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/runtime/archive/xz.php"] [unique_id "aqxYtOcL08BTTQixEnpofgAAAFI"]
[Thu Sep 17 15:16:36.593858 2026] [security2:error] [pid 971102:tid 971345] [client 41.210.157.227:47437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYtOcL08BTTQixEnpofQAAbzk"]
[Thu Sep 17 15:16:36.691587 2026] [security2:error] [pid 971102:tid 971244] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtOcL08BTTQixEnpoggAAAAo"]
[Thu Sep 17 15:16:37.080315 2026] [security2:error] [pid 971102:tid 971327] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtOcL08BTTQixEnpoiQAAAF0"]
[Thu Sep 17 15:16:37.106001 2026] [security2:error] [pid 971102:tid 971338] [client 20.255.75.24:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/admin.php"] [unique_id "aqxYtecL08BTTQixEnpokAAAAGg"]
[Thu Sep 17 15:16:37.461048 2026] [security2:error] [pid 971102:tid 971320] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtecL08BTTQixEnpolgAAAFY"]
[Thu Sep 17 15:16:37.546757 2026] [security2:error] [pid 971102:tid 971272] [client 172.239.147.162:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxYtecL08BTTQixEnponAAAACY"], referer: binance.com
[Thu Sep 17 15:16:37.553887 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxYtecL08BTTQixEnponQAAAFk"]
[Thu Sep 17 15:16:37.611594 2026] [security2:error] [pid 971102:tid 971259] [client 20.255.75.24:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/13.php"] [unique_id "aqxYtecL08BTTQixEnpongAAABk"]
[Thu Sep 17 15:16:37.834522 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtecL08BTTQixEnpoogAAAA8"]
[Thu Sep 17 15:16:37.892392 2026] [security2:error] [pid 971102:tid 971281] [client 172.239.147.162:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxYtecL08BTTQixEnpoqQAAAC8"], referer: binance.com
[Thu Sep 17 15:16:37.962710 2026] [security2:error] [pid 971102:tid 971286] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.bak"] [unique_id "aqxYtecL08BTTQixEnporQAAADQ"]
[Thu Sep 17 15:16:38.082723 2026] [security2:error] [pid 971102:tid 971241] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.backup"] [unique_id "aqxYtucL08BTTQixEnposwAAAAc"]
[Thu Sep 17 15:16:38.096516 2026] [security2:error] [pid 971102:tid 971300] [client 20.255.75.24:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/222.php"] [unique_id "aqxYtucL08BTTQixEnpotQAAAEI"]
[Thu Sep 17 15:16:38.330300 2026] [security2:error] [pid 971102:tid 971270] [client 5.189.145.112:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxYtucL08BTTQixEnpougAAACQ"], referer: binance.com
[Thu Sep 17 15:16:38.338868 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtucL08BTTQixEnpouAAAABg"]
[Thu Sep 17 15:16:38.432073 2026] [security2:error] [pid 971102:tid 971345] [client 74.7.175.166:49460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "www.escribirglobal.gocbeglobal.com"] [uri "/robots.txt"] [unique_id "aqxYtucL08BTTQixEnpovgAAb24"]
[Thu Sep 17 15:16:38.564973 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.old"] [unique_id "aqxYtucL08BTTQixEnpowAAAAFw"]
[Thu Sep 17 15:16:38.589725 2026] [security2:error] [pid 971102:tid 971245] [client 20.255.75.24:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/aa.php"] [unique_id "aqxYtucL08BTTQixEnpowQAAAAs"]
[Thu Sep 17 15:16:38.915040 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtucL08BTTQixEnpoxQAAAHc"]
[Thu Sep 17 15:16:39.104744 2026] [security2:error] [pid 971102:tid 971295] [client 20.255.75.24:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/abcd.php"] [unique_id "aqxYt-cL08BTTQixEnpo1QAAAD0"]
[Thu Sep 17 15:16:39.201838 2026] [security2:error] [pid 971102:tid 971272] [client 134.185.85.61:54138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "clarkcountyclothing.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYt-cL08BTTQixEnpo2QAAACY"]
[Thu Sep 17 15:16:39.215278 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYt-cL08BTTQixEnpo1gAAAC0"]
[Thu Sep 17 15:16:39.249034 2026] [security2:error] [pid 971102:tid 971250] [client 172.239.147.162:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxYt-cL08BTTQixEnpo2wAAABA"], referer: binance.com
[Thu Sep 17 15:16:39.270309 2026] [security2:error] [pid 971102:tid 971320] [client 172.239.147.162:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxYt-cL08BTTQixEnpo3AAAAFY"], referer: binance.com
[Thu Sep 17 15:16:39.357908 2026] [security2:error] [pid 971102:tid 971288] [client 104.28.198.244:22906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYt-cL08BTTQixEnpo4AAAADY"]
[Thu Sep 17 15:16:39.358028 2026] [security2:error] [pid 971102:tid 971288] [client 104.28.198.244:22906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYt-cL08BTTQixEnpo4AAAADY"]
[Thu Sep 17 15:16:39.454348 2026] [security2:error] [pid 971102:tid 971347] [client 34.74.242.206:41745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxYt-cL08BTTQixEnpo5gAAAHE"]
[Thu Sep 17 15:16:39.454460 2026] [security2:error] [pid 971102:tid 971347] [client 34.74.242.206:41745] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxYt-cL08BTTQixEnpo5gAAAHE"]
[Thu Sep 17 15:16:39.560161 2026] [security2:error] [pid 971102:tid 971317] [client 34.74.242.206:41736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stevenreedcollins.com"] [uri "/"] [unique_id "aqxYt-cL08BTTQixEnpo6AAAAFM"]
[Thu Sep 17 15:16:39.560271 2026] [security2:error] [pid 971102:tid 971317] [client 34.74.242.206:41736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.stevenreedcollins.com"] [uri "/"] [unique_id "aqxYt-cL08BTTQixEnpo6AAAAFM"]
[Thu Sep 17 15:16:39.584603 2026] [security2:error] [pid 971102:tid 971281] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYt-cL08BTTQixEnpo5wAAAC8"]
[Thu Sep 17 15:16:39.589756 2026] [security2:error] [pid 971102:tid 971256] [client 134.185.85.61:64882] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "clarkcountyclothing.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYt-cL08BTTQixEnpo6wAAABY"]
[Thu Sep 17 15:16:39.632086 2026] [security2:error] [pid 971102:tid 971319] [client 20.255.75.24:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/about.php"] [unique_id "aqxYt-cL08BTTQixEnpo8AAAAFU"]
[Thu Sep 17 15:16:39.829516 2026] [autoindex:error] [pid 971102:tid 971269] [client 34.24.217.248:60024] AH01276: Cannot serve directory /home1/haatpamy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:16:39.870714 2026] [security2:error] [pid 971102:tid 971315] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYt-cL08BTTQixEnpo9gAAAFE"]
[Thu Sep 17 15:16:39.885103 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYt-cL08BTTQixEnpo-wAAAG4"]
[Thu Sep 17 15:16:39.895264 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxYt-cL08BTTQixEnpo_AAAAFg"]
[Thu Sep 17 15:16:40.049450 2026] [security2:error] [pid 971102:tid 971234] [client 34.24.217.248:60038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYuOcL08BTTQixEnppBwAAAAA"]
[Thu Sep 17 15:16:40.116685 2026] [security2:error] [pid 971102:tid 971348] [client 20.255.75.24:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/admin.php"] [unique_id "aqxYuOcL08BTTQixEnppCAAAAHI"]
[Thu Sep 17 15:16:40.126545 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxYuOcL08BTTQixEnppCQAAAHU"]
[Thu Sep 17 15:16:40.152272 2026] [security2:error] [pid 971102:tid 971247] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppAwAAAA0"]
[Thu Sep 17 15:16:40.212554 2026] [security2:error] [pid 971102:tid 971283] [client 34.24.217.248:60048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYuOcL08BTTQixEnppCwAAADE"]
[Thu Sep 17 15:16:40.219420 2026] [security2:error] [pid 971102:tid 971261] [client 171.8.87.141:45406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppCgAAGxw"]
[Thu Sep 17 15:16:40.451959 2026] [security2:error] [pid 971102:tid 971276] [client 34.24.217.248:60062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYuOcL08BTTQixEnppGgAAACo"]
[Thu Sep 17 15:16:40.502777 2026] [security2:error] [pid 971102:tid 971350] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppFAAAAHQ"]
[Thu Sep 17 15:16:40.589183 2026] [security2:error] [pid 971102:tid 971279] [client 103.131.71.35:64017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "norifon.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppHAAAAC0"]
[Thu Sep 17 15:16:40.605123 2026] [security2:error] [pid 971102:tid 971360] [client 20.255.75.24:1349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/adminfuns.php"] [unique_id "aqxYuOcL08BTTQixEnppIQAAAH4"]
[Thu Sep 17 15:16:40.620891 2026] [security2:error] [pid 971102:tid 971323] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env"] [unique_id "aqxYuOcL08BTTQixEnppIgAAAFk"]
[Thu Sep 17 15:16:40.646411 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxYuOcL08BTTQixEnppIwAAAAc"]
[Thu Sep 17 15:16:40.658206 2026] [security2:error] [pid 971102:tid 971288] [client 34.172.22.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppHQAAADY"]
[Thu Sep 17 15:16:40.711505 2026] [security2:error] [pid 971102:tid 971305] [client 185.55.149.49:49301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYuOcL08BTTQixEnppJwAAAEc"]
[Thu Sep 17 15:16:40.711641 2026] [security2:error] [pid 971102:tid 971305] [client 185.55.149.49:49301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYuOcL08BTTQixEnppJwAAAEc"]
[Thu Sep 17 15:16:40.901133 2026] [security2:error] [pid 971102:tid 971265] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppKwAAAB8"]
[Thu Sep 17 15:16:41.025753 2026] [security2:error] [pid 971102:tid 971329] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxYuecL08BTTQixEnppNQAAAF8"]
[Thu Sep 17 15:16:41.081015 2026] [security2:error] [pid 971102:tid 971282] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxYuecL08BTTQixEnppOAAAADA"]
[Thu Sep 17 15:16:41.106261 2026] [security2:error] [pid 971102:tid 971269] [client 20.255.75.24:1047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxYuecL08BTTQixEnppOQAAACM"]
[Thu Sep 17 15:16:41.198588 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxYuecL08BTTQixEnppPQAAAAk"]
[Thu Sep 17 15:16:41.219818 2026] [security2:error] [pid 971102:tid 971240] [client 172.239.147.162:63738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxYuecL08BTTQixEnppQAAAAAY"], referer: binance.com
[Thu Sep 17 15:16:41.254304 2026] [security2:error] [pid 971102:tid 971274] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuecL08BTTQixEnppOgAAACg"]
[Thu Sep 17 15:16:41.591087 2026] [security2:error] [pid 971102:tid 971361] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuecL08BTTQixEnppUQAAAH8"]
[Thu Sep 17 15:16:41.634089 2026] [security2:error] [pid 971102:tid 971260] [client 20.255.75.24:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/ae.php"] [unique_id "aqxYuecL08BTTQixEnppWQAAABo"]
[Thu Sep 17 15:16:41.740437 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuecL08BTTQixEnppXQAAACY"]
[Thu Sep 17 15:16:41.740554 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuecL08BTTQixEnppXQAAACY"]
[Thu Sep 17 15:16:41.829128 2026] [security2:error] [pid 971102:tid 971349] [client 216.73.161.135:27483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/wp-login.php"] [unique_id "aqxYuecL08BTTQixEnppXwAAAHM"]
[Thu Sep 17 15:16:41.950937 2026] [security2:error] [pid 971102:tid 971280] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuecL08BTTQixEnppZQAAAC4"]
[Thu Sep 17 15:16:41.985379 2026] [security2:error] [pid 971102:tid 971342] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxYuecL08BTTQixEnppbAAAAGw"]
[Thu Sep 17 15:16:42.059180 2026] [security2:error] [pid 971102:tid 971256] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env~"] [unique_id "aqxYuucL08BTTQixEnppbQAAABY"]
[Thu Sep 17 15:16:42.155668 2026] [security2:error] [pid 971102:tid 971246] [client 20.255.75.24:1346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/akcc.php"] [unique_id "aqxYuucL08BTTQixEnppdgAAAAw"]
[Thu Sep 17 15:16:42.164457 2026] [security2:error] [pid 971102:tid 971334] [client 172.239.147.162:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxYuucL08BTTQixEnppdwAAAGQ"], referer: binance.com
[Thu Sep 17 15:16:42.373498 2026] [security2:error] [pid 971102:tid 971275] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuucL08BTTQixEnppfAAAACk"]
[Thu Sep 17 15:16:42.516229 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.swp"] [unique_id "aqxYuucL08BTTQixEnpphwAAAHU"]
[Thu Sep 17 15:16:42.566539 2026] [security2:error] [pid 971102:tid 971293] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxYuucL08BTTQixEnppiAAAADs"]
[Thu Sep 17 15:16:42.631192 2026] [security2:error] [pid 971102:tid 971332] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxYuucL08BTTQixEnppiwAAAGI"]
[Thu Sep 17 15:16:42.646543 2026] [security2:error] [pid 971102:tid 971268] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env~"] [unique_id "aqxYuucL08BTTQixEnppjAAAACI"]
[Thu Sep 17 15:16:42.682566 2026] [security2:error] [pid 971102:tid 971346] [client 20.255.75.24:1347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/bak.php"] [unique_id "aqxYuucL08BTTQixEnppjwAAAHA"]
[Thu Sep 17 15:16:42.692878 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxYuucL08BTTQixEnppkAAAAHQ"]
[Thu Sep 17 15:16:42.751705 2026] [security2:error] [pid 971102:tid 971324] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxYuucL08BTTQixEnppkwAAAFo"]
[Thu Sep 17 15:16:42.777359 2026] [security2:error] [pid 971102:tid 971243] [client 154.190.208.131:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuucL08BTTQixEnpplgAAAAk"]
[Thu Sep 17 15:16:42.778195 2026] [security2:error] [pid 971102:tid 971243] [client 154.190.208.131:41920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuucL08BTTQixEnpplgAAAAk"]
[Thu Sep 17 15:16:42.833112 2026] [security2:error] [pid 971102:tid 971253] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxYuucL08BTTQixEnppmQAAABM"]
[Thu Sep 17 15:16:42.897730 2026] [security2:error] [pid 971102:tid 971235] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxYuucL08BTTQixEnppnAAAAAE"]
[Thu Sep 17 15:16:42.934622 2026] [security2:error] [pid 971102:tid 971264] [client 159.69.158.189:32662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxYuucL08BTTQixEnppoAAAAB4"], referer: https://faewave.com
[Thu Sep 17 15:16:42.940050 2026] [security2:error] [pid 971102:tid 971338] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuucL08BTTQixEnppmAAAAGg"]
[Thu Sep 17 15:16:43.029561 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxYu-cL08BTTQixEnppowAAAC8"]
[Thu Sep 17 15:16:43.040294 2026] [security2:error] [pid 971102:tid 971308] [client 51.161.128.55:45778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "argentumequitycapital.com"] [uri "/webmail"] [unique_id "aqxYu-cL08BTTQixEnpppAAAAEo"]
[Thu Sep 17 15:16:43.054310 2026] [security2:error] [pid 971102:tid 971358] [client 51.161.128.55:45792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "argentumequitycapital.com"] [uri "/mail"] [unique_id "aqxYu-cL08BTTQixEnpppQAAAHw"]
[Thu Sep 17 15:16:43.067430 2026] [security2:error] [pid 971102:tid 971294] [client 51.161.128.55:45808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.argentumequitycapital.com"] [uri "/"] [unique_id "aqxYu-cL08BTTQixEnpppgAAADw"]
[Thu Sep 17 15:16:43.092041 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxYu-cL08BTTQixEnppqQAAABk"]
[Thu Sep 17 15:16:43.152052 2026] [security2:error] [pid 971102:tid 971277] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxYu-cL08BTTQixEnppqwAAACs"]
[Thu Sep 17 15:16:43.209708 2026] [security2:error] [pid 971102:tid 971252] [client 20.255.75.24:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/cc.php"] [unique_id "aqxYu-cL08BTTQixEnpprwAAABI"]
[Thu Sep 17 15:16:43.212760 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxYu-cL08BTTQixEnppsAAAAFE"]
[Thu Sep 17 15:16:43.224331 2026] [security2:error] [pid 971102:tid 971255] [client 51.161.128.55:45814] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.argentumequitycapital.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxYu-cL08BTTQixEnppswAAABU"]
[Thu Sep 17 15:16:43.238902 2026] [security2:error] [pid 971102:tid 971314] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYu-cL08BTTQixEnppqgAAAFA"]
[Thu Sep 17 15:16:43.257405 2026] [security2:error] [pid 971102:tid 971236] [client 114.198.138.124:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnpptgAAAAI"]
[Thu Sep 17 15:16:43.257493 2026] [security2:error] [pid 971102:tid 971236] [client 114.198.138.124:62289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnpptgAAAAI"]
[Thu Sep 17 15:16:43.281183 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxYu-cL08BTTQixEnpptwAAAGA"]
[Thu Sep 17 15:16:43.313266 2026] [security2:error] [pid 971102:tid 971360] [client 172.239.147.162:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxYu-cL08BTTQixEnppuAAAAH4"], referer: binance.com
[Thu Sep 17 15:16:43.343007 2026] [security2:error] [pid 971102:tid 971322] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxYu-cL08BTTQixEnppuQAAAFg"]
[Thu Sep 17 15:16:43.401477 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxYu-cL08BTTQixEnppwAAAAFQ"]
[Thu Sep 17 15:16:43.456727 2026] [security2:error] [pid 971102:tid 971295] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxYu-cL08BTTQixEnppxgAAAD0"]
[Thu Sep 17 15:16:43.474678 2026] [security2:error] [pid 971102:tid 971288] [client 186.105.232.15:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnppyAAAADY"]
[Thu Sep 17 15:16:43.474832 2026] [security2:error] [pid 971102:tid 971288] [client 186.105.232.15:52121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnppyAAAADY"]
[Thu Sep 17 15:16:43.513277 2026] [security2:error] [pid 971102:tid 971239] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxYu-cL08BTTQixEnppygAAAAU"]
[Thu Sep 17 15:16:43.564757 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYu-cL08BTTQixEnppxAAAAHU"]
[Thu Sep 17 15:16:43.568854 2026] [security2:error] [pid 971102:tid 971332] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxYu-cL08BTTQixEnppywAAAGI"]
[Thu Sep 17 15:16:43.595609 2026] [security2:error] [pid 971102:tid 971312] [client 172.239.147.162:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxYu-cL08BTTQixEnppzgAAAE4"], referer: binance.com
[Thu Sep 17 15:16:43.624616 2026] [security2:error] [pid 971102:tid 971359] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxYu-cL08BTTQixEnppzwAAAH0"]
[Thu Sep 17 15:16:43.680079 2026] [security2:error] [pid 971102:tid 971307] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxYu-cL08BTTQixEnpp0QAAAEk"]
[Thu Sep 17 15:16:43.714544 2026] [security2:error] [pid 971102:tid 971325] [client 20.255.75.24:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/chosen.php"] [unique_id "aqxYu-cL08BTTQixEnpp0wAAAFs"]
[Thu Sep 17 15:16:43.734810 2026] [security2:error] [pid 971102:tid 971289] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxYu-cL08BTTQixEnpp1gAAADc"]
[Thu Sep 17 15:16:43.791279 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxYu-cL08BTTQixEnpp2gAAAC8"]
[Thu Sep 17 15:16:43.846541 2026] [security2:error] [pid 971102:tid 971308] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxYu-cL08BTTQixEnpp2wAAAEo"]
[Thu Sep 17 15:16:43.903339 2026] [security2:error] [pid 971102:tid 971341] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxYu-cL08BTTQixEnpp3wAAAGs"]
[Thu Sep 17 15:16:43.960413 2026] [security2:error] [pid 971102:tid 971327] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxYu-cL08BTTQixEnpp4QAAAF0"]
[Thu Sep 17 15:16:44.021533 2026] [security2:error] [pid 971102:tid 971280] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxYvOcL08BTTQixEnpp5gAAAC4"]
[Thu Sep 17 15:16:44.082635 2026] [security2:error] [pid 971102:tid 971354] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxYvOcL08BTTQixEnpp6QAAAHg"]
[Thu Sep 17 15:16:44.149527 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxYvOcL08BTTQixEnpp7QAAAG4"]
[Thu Sep 17 15:16:44.209642 2026] [security2:error] [pid 971102:tid 971252] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYvOcL08BTTQixEnpp6wAAABI"]
[Thu Sep 17 15:16:44.211901 2026] [security2:error] [pid 971102:tid 971306] [client 20.255.75.24:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/classwithtostring.php"] [unique_id "aqxYvOcL08BTTQixEnpp7wAAAEg"]
[Thu Sep 17 15:16:44.213706 2026] [security2:error] [pid 971102:tid 971255] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxYvOcL08BTTQixEnpp8AAAABU"]
[Thu Sep 17 15:16:44.281357 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxYvOcL08BTTQixEnpp8QAAAGQ"]
[Thu Sep 17 15:16:44.311456 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxYvOcL08BTTQixEnpp8gAAABA"]
[Thu Sep 17 15:16:44.360738 2026] [security2:error] [pid 971102:tid 971328] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxYvOcL08BTTQixEnpp8wAAAF4"]
[Thu Sep 17 15:16:44.425710 2026] [security2:error] [pid 971102:tid 971237] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxYvOcL08BTTQixEnpp9gAAAAM"]
[Thu Sep 17 15:16:44.489465 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxYvOcL08BTTQixEnpp-gAAAAo"]
[Thu Sep 17 15:16:44.547182 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxYvOcL08BTTQixEnpp-wAAABc"]
[Thu Sep 17 15:16:44.551414 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxYvOcL08BTTQixEnpp_AAAAGA"]
[Thu Sep 17 15:16:44.560589 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYvOcL08BTTQixEnpp9wAAAHM"]
[Thu Sep 17 15:16:44.611702 2026] [security2:error] [pid 971102:tid 971321] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxYvOcL08BTTQixEnpqAAAAAFc"]
[Thu Sep 17 15:16:44.669539 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxYvOcL08BTTQixEnpqAQAAACA"]
[Thu Sep 17 15:16:44.731161 2026] [security2:error] [pid 971102:tid 971360] [client 20.255.75.24:1345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/wp-signup.php"] [unique_id "aqxYvOcL08BTTQixEnpqAwAAAH4"]
[Thu Sep 17 15:16:44.733133 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/app/.env"] [unique_id "aqxYvOcL08BTTQixEnpqBAAAAHI"]
[Thu Sep 17 15:16:44.733147 2026] [security2:error] [pid 971102:tid 971302] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxYvOcL08BTTQixEnpqBQAAAEQ"]
[Thu Sep 17 15:16:44.793857 2026] [security2:error] [pid 971102:tid 971288] [client 69.130.172.199:39029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYvOcL08BTTQixEnpqAgAANhM"], referer: https://www.google.com/
[Thu Sep 17 15:16:44.793884 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxYvOcL08BTTQixEnpqCAAAACc"], referer: binance.com
[Thu Sep 17 15:16:44.794975 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxYvOcL08BTTQixEnpqCQAAAHU"]
[Thu Sep 17 15:16:44.853335 2026] [security2:error] [pid 971102:tid 971311] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxYvOcL08BTTQixEnpqCwAAAE0"]
[Thu Sep 17 15:16:44.855825 2026] [security2:error] [pid 971102:tid 971234] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/apps/.env"] [unique_id "aqxYvOcL08BTTQixEnpqDAAAAAA"]
[Thu Sep 17 15:16:44.876443 2026] [security2:error] [pid 971102:tid 971283] [client 172.239.147.162:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxYvOcL08BTTQixEnpqDQAAADE"], referer: binance.com
[Thu Sep 17 15:16:44.913622 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxYvOcL08BTTQixEnpqEAAAAAk"]
[Thu Sep 17 15:16:44.977042 2026] [security2:error] [pid 971102:tid 971326] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxYvOcL08BTTQixEnpqEQAAAFw"]
[Thu Sep 17 15:16:44.980976 2026] [security2:error] [pid 971102:tid 971313] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/.env"] [unique_id "aqxYvOcL08BTTQixEnpqEwAAAE8"]
[Thu Sep 17 15:16:45.038253 2026] [security2:error] [pid 971102:tid 971260] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxYvecL08BTTQixEnpqFAAAABo"]
[Thu Sep 17 15:16:45.101473 2026] [security2:error] [pid 971102:tid 971245] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxYvecL08BTTQixEnpqGQAAAAs"]
[Thu Sep 17 15:16:45.105288 2026] [security2:error] [pid 971102:tid 971325] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/web/.env"] [unique_id "aqxYvecL08BTTQixEnpqGgAAAFs"]
[Thu Sep 17 15:16:45.163399 2026] [security2:error] [pid 971102:tid 971272] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxYvecL08BTTQixEnpqHgAAACY"]
[Thu Sep 17 15:16:45.224182 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxYvecL08BTTQixEnpqHwAAAHc"]
[Thu Sep 17 15:16:45.229320 2026] [security2:error] [pid 971102:tid 971264] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/site/.env"] [unique_id "aqxYvecL08BTTQixEnpqIAAAAB4"]
[Thu Sep 17 15:16:45.235409 2026] [security2:error] [pid 971102:tid 971235] [client 20.255.75.24:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/doc.php"] [unique_id "aqxYvecL08BTTQixEnpqIQAAAAE"]
[Thu Sep 17 15:16:45.286350 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxYvecL08BTTQixEnpqIgAAAC8"]
[Thu Sep 17 15:16:45.360963 2026] [security2:error] [pid 971102:tid 971356] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/public/.env"] [unique_id "aqxYvecL08BTTQixEnpqJQAAAHo"]
[Thu Sep 17 15:16:45.469813 2026] [security2:error] [pid 971102:tid 971261] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxYvecL08BTTQixEnpqLwAAABs"]
[Thu Sep 17 15:16:45.524476 2026] [security2:error] [pid 971102:tid 971354] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxYvecL08BTTQixEnpqMwAAAHg"]
[Thu Sep 17 15:16:45.579449 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxYvecL08BTTQixEnpqNQAAAG4"]
[Thu Sep 17 15:16:45.636280 2026] [security2:error] [pid 971102:tid 971336] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxYvecL08BTTQixEnpqNgAAAGY"]
[Thu Sep 17 15:16:45.641013 2026] [security2:error] [pid 971102:tid 971271] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYvecL08BTTQixEnpqMgAAACU"]
[Thu Sep 17 15:16:45.690892 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxYvecL08BTTQixEnpqNwAAAGQ"]
[Thu Sep 17 15:16:45.747780 2026] [security2:error] [pid 971102:tid 971269] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxYvecL08BTTQixEnpqPAAAACM"]
[Thu Sep 17 15:16:45.755943 2026] [security2:error] [pid 971102:tid 971252] [client 20.255.75.24:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/edit.php"] [unique_id "aqxYvecL08BTTQixEnpqPQAAABI"]
[Thu Sep 17 15:16:45.785987 2026] [security2:error] [pid 971102:tid 971319] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/backend/.env"] [unique_id "aqxYvecL08BTTQixEnpqPgAAAFU"]
[Thu Sep 17 15:16:45.806125 2026] [security2:error] [pid 971102:tid 971292] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxYvecL08BTTQixEnpqPwAAADo"]
[Thu Sep 17 15:16:45.860966 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxYvecL08BTTQixEnpqQAAAAAo"]
[Thu Sep 17 15:16:45.904459 2026] [security2:error] [pid 971102:tid 971267] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/server/.env"] [unique_id "aqxYvecL08BTTQixEnpqRwAAACE"]
[Thu Sep 17 15:16:45.915394 2026] [security2:error] [pid 971102:tid 971290] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxYvecL08BTTQixEnpqSAAAADg"]
[Thu Sep 17 15:16:45.974064 2026] [security2:error] [pid 971102:tid 971337] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxYvecL08BTTQixEnpqSwAAAGc"]
[Thu Sep 17 15:16:46.025567 2026] [security2:error] [pid 971102:tid 971340] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/frontend/.env"] [unique_id "aqxYvucL08BTTQixEnpqTQAAAGo"]
[Thu Sep 17 15:16:46.027788 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxYvucL08BTTQixEnpqTgAAACA"]
[Thu Sep 17 15:16:46.068213 2026] [security2:error] [pid 971102:tid 971318] [client 69.130.172.199:33147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYvecL08BTTQixEnpqTAAAVFU"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260612184752&hidebots=0&hideliu=1&hidemyself=1&target=The_God-Emperor&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:16:46.126030 2026] [security2:error] [pid 971102:tid 971285] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxYvucL08BTTQixEnpqUAAAADM"]
[Thu Sep 17 15:16:46.149478 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/src/.env"] [unique_id "aqxYvucL08BTTQixEnpqUQAAAAI"]
[Thu Sep 17 15:16:46.181333 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxYvucL08BTTQixEnpqVAAAAHU"]
[Thu Sep 17 15:16:46.197029 2026] [security2:error] [pid 971102:tid 971275] [client 172.239.147.162:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxYvucL08BTTQixEnpqVgAAACk"], referer: binance.com
[Thu Sep 17 15:16:46.244896 2026] [security2:error] [pid 971102:tid 971296] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxYvucL08BTTQixEnpqWwAAAD4"]
[Thu Sep 17 15:16:46.270345 2026] [security2:error] [pid 971102:tid 971283] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/core/.env"] [unique_id "aqxYvucL08BTTQixEnpqXAAAADE"]
[Thu Sep 17 15:16:46.290895 2026] [security2:error] [pid 971102:tid 971345] [client 20.255.75.24:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/worksec.php"] [unique_id "aqxYvucL08BTTQixEnpqXQAAAG8"]
[Thu Sep 17 15:16:46.307909 2026] [security2:error] [pid 971102:tid 971323] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxYvucL08BTTQixEnpqXgAAAFk"]
[Thu Sep 17 15:16:46.375254 2026] [security2:error] [pid 971102:tid 971329] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxYvucL08BTTQixEnpqXwAAAF8"]
[Thu Sep 17 15:16:46.398875 2026] [security2:error] [pid 971102:tid 971313] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/core/app/.env"] [unique_id "aqxYvucL08BTTQixEnpqYgAAAE8"]
[Thu Sep 17 15:16:46.442555 2026] [security2:error] [pid 971102:tid 971358] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxYvucL08BTTQixEnpqZgAAAHw"]
[Thu Sep 17 15:16:46.502477 2026] [security2:error] [pid 971102:tid 971301] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxYvucL08BTTQixEnpqbgAAAEM"]
[Thu Sep 17 15:16:46.523743 2026] [security2:error] [pid 971102:tid 971343] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/config/.env"] [unique_id "aqxYvucL08BTTQixEnpqbwAAAG0"]
[Thu Sep 17 15:16:46.530590 2026] [security2:error] [pid 971102:tid 971234] [client 172.239.147.162:58607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxYvucL08BTTQixEnpqcQAAAAA"], referer: binance.com
[Thu Sep 17 15:16:46.546598 2026] [security2:error] [pid 971102:tid 971249] [client 3.82.141.143:39094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env.old"] [unique_id "aqxYvucL08BTTQixEnpqcgAAAA8"]
[Thu Sep 17 15:16:46.558396 2026] [security2:error] [pid 971102:tid 971324] [client 3.82.141.143:39056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env"] [unique_id "aqxYvucL08BTTQixEnpqdgAAAFo"]
[Thu Sep 17 15:16:46.560979 2026] [security2:error] [pid 971102:tid 971274] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxYvucL08BTTQixEnpqewAAACg"]
[Thu Sep 17 15:16:46.569046 2026] [security2:error] [pid 971102:tid 971287] [client 3.82.141.143:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/config.php"] [unique_id "aqxYvucL08BTTQixEnpqigAAADU"]
[Thu Sep 17 15:16:46.570483 2026] [security2:error] [pid 971102:tid 971272] [client 3.82.141.143:39098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env.bak"] [unique_id "aqxYvucL08BTTQixEnpqiwAAACY"]
[Thu Sep 17 15:16:46.576748 2026] [security2:error] [pid 971102:tid 971261] [client 3.82.141.143:39362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php~"] [unique_id "aqxYvucL08BTTQixEnpqnAAAABs"]
[Thu Sep 17 15:16:46.578798 2026] [security2:error] [pid 971102:tid 971306] [client 3.82.141.143:39394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php"] [unique_id "aqxYvucL08BTTQixEnpqoAAAAEg"]
[Thu Sep 17 15:16:46.579140 2026] [security2:error] [pid 971102:tid 971327] [client 3.82.141.143:39216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYvucL08BTTQixEnpqoQAAAF0"]
[Thu Sep 17 15:16:46.579930 2026] [security2:error] [pid 971102:tid 971241] [client 3.82.141.143:39260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php.old"] [unique_id "aqxYvucL08BTTQixEnpqpAAAAAc"]
[Thu Sep 17 15:16:46.580147 2026] [security2:error] [pid 971102:tid 971310] [client 3.82.141.143:39128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/web.config"] [unique_id "aqxYvucL08BTTQixEnpqowAAAEw"]
[Thu Sep 17 15:16:46.597789 2026] [security2:error] [pid 971102:tid 971344] [client 3.82.141.143:39374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env.backup"] [unique_id "aqxYvucL08BTTQixEnpqqwAAAG4"]
[Thu Sep 17 15:16:46.613200 2026] [security2:error] [pid 971102:tid 971348] [client 3.82.141.143:39094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php.save"] [unique_id "aqxYvucL08BTTQixEnpqtwAAAHI"]
[Thu Sep 17 15:16:46.626767 2026] [security2:error] [pid 971102:tid 971247] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxYvucL08BTTQixEnpquQAAAA0"]
[Thu Sep 17 15:16:46.661165 2026] [security2:error] [pid 971102:tid 971273] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/private/.env"] [unique_id "aqxYvucL08BTTQixEnpqvAAAACc"]
[Thu Sep 17 15:16:46.690514 2026] [security2:error] [pid 971102:tid 971313] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxYvucL08BTTQixEnpqvQAAAE8"]
[Thu Sep 17 15:16:46.750734 2026] [security2:error] [pid 971102:tid 971314] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxYvucL08BTTQixEnpqvgAAAFA"]
[Thu Sep 17 15:16:46.780446 2026] [security2:error] [pid 971102:tid 971349] [client 20.255.75.24:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/ultra.php"] [unique_id "aqxYvucL08BTTQixEnpqvwAAAHM"]
[Thu Sep 17 15:16:46.786477 2026] [security2:error] [pid 971102:tid 971272] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/application/.env"] [unique_id "aqxYvucL08BTTQixEnpqwAAAACY"]
[Thu Sep 17 15:16:46.810125 2026] [security2:error] [pid 971102:tid 971306] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxYvucL08BTTQixEnpqwQAAAEg"]
[Thu Sep 17 15:16:46.847477 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:65232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYvucL08BTTQixEnpqwgAAAAs"]
[Thu Sep 17 15:16:46.850446 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:65232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYvucL08BTTQixEnpqwgAAAAs"]
[Thu Sep 17 15:16:46.869726 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxYvucL08BTTQixEnpqwwAAADw"]
[Thu Sep 17 15:16:46.913499 2026] [security2:error] [pid 971102:tid 971305] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/bootstrap/.env"] [unique_id "aqxYvucL08BTTQixEnpqxAAAAEc"]
[Thu Sep 17 15:16:46.927891 2026] [security2:error] [pid 971102:tid 971235] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxYvucL08BTTQixEnpqyAAAAAE"]
[Thu Sep 17 15:16:46.953863 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxYvucL08BTTQixEnpqywAAAFI"]
[Thu Sep 17 15:16:46.982710 2026] [security2:error] [pid 971102:tid 971361] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxYvucL08BTTQixEnpqzAAAAH8"]
[Thu Sep 17 15:16:47.038754 2026] [security2:error] [pid 971102:tid 971345] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/database/.env"] [unique_id "aqxYv-cL08BTTQixEnpqzgAAAG8"]
[Thu Sep 17 15:16:47.041045 2026] [security2:error] [pid 971102:tid 971323] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxYv-cL08BTTQixEnpqzwAAAFk"]
[Thu Sep 17 15:16:47.095608 2026] [security2:error] [pid 971102:tid 971319] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxYv-cL08BTTQixEnpq0AAAAFU"]
[Thu Sep 17 15:16:47.153391 2026] [security2:error] [pid 971102:tid 971240] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxYv-cL08BTTQixEnpq1AAAAAY"]
[Thu Sep 17 15:16:47.158152 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/storage/.env"] [unique_id "aqxYv-cL08BTTQixEnpq1QAAABM"]
[Thu Sep 17 15:16:47.182721 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxYv-cL08BTTQixEnpq1gAAAD4"]
[Thu Sep 17 15:16:47.210951 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxYv-cL08BTTQixEnpq2AAAAC8"]
[Thu Sep 17 15:16:47.249750 2026] [security2:error] [pid 971102:tid 971335] [client 20.255.75.24:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/gecko.php"] [unique_id "aqxYv-cL08BTTQixEnpq2wAAAGU"]
[Thu Sep 17 15:16:47.257059 2026] [security2:error] [pid 971102:tid 971288] [client 104.188.154.142:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYvucL08BTTQixEnpqWgAANhs"]
[Thu Sep 17 15:16:47.266293 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxYv-cL08BTTQixEnpq3AAAAGA"]
[Thu Sep 17 15:16:47.278132 2026] [security2:error] [pid 971102:tid 971259] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/var/www/.env"] [unique_id "aqxYv-cL08BTTQixEnpq3QAAABk"]
[Thu Sep 17 15:16:47.324989 2026] [security2:error] [pid 971102:tid 971301] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxYv-cL08BTTQixEnpq3gAAAEM"]
[Thu Sep 17 15:16:47.381529 2026] [security2:error] [pid 971102:tid 971242] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxYv-cL08BTTQixEnpq4AAAAAg"]
[Thu Sep 17 15:16:47.399877 2026] [security2:error] [pid 971102:tid 971257] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/var/www/html/.env"] [unique_id "aqxYv-cL08BTTQixEnpq4QAAABc"]
[Thu Sep 17 15:16:47.411682 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxYv-cL08BTTQixEnpq4gAAAG0"]
[Thu Sep 17 15:16:47.416008 2026] [security2:error] [pid 971102:tid 971227] [remote 104.188.154.142:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYvucL08BTTQixEnpqWAAANno"]
[Thu Sep 17 15:16:47.417562 2026] [security2:error] [pid 971102:tid 971146] [remote 104.188.154.142:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYvucL08BTTQixEnpqWQAANio"]
[Thu Sep 17 15:16:47.437630 2026] [security2:error] [pid 971102:tid 971251] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxYv-cL08BTTQixEnpq5QAAABE"]
[Thu Sep 17 15:16:47.495012 2026] [security2:error] [pid 971102:tid 971290] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxYv-cL08BTTQixEnpq6gAAADg"]
[Thu Sep 17 15:16:47.521189 2026] [security2:error] [pid 971102:tid 971270] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/current/.env"] [unique_id "aqxYv-cL08BTTQixEnpq6wAAACQ"]
[Thu Sep 17 15:16:47.549001 2026] [security2:error] [pid 971102:tid 971324] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7AAAAFo"]
[Thu Sep 17 15:16:47.603176 2026] [security2:error] [pid 971102:tid 971264] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7QAAAB4"]
[Thu Sep 17 15:16:47.640109 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7gAAABI"]
[Thu Sep 17 15:16:47.641894 2026] [security2:error] [pid 971102:tid 971287] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/release/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7wAAADU"]
[Thu Sep 17 15:16:47.658272 2026] [security2:error] [pid 971102:tid 971349] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxYv-cL08BTTQixEnpq8AAAAHM"]
[Thu Sep 17 15:16:47.718558 2026] [security2:error] [pid 971102:tid 971342] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxYv-cL08BTTQixEnpq8QAAAGw"]
[Thu Sep 17 15:16:47.761122 2026] [security2:error] [pid 971102:tid 971303] [client 20.255.75.24:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/goods.php"] [unique_id "aqxYv-cL08BTTQixEnpq9AAAAEU"]
[Thu Sep 17 15:16:47.762079 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/releases/.env"] [unique_id "aqxYv-cL08BTTQixEnpq8wAAABg"]
[Thu Sep 17 15:16:47.772101 2026] [security2:error] [pid 971102:tid 971246] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxYv-cL08BTTQixEnpq9QAAAAw"]
[Thu Sep 17 15:16:47.826423 2026] [security2:error] [pid 971102:tid 971327] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxYv-cL08BTTQixEnpq9gAAAF0"]
[Thu Sep 17 15:16:47.869220 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/site/.env"] [unique_id "aqxYv-cL08BTTQixEnpq9wAAADs"]
[Thu Sep 17 15:16:47.905157 2026] [security2:error] [pid 971102:tid 971347] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxYv-cL08BTTQixEnpq-AAAAHE"]
[Thu Sep 17 15:16:47.944936 2026] [security2:error] [pid 971102:tid 971340] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/shared/.env"] [unique_id "aqxYv-cL08BTTQixEnpq-QAAAGo"]
[Thu Sep 17 15:16:47.956835 2026] [security2:error] [pid 971102:tid 971280] [client 172.239.147.162:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxYv-cL08BTTQixEnpq-gAAAC4"], referer: binance.com
[Thu Sep 17 15:16:47.960097 2026] [security2:error] [pid 971102:tid 971255] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxYv-cL08BTTQixEnpq_AAAABU"]
[Thu Sep 17 15:16:48.016053 2026] [security2:error] [pid 971102:tid 971260] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxYwOcL08BTTQixEnpq_wAAABo"]
[Thu Sep 17 15:16:48.064855 2026] [security2:error] [pid 971102:tid 971241] [client 172.239.147.162:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxYwOcL08BTTQixEnprAwAAAAc"], referer: binance.com
[Thu Sep 17 15:16:48.071185 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxYwOcL08BTTQixEnprBAAAAGg"]
[Thu Sep 17 15:16:48.072636 2026] [security2:error] [pid 971102:tid 971317] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/deploy/.env"] [unique_id "aqxYwOcL08BTTQixEnprBQAAAFM"]
[Thu Sep 17 15:16:48.108086 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxYwOcL08BTTQixEnprBgAAAD0"]
[Thu Sep 17 15:16:48.132314 2026] [security2:error] [pid 971102:tid 971336] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxYwOcL08BTTQixEnprBwAAAGY"]
[Thu Sep 17 15:16:48.186986 2026] [security2:error] [pid 971102:tid 971282] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxYwOcL08BTTQixEnprCgAAADA"]
[Thu Sep 17 15:16:48.197482 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/build/.env"] [unique_id "aqxYwOcL08BTTQixEnprCwAAAC0"]
[Thu Sep 17 15:16:48.241199 2026] [security2:error] [pid 971102:tid 971341] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxYwOcL08BTTQixEnprDQAAAGs"]
[Thu Sep 17 15:16:48.298946 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxYwOcL08BTTQixEnprDwAAAHU"]
[Thu Sep 17 15:16:48.301425 2026] [security2:error] [pid 971102:tid 971245] [client 20.255.75.24:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/man.php"] [unique_id "aqxYwOcL08BTTQixEnprEAAAAAs"]
[Thu Sep 17 15:16:48.321730 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/dist/.env"] [unique_id "aqxYwOcL08BTTQixEnprEgAAAFw"]
[Thu Sep 17 15:16:48.354105 2026] [security2:error] [pid 971102:tid 971305] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxYwOcL08BTTQixEnprFQAAAEc"]
[Thu Sep 17 15:16:48.409487 2026] [security2:error] [pid 971102:tid 971273] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxYwOcL08BTTQixEnprFwAAACc"]
[Thu Sep 17 15:16:48.441637 2026] [security2:error] [pid 971102:tid 971345] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/public_html/.env"] [unique_id "aqxYwOcL08BTTQixEnprGQAAAG8"]
[Thu Sep 17 15:16:48.464212 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxYwOcL08BTTQixEnprGgAAAAk"]
[Thu Sep 17 15:16:48.528898 2026] [security2:error] [pid 971102:tid 971253] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxYwOcL08BTTQixEnprHgAAABM"]
[Thu Sep 17 15:16:48.586652 2026] [security2:error] [pid 971102:tid 971289] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxYwOcL08BTTQixEnprIAAAADc"]
[Thu Sep 17 15:16:48.589793 2026] [security2:error] [pid 971102:tid 971244] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/htdocs/.env"] [unique_id "aqxYwOcL08BTTQixEnprIQAAAAo"]
[Thu Sep 17 15:16:48.623576 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxYwOcL08BTTQixEnprIgAAADo"]
[Thu Sep 17 15:16:48.643478 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxYwOcL08BTTQixEnprIwAAABk"]
[Thu Sep 17 15:16:48.698606 2026] [security2:error] [pid 971102:tid 971343] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxYwOcL08BTTQixEnprJwAAAG0"]
[Thu Sep 17 15:16:48.728217 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/www/.env"] [unique_id "aqxYwOcL08BTTQixEnprKAAAAEQ"]
[Thu Sep 17 15:16:48.767758 2026] [security2:error] [pid 971102:tid 971271] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxYwOcL08BTTQixEnprKQAAACU"]
[Thu Sep 17 15:16:48.811194 2026] [security2:error] [pid 971102:tid 971335] [client 20.255.75.24:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/wp-settings.php"] [unique_id "aqxYwOcL08BTTQixEnprKgAAAGU"]
[Thu Sep 17 15:16:48.829930 2026] [security2:error] [pid 971102:tid 971314] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxYwOcL08BTTQixEnprKwAAAFA"]
[Thu Sep 17 15:16:48.850760 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/html/.env"] [unique_id "aqxYwOcL08BTTQixEnprLAAAAA8"]
[Thu Sep 17 15:16:48.852079 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxYwOcL08BTTQixEnprLQAAACw"]
[Thu Sep 17 15:16:48.885973 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxYwOcL08BTTQixEnprLgAAAHc"]
[Thu Sep 17 15:16:48.942359 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxYwOcL08BTTQixEnprMAAAACQ"]
[Thu Sep 17 15:16:48.975475 2026] [security2:error] [pid 971102:tid 971264] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/live/.env"] [unique_id "aqxYwOcL08BTTQixEnprMQAAAB4"]
[Thu Sep 17 15:16:48.993484 2026] [security2:error] [pid 971102:tid 971267] [client 34.154.67.31:46072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env"] [unique_id "aqxYwOcL08BTTQixEnprMgAAACE"]
[Thu Sep 17 15:16:48.998048 2026] [security2:error] [pid 971102:tid 971269] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxYwOcL08BTTQixEnprMwAAACM"]
[Thu Sep 17 15:16:49.056780 2026] [security2:error] [pid 971102:tid 971252] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxYwecL08BTTQixEnprNwAAABI"]
[Thu Sep 17 15:16:49.084872 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxYwecL08BTTQixEnprOAAAADU"]
[Thu Sep 17 15:16:49.103559 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/prod/.env"] [unique_id "aqxYwecL08BTTQixEnprOQAAAHM"]
[Thu Sep 17 15:16:49.118087 2026] [security2:error] [pid 971102:tid 971261] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxYwecL08BTTQixEnprOgAAABs"]
[Thu Sep 17 15:16:49.242595 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxYwecL08BTTQixEnprQQAAAG4"]
[Thu Sep 17 15:16:49.242601 2026] [security2:error] [pid 971102:tid 971260] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/dev/.env"] [unique_id "aqxYwecL08BTTQixEnprQgAAABo"]
[Thu Sep 17 15:16:49.301914 2026] [security2:error] [pid 971102:tid 971284] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxYwecL08BTTQixEnprRQAAADI"]
[Thu Sep 17 15:16:49.308625 2026] [security2:error] [pid 971102:tid 971272] [client 20.255.75.24:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/k.php"] [unique_id "aqxYwecL08BTTQixEnprRgAAACY"]
[Thu Sep 17 15:16:49.315350 2026] [security2:error] [pid 971102:tid 971241] [client 134.185.85.61:63592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYwecL08BTTQixEnprRwAAAAc"]
[Thu Sep 17 15:16:49.317636 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxYwecL08BTTQixEnprSAAAAGg"]
[Thu Sep 17 15:16:49.363804 2026] [security2:error] [pid 971102:tid 971299] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxYwecL08BTTQixEnprSQAAAEE"]
[Thu Sep 17 15:16:49.367848 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/staging/.env"] [unique_id "aqxYwecL08BTTQixEnprSwAAAHk"]
[Thu Sep 17 15:16:49.398923 2026] [security2:error] [pid 971102:tid 971306] [client 172.239.147.162:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-filter-sentinel.php"] [unique_id "aqxYwecL08BTTQixEnprTAAAAEg"], referer: binance.com
[Thu Sep 17 15:16:49.423987 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxYwecL08BTTQixEnprTQAAAFE"]
[Thu Sep 17 15:16:49.499163 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/opt/.env"] [unique_id "aqxYwecL08BTTQixEnprTwAAAHU"]
[Thu Sep 17 15:16:49.549463 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/core/.env"] [unique_id "aqxYwecL08BTTQixEnprUAAAAFw"]
[Thu Sep 17 15:16:49.570581 2026] [security2:error] [pid 971102:tid 971310] [client 216.244.91.82:65193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYwecL08BTTQixEnprQwAAAEw"]
[Thu Sep 17 15:16:49.607372 2026] [security2:error] [pid 971102:tid 971356] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxYwecL08BTTQixEnprVQAAAHo"]
[Thu Sep 17 15:16:49.623388 2026] [security2:error] [pid 971102:tid 971350] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/laravel/.env"] [unique_id "aqxYwecL08BTTQixEnprVgAAAHQ"]
[Thu Sep 17 15:16:49.664901 2026] [security2:error] [pid 971102:tid 971312] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxYwecL08BTTQixEnprVwAAAE4"]
[Thu Sep 17 15:16:49.711305 2026] [security2:error] [pid 971102:tid 971237] [client 134.185.85.61:60547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYwecL08BTTQixEnprXAAAAAM"]
[Thu Sep 17 15:16:49.722396 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxYwecL08BTTQixEnprXgAAADw"]
[Thu Sep 17 15:16:49.747557 2026] [security2:error] [pid 971102:tid 971273] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/symfony/.env"] [unique_id "aqxYwecL08BTTQixEnprXwAAACc"]
[Thu Sep 17 15:16:49.783224 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/core/app/.env"] [unique_id "aqxYwecL08BTTQixEnprYAAAAHA"]
[Thu Sep 17 15:16:49.783655 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxYwecL08BTTQixEnprYQAAAGQ"]
[Thu Sep 17 15:16:49.793432 2026] [security2:error] [pid 971102:tid 971305] [client 20.255.75.24:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/autoload_classmap.php"] [unique_id "aqxYwecL08BTTQixEnprYgAAAEc"]
[Thu Sep 17 15:16:49.850563 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxYwecL08BTTQixEnprZAAAAFQ"]
[Thu Sep 17 15:16:49.875327 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/wordpress/.env"] [unique_id "aqxYwecL08BTTQixEnprZgAAAF4"]
[Thu Sep 17 15:16:49.909702 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxYwecL08BTTQixEnprZwAAAAk"]
[Thu Sep 17 15:16:49.969743 2026] [security2:error] [pid 971102:tid 971313] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxYwecL08BTTQixEnpraAAAAE8"]
[Thu Sep 17 15:16:50.001472 2026] [security2:error] [pid 971102:tid 971296] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/wp/.env"] [unique_id "aqxYwecL08BTTQixEnpraQAAAD4"]
[Thu Sep 17 15:16:50.017822 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxYwucL08BTTQixEnpragAAAH4"]
[Thu Sep 17 15:16:50.126737 2026] [security2:error] [pid 971102:tid 971266] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cms/.env"] [unique_id "aqxYwucL08BTTQixEnprawAAACA"]
[Thu Sep 17 15:16:50.144201 2026] [security2:error] [pid 971102:tid 971289] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxYwucL08BTTQixEnprbAAAADc"]
[Thu Sep 17 15:16:50.199499 2026] [security2:error] [pid 971102:tid 971320] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxYwucL08BTTQixEnprcAAAAFY"]
[Thu Sep 17 15:16:50.252198 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/private/.env"] [unique_id "aqxYwucL08BTTQixEnprdQAAACU"]
[Thu Sep 17 15:16:50.254239 2026] [security2:error] [pid 971102:tid 971242] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxYwucL08BTTQixEnprdwAAAAg"]
[Thu Sep 17 15:16:50.259316 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/drupal/.env"] [unique_id "aqxYwucL08BTTQixEnpreAAAABE"]
[Thu Sep 17 15:16:50.271609 2026] [security2:error] [pid 971102:tid 971277] [client 20.255.75.24:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/profile.php"] [unique_id "aqxYwucL08BTTQixEnpreQAAACs"]
[Thu Sep 17 15:16:50.310072 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxYwucL08BTTQixEnpregAAAGA"]
[Thu Sep 17 15:16:50.365605 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxYwucL08BTTQixEnprgQAAACQ"]
[Thu Sep 17 15:16:50.393554 2026] [security2:error] [pid 971102:tid 971267] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/joomla/.env"] [unique_id "aqxYwucL08BTTQixEnprggAAACE"]
[Thu Sep 17 15:16:50.421404 2026] [security2:error] [pid 971102:tid 971349] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxYwucL08BTTQixEnprgwAAAHM"]
[Thu Sep 17 15:16:50.476743 2026] [security2:error] [pid 971102:tid 971263] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxYwucL08BTTQixEnprhwAAAB0"]
[Thu Sep 17 15:16:50.480607 2026] [security2:error] [pid 971102:tid 971278] [client 172.239.147.162:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxYwucL08BTTQixEnpriAAAACw"], referer: binance.com
[Thu Sep 17 15:16:50.486167 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxYwucL08BTTQixEnpriQAAABg"]
[Thu Sep 17 15:16:50.523772 2026] [security2:error] [pid 971102:tid 971293] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/magento/.env"] [unique_id "aqxYwucL08BTTQixEnprjAAAADs"]
[Thu Sep 17 15:16:50.532469 2026] [security2:error] [pid 971102:tid 971236] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxYwucL08BTTQixEnprjQAAAAI"]
[Thu Sep 17 15:16:50.587840 2026] [security2:error] [pid 971102:tid 971284] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxYwucL08BTTQixEnprjgAAADI"]
[Thu Sep 17 15:16:50.638267 2026] [security2:error] [pid 971102:tid 971264] [client 172.239.147.162:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxYwucL08BTTQixEnprkAAAAB4"], referer: binance.com
[Thu Sep 17 15:16:50.647972 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxYwucL08BTTQixEnprkQAAAGg"]
[Thu Sep 17 15:16:50.707226 2026] [security2:error] [pid 971102:tid 971262] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxYwucL08BTTQixEnprlgAAABw"]
[Thu Sep 17 15:16:50.713575 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bootstrap/.env"] [unique_id "aqxYwucL08BTTQixEnprmQAAAEg"]
[Thu Sep 17 15:16:50.761552 2026] [security2:error] [pid 971102:tid 971272] [client 20.255.75.24:1051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/server.php"] [unique_id "aqxYwucL08BTTQixEnprmgAAACY"]
[Thu Sep 17 15:16:50.764044 2026] [security2:error] [pid 971102:tid 971348] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxYwucL08BTTQixEnprmwAAAHI"]
[Thu Sep 17 15:16:50.820706 2026] [security2:error] [pid 971102:tid 971280] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxYwucL08BTTQixEnprnAAAAC4"]
[Thu Sep 17 15:16:50.876710 2026] [security2:error] [pid 971102:tid 971354] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxYwucL08BTTQixEnprnQAAAHg"]
[Thu Sep 17 15:16:50.912287 2026] [security2:error] [pid 971102:tid 971276] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/shopify/.env"] [unique_id "aqxYwucL08BTTQixEnprnwAAACo"]
[Thu Sep 17 15:16:50.933435 2026] [security2:error] [pid 971102:tid 971329] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxYwucL08BTTQixEnproAAAAF8"]
[Thu Sep 17 15:16:50.947759 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/database/.env"] [unique_id "aqxYwucL08BTTQixEnproQAAAHo"]
[Thu Sep 17 15:16:50.988584 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxYwucL08BTTQixEnprowAAAHQ"]
[Thu Sep 17 15:16:51.036737 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/prestashop/.env"] [unique_id "aqxYw-cL08BTTQixEnprpQAAAAM"]
[Thu Sep 17 15:16:51.044061 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxYw-cL08BTTQixEnprpgAAADw"]
[Thu Sep 17 15:16:51.101637 2026] [security2:error] [pid 971102:tid 971273] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxYw-cL08BTTQixEnprqAAAACc"]
[Thu Sep 17 15:16:51.156085 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxYw-cL08BTTQixEnprrAAAAFQ"]
[Thu Sep 17 15:16:51.156086 2026] [security2:error] [pid 971102:tid 971305] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/codeigniter/.env"] [unique_id "aqxYw-cL08BTTQixEnprqwAAAEc"]
[Thu Sep 17 15:16:51.175804 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/storage/.env"] [unique_id "aqxYw-cL08BTTQixEnprrgAAAF4"]
[Thu Sep 17 15:16:51.211844 2026] [security2:error] [pid 971102:tid 971361] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxYw-cL08BTTQixEnprsAAAAH8"]
[Thu Sep 17 15:16:51.245288 2026] [security2:error] [pid 971102:tid 971358] [client 20.255.75.24:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/shell.php"] [unique_id "aqxYw-cL08BTTQixEnprtAAAAHw"]
[Thu Sep 17 15:16:51.268413 2026] [security2:error] [pid 971102:tid 971291] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxYw-cL08BTTQixEnprtgAAADk"]
[Thu Sep 17 15:16:51.286319 2026] [security2:error] [pid 971102:tid 971313] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cakephp/.env"] [unique_id "aqxYw-cL08BTTQixEnprtwAAAE8"]
[Thu Sep 17 15:16:51.326009 2026] [security2:error] [pid 971102:tid 971300] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxYw-cL08BTTQixEnpruAAAAEI"]
[Thu Sep 17 15:16:51.382263 2026] [security2:error] [pid 971102:tid 971360] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxYw-cL08BTTQixEnpruQAAAH4"]
[Thu Sep 17 15:16:51.409860 2026] [security2:error] [pid 971102:tid 971281] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxYw-cL08BTTQixEnprugAAAC8"]
[Thu Sep 17 15:16:51.416280 2026] [security2:error] [pid 971102:tid 971320] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/zend/.env"] [unique_id "aqxYw-cL08BTTQixEnprvAAAAFY"]
[Thu Sep 17 15:16:51.438166 2026] [security2:error] [pid 971102:tid 971331] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxYw-cL08BTTQixEnprvQAAAGE"]
[Thu Sep 17 15:16:51.493943 2026] [security2:error] [pid 971102:tid 971254] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxYw-cL08BTTQixEnprvwAAABQ"]
[Thu Sep 17 15:16:51.502725 2026] [security2:error] [pid 971102:tid 971319] [client 185.55.149.49:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYw-cL08BTTQixEnprvgAAAFU"]
[Thu Sep 17 15:16:51.502842 2026] [security2:error] [pid 971102:tid 971319] [client 185.55.149.49:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYw-cL08BTTQixEnprvgAAAFU"]
[Thu Sep 17 15:16:51.551222 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/yii/.env"] [unique_id "aqxYw-cL08BTTQixEnprwAAAAEQ"]
[Thu Sep 17 15:16:51.554290 2026] [security2:error] [pid 971102:tid 971257] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxYw-cL08BTTQixEnprwQAAABc"]
[Thu Sep 17 15:16:51.565540 2026] [security2:error] [pid 971102:tid 971244] [client 162.241.226.11:23990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYw-cL08BTTQixEnpruwAAAAo"]
[Thu Sep 17 15:16:51.617765 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxYw-cL08BTTQixEnprwwAAACQ"]
[Thu Sep 17 15:16:51.643327 2026] [security2:error] [pid 971102:tid 971259] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxYw-cL08BTTQixEnprxgAAABk"]
[Thu Sep 17 15:16:51.674681 2026] [security2:error] [pid 971102:tid 971286] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/laravel5/.env"] [unique_id "aqxYw-cL08BTTQixEnpryAAAADQ"]
[Thu Sep 17 15:16:51.684824 2026] [security2:error] [pid 971102:tid 971342] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxYw-cL08BTTQixEnpryQAAAGw"]
[Thu Sep 17 15:16:51.742138 2026] [security2:error] [pid 971102:tid 971327] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxYw-cL08BTTQixEnprzgAAAF0"]
[Thu Sep 17 15:16:51.758580 2026] [security2:error] [pid 971102:tid 971277] [client 20.255.75.24:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/t.php"] [unique_id "aqxYw-cL08BTTQixEnpr0AAAACs"]
[Thu Sep 17 15:16:51.786157 2026] [security2:error] [pid 971102:tid 971292] [client 172.239.147.162:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxYw-cL08BTTQixEnpr0QAAADo"], referer: binance.com
[Thu Sep 17 15:16:51.797596 2026] [security2:error] [pid 971102:tid 971347] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/v1/.env"] [unique_id "aqxYw-cL08BTTQixEnpr0gAAAHE"]
[Thu Sep 17 15:16:51.801702 2026] [security2:error] [pid 971102:tid 971314] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxYw-cL08BTTQixEnpr0wAAAFA"]
[Thu Sep 17 15:16:51.810860 2026] [security2:error] [pid 971102:tid 971269] [client 162.241.226.11:24004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYw-cL08BTTQixEnprxAAAACM"]
[Thu Sep 17 15:16:51.830331 2026] [security2:error] [pid 971102:tid 971249] [client 172.239.147.162:58812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-icon-collections-registry.php"] [unique_id "aqxYw-cL08BTTQixEnpr1QAAAA8"], referer: binance.com
[Thu Sep 17 15:16:51.857461 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxYw-cL08BTTQixEnpr1gAAAG4"]
[Thu Sep 17 15:16:51.876873 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxYw-cL08BTTQixEnpr1wAAAAc"]
[Thu Sep 17 15:16:51.913575 2026] [security2:error] [pid 971102:tid 971317] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxYw-cL08BTTQixEnpr2AAAAFM"]
[Thu Sep 17 15:16:51.916236 2026] [security2:error] [pid 971102:tid 971321] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/v2/.env"] [unique_id "aqxYw-cL08BTTQixEnpr2QAAAFc"]
[Thu Sep 17 15:16:51.969619 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxYw-cL08BTTQixEnpr2gAAAGk"]
[Thu Sep 17 15:16:52.025014 2026] [security2:error] [pid 971102:tid 971295] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxYxOcL08BTTQixEnpr3QAAAD0"]
[Thu Sep 17 15:16:52.036382 2026] [security2:error] [pid 971102:tid 971262] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/v3/.env"] [unique_id "aqxYxOcL08BTTQixEnpr3gAAABw"]
[Thu Sep 17 15:16:52.090866 2026] [security2:error] [pid 971102:tid 971355] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxYxOcL08BTTQixEnpr4QAAAHk"]
[Thu Sep 17 15:16:52.095759 2026] [security2:error] [pid 971102:tid 971188] [remote 216.73.217.142:60157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxYxOcL08BTTQixEnpr4gAAVFM"]
[Thu Sep 17 15:16:52.104889 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/release/.env"] [unique_id "aqxYxOcL08BTTQixEnpr4wAAAH8"]
[Thu Sep 17 15:16:52.147070 2026] [security2:error] [pid 971102:tid 971308] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxYxOcL08BTTQixEnpr5QAAAEo"]
[Thu Sep 17 15:16:52.160027 2026] [security2:error] [pid 971102:tid 971275] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/v1/.env"] [unique_id "aqxYxOcL08BTTQixEnpr6AAAACk"]
[Thu Sep 17 15:16:52.202121 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxYxOcL08BTTQixEnpr6gAAAFE"]
[Thu Sep 17 15:16:52.215727 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxYxOcL08BTTQixEnpr6wAAAGY"]
[Thu Sep 17 15:16:52.222310 2026] [security2:error] [pid 971102:tid 971348] [client 45.169.98.18:57541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxOcL08BTTQixEnpr7AAAAHI"]
[Thu Sep 17 15:16:52.222395 2026] [security2:error] [pid 971102:tid 971348] [client 45.169.98.18:57541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxOcL08BTTQixEnpr7AAAAHI"]
[Thu Sep 17 15:16:52.238953 2026] [security2:error] [pid 971102:tid 971272] [client 20.255.75.24:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/hello.php"] [unique_id "aqxYxOcL08BTTQixEnpr7QAAACY"]
[Thu Sep 17 15:16:52.259011 2026] [security2:error] [pid 971102:tid 971280] [client 3.82.141.143:20710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php.save"] [unique_id "aqxYxOcL08BTTQixEnpr8AAAAC4"]
[Thu Sep 17 15:16:52.260026 2026] [security2:error] [pid 971102:tid 971240] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxYxOcL08BTTQixEnpr7gAAAAY"]
[Thu Sep 17 15:16:52.270549 2026] [security2:error] [pid 971102:tid 971237] [client 3.82.141.143:20632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/config.php"] [unique_id "aqxYxOcL08BTTQixEnpr8wAAAAM"]
[Thu Sep 17 15:16:52.271458 2026] [security2:error] [pid 971102:tid 971299] [client 3.82.141.143:20510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env"] [unique_id "aqxYxOcL08BTTQixEnpr8gAAAEE"]
[Thu Sep 17 15:16:52.271489 2026] [security2:error] [pid 971102:tid 971354] [client 3.82.141.143:20674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php.old"] [unique_id "aqxYxOcL08BTTQixEnpr9wAAAHg"]
[Thu Sep 17 15:16:52.271493 2026] [security2:error] [pid 971102:tid 971245] [client 3.82.141.143:20706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php~"] [unique_id "aqxYxOcL08BTTQixEnpr-AAAAAs"]
[Thu Sep 17 15:16:52.271760 2026] [security2:error] [pid 971102:tid 971310] [client 3.82.141.143:20694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-config.php"] [unique_id "aqxYxOcL08BTTQixEnpr9gAAAEw"]
[Thu Sep 17 15:16:52.271977 2026] [security2:error] [pid 971102:tid 971276] [client 3.82.141.143:20606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env.bak"] [unique_id "aqxYxOcL08BTTQixEnpr9AAAACo"]
[Thu Sep 17 15:16:52.272598 2026] [security2:error] [pid 971102:tid 971256] [client 3.82.141.143:20588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env.old"] [unique_id "aqxYxOcL08BTTQixEnpr-QAAABY"]
[Thu Sep 17 15:16:52.284239 2026] [security2:error] [pid 971102:tid 971300] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/v2/.env"] [unique_id "aqxYxOcL08BTTQixEnpsAgAAAEI"]
[Thu Sep 17 15:16:52.299434 2026] [security2:error] [pid 971102:tid 971358] [client 3.82.141.143:20682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYxOcL08BTTQixEnpsBAAAAHw"]
[Thu Sep 17 15:16:52.305462 2026] [security2:error] [pid 971102:tid 971285] [client 3.82.141.143:20572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env.backup"] [unique_id "aqxYxOcL08BTTQixEnpsBQAAADM"]
[Thu Sep 17 15:16:52.316933 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxYxOcL08BTTQixEnpsBgAAACA"]
[Thu Sep 17 15:16:52.343486 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/releases/.env"] [unique_id "aqxYxOcL08BTTQixEnpsCAAAAFY"]
[Thu Sep 17 15:16:52.374271 2026] [security2:error] [pid 971102:tid 971251] [client 34.154.67.31:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxYxOcL08BTTQixEnpsCgAAABE"]
[Thu Sep 17 15:16:52.375463 2026] [security2:error] [pid 971102:tid 971307] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxYxOcL08BTTQixEnpsCwAAAEk"]
[Thu Sep 17 15:16:52.405197 2026] [security2:error] [pid 971102:tid 971341] [client 3.82.141.143:20668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr7wAAAGs"]
[Thu Sep 17 15:16:52.405278 2026] [security2:error] [pid 971102:tid 971270] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/rest/.env"] [unique_id "aqxYxOcL08BTTQixEnpsDwAAACQ"]
[Thu Sep 17 15:16:52.410682 2026] [security2:error] [pid 971102:tid 971350] [client 3.82.141.143:20506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr_QAAAHQ"]
[Thu Sep 17 15:16:52.410768 2026] [security2:error] [pid 971102:tid 971265] [client 3.82.141.143:20526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr9QAAAB8"]
[Thu Sep 17 15:16:52.411477 2026] [security2:error] [pid 971102:tid 971351] [client 3.82.141.143:20612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr-gAAAHU"]
[Thu Sep 17 15:16:52.411764 2026] [security2:error] [pid 971102:tid 971305] [client 3.82.141.143:20558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsAAAAAEc"]
[Thu Sep 17 15:16:52.412128 2026] [security2:error] [pid 971102:tid 971294] [client 3.82.141.143:20602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr_AAAADw"]
[Thu Sep 17 15:16:52.413486 2026] [security2:error] [pid 971102:tid 971273] [client 3.82.141.143:20622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr_gAAACc"]
[Thu Sep 17 15:16:52.426755 2026] [security2:error] [pid 971102:tid 971328] [client 3.82.141.143:20542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsAwAAAF4"]
[Thu Sep 17 15:16:52.432163 2026] [security2:error] [pid 971102:tid 971337] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxYxOcL08BTTQixEnpsEgAAAGc"]
[Thu Sep 17 15:16:52.468744 2026] [security2:error] [pid 971102:tid 971274] [client 3.82.141.143:20736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsBwAAACg"]
[Thu Sep 17 15:16:52.491365 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxYxOcL08BTTQixEnpsEwAAABk"]
[Thu Sep 17 15:16:52.526273 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/graphql/.env"] [unique_id "aqxYxOcL08BTTQixEnpsGAAAAHM"]
[Thu Sep 17 15:16:52.549304 2026] [security2:error] [pid 971102:tid 971271] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxYxOcL08BTTQixEnpsIAAAACU"]
[Thu Sep 17 15:16:52.560070 2026] [security2:error] [pid 971102:tid 971284] [client 3.82.141.143:20558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/web.config"] [unique_id "aqxYxOcL08BTTQixEnpsLAAAADI"]
[Thu Sep 17 15:16:52.579797 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shared/.env"] [unique_id "aqxYxOcL08BTTQixEnpsLgAAAAU"]
[Thu Sep 17 15:16:52.608699 2026] [security2:error] [pid 971102:tid 971317] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxYxOcL08BTTQixEnpsMAAAAFM"]
[Thu Sep 17 15:16:52.649115 2026] [security2:error] [pid 971102:tid 971303] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/gateway/.env"] [unique_id "aqxYxOcL08BTTQixEnpsMQAAAEU"]
[Thu Sep 17 15:16:52.665619 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxYxOcL08BTTQixEnpsMgAAAGk"]
[Thu Sep 17 15:16:52.721798 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxYxOcL08BTTQixEnpsNQAAAFQ"]
[Thu Sep 17 15:16:52.774535 2026] [security2:error] [pid 971102:tid 971336] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/microservice/.env"] [unique_id "aqxYxOcL08BTTQixEnpsNgAAAGY"]
[Thu Sep 17 15:16:52.777531 2026] [security2:error] [pid 971102:tid 971348] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxYxOcL08BTTQixEnpsNwAAAHI"]
[Thu Sep 17 15:16:52.810880 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/deploy/.env"] [unique_id "aqxYxOcL08BTTQixEnpsOAAAAAY"]
[Thu Sep 17 15:16:52.839144 2026] [security2:error] [pid 971102:tid 971306] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxYxOcL08BTTQixEnpsOQAAAEg"]
[Thu Sep 17 15:16:52.893312 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/service/.env"] [unique_id "aqxYxOcL08BTTQixEnpsOwAAAHw"]
[Thu Sep 17 15:16:52.895433 2026] [security2:error] [pid 971102:tid 971296] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxYxOcL08BTTQixEnpsPAAAAD4"]
[Thu Sep 17 15:16:52.951148 2026] [security2:error] [pid 971102:tid 971234] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxYxOcL08BTTQixEnpsPgAAAAA"]
[Thu Sep 17 15:16:52.967595 2026] [security2:error] [pid 971102:tid 971315] [client 172.239.147.162:56661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxYxOcL08BTTQixEnpsPwAAAFE"], referer: binance.com
[Thu Sep 17 15:16:53.008925 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxYxecL08BTTQixEnpsQAAAACA"]
[Thu Sep 17 15:16:53.023200 2026] [security2:error] [pid 971102:tid 971254] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/v3/.env"] [unique_id "aqxYxecL08BTTQixEnpsQQAAABQ"]
[Thu Sep 17 15:16:53.045300 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/build/.env"] [unique_id "aqxYxecL08BTTQixEnpsQgAAAFU"]
[Thu Sep 17 15:16:53.060281 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:46126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxYxecL08BTTQixEnpsQwAAADM"]
[Thu Sep 17 15:16:53.072449 2026] [security2:error] [pid 971102:tid 971302] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxYxecL08BTTQixEnpsRAAAAEQ"]
[Thu Sep 17 15:16:53.136798 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxYxecL08BTTQixEnpsRQAAAAo"]
[Thu Sep 17 15:16:53.152515 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/dev/.env"] [unique_id "aqxYxecL08BTTQixEnpsRgAAABE"]
[Thu Sep 17 15:16:53.194060 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxYxecL08BTTQixEnpsSQAAACQ"]
[Thu Sep 17 15:16:53.251732 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxYxecL08BTTQixEnpsTQAAADw"]
[Thu Sep 17 15:16:53.257555 2026] [security2:error] [pid 971102:tid 971243] [client 3.82.141.143:20794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsFQAAAAk"]
[Thu Sep 17 15:16:53.261016 2026] [security2:error] [pid 971102:tid 971326] [client 154.190.208.131:42527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsTgAAAFw"]
[Thu Sep 17 15:16:53.261159 2026] [security2:error] [pid 971102:tid 971326] [client 154.190.208.131:42527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsTgAAAFw"]
[Thu Sep 17 15:16:53.276269 2026] [security2:error] [pid 971102:tid 971316] [client 3.82.141.143:20746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsGQAAAFI"]
[Thu Sep 17 15:16:53.279291 2026] [security2:error] [pid 971102:tid 971337] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/staging/.env"] [unique_id "aqxYxecL08BTTQixEnpsTwAAAGc"]
[Thu Sep 17 15:16:53.281999 2026] [security2:error] [pid 971102:tid 971259] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dist/.env"] [unique_id "aqxYxecL08BTTQixEnpsUAAAABk"]
[Thu Sep 17 15:16:53.287143 2026] [security2:error] [pid 971102:tid 971290] [client 3.82.141.143:20640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsHgAAADg"]
[Thu Sep 17 15:16:53.287206 2026] [security2:error] [pid 971102:tid 971312] [client 3.82.141.143:20786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsHwAAAE4"]
[Thu Sep 17 15:16:53.289044 2026] [security2:error] [pid 971102:tid 971286] [client 3.82.141.143:20668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsGgAAADQ"]
[Thu Sep 17 15:16:53.302777 2026] [security2:error] [pid 971102:tid 971277] [client 3.82.141.143:20606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsIQAAACs"]
[Thu Sep 17 15:16:53.303387 2026] [security2:error] [pid 971102:tid 971292] [client 3.82.141.143:20510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsIgAAADo"]
[Thu Sep 17 15:16:53.304336 2026] [security2:error] [pid 971102:tid 971332] [client 3.82.141.143:20770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsFwAAAGI"]
[Thu Sep 17 15:16:53.312000 2026] [security2:error] [pid 971102:tid 971282] [client 3.82.141.143:20814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJQAAADA"]
[Thu Sep 17 15:16:53.323216 2026] [security2:error] [pid 971102:tid 971278] [client 3.82.141.143:20602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsKwAAACw"]
[Thu Sep 17 15:16:53.325607 2026] [security2:error] [pid 971102:tid 971359] [client 3.82.141.143:20816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJAAAAH0"]
[Thu Sep 17 15:16:53.325744 2026] [security2:error] [pid 971102:tid 971260] [client 3.82.141.143:20588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJwAAABo"]
[Thu Sep 17 15:16:53.336292 2026] [security2:error] [pid 971102:tid 971269] [client 3.82.141.143:20652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJgAAACM"]
[Thu Sep 17 15:16:53.408507 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/vendor/.env"] [unique_id "aqxYxecL08BTTQixEnpsVAAAAAI"]
[Thu Sep 17 15:16:53.428280 2026] [security2:error] [pid 971102:tid 971258] [client 34.24.217.248:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/info.php"] [unique_id "aqxYxecL08BTTQixEnpsVgAAABg"]
[Thu Sep 17 15:16:53.480533 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxYxecL08BTTQixEnpsWAAAACc"], referer: binance.com
[Thu Sep 17 15:16:53.515504 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxYxecL08BTTQixEnpsWQAAAAU"]
[Thu Sep 17 15:16:53.527866 2026] [security2:error] [pid 971102:tid 971327] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/lib/.env"] [unique_id "aqxYxecL08BTTQixEnpsWgAAAF0"]
[Thu Sep 17 15:16:53.611180 2026] [security2:error] [pid 971102:tid 971263] [client 34.24.217.248:49254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/php.php"] [unique_id "aqxYxecL08BTTQixEnpsXgAAAB0"]
[Thu Sep 17 15:16:53.655041 2026] [security2:error] [pid 971102:tid 971295] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/resources/.env"] [unique_id "aqxYxecL08BTTQixEnpsYQAAAD0"]
[Thu Sep 17 15:16:53.753597 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/htdocs/.env"] [unique_id "aqxYxecL08BTTQixEnpsZwAAAEg"]
[Thu Sep 17 15:16:53.787622 2026] [security2:error] [pid 971102:tid 971280] [client 34.24.217.248:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/i.php"] [unique_id "aqxYxecL08BTTQixEnpsbAAAAC4"]
[Thu Sep 17 15:16:53.796786 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/assets/.env"] [unique_id "aqxYxecL08BTTQixEnpsbQAAAC0"]
[Thu Sep 17 15:16:53.842299 2026] [security2:error] [pid 971102:tid 971317] [client 114.198.138.124:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsbwAAAFM"]
[Thu Sep 17 15:16:53.842384 2026] [security2:error] [pid 971102:tid 971317] [client 114.198.138.124:62935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsbwAAAFM"]
[Thu Sep 17 15:16:53.871676 2026] [security2:error] [pid 971102:tid 971238] [client 193.124.20.178:55590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr5AAAAAQ"], referer: https://bigsisterteams.com/contact/
[Thu Sep 17 15:16:53.918169 2026] [security2:error] [pid 971102:tid 971266] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/uploads/.env"] [unique_id "aqxYxecL08BTTQixEnpscQAAACA"]
[Thu Sep 17 15:16:53.934335 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env"] [unique_id "aqxYxecL08BTTQixEnpscgAAAFY"]
[Thu Sep 17 15:16:53.973888 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxYxecL08BTTQixEnpscwAAAFE"]
[Thu Sep 17 15:16:53.989678 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/www/.env"] [unique_id "aqxYxecL08BTTQixEnpsdAAAAFU"]
[Thu Sep 17 15:16:54.048284 2026] [security2:error] [pid 971102:tid 971356] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/internal/.env"] [unique_id "aqxYxucL08BTTQixEnpseAAAAHo"]
[Thu Sep 17 15:16:54.049249 2026] [security2:error] [pid 971102:tid 971261] [client 172.239.147.162:53233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxYxucL08BTTQixEnpseQAAABs"], referer: binance.com
[Thu Sep 17 15:16:54.160941 2026] [security2:error] [pid 971102:tid 971313] [client 34.24.217.248:49278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxYxucL08BTTQixEnpsfAAAAE8"]
[Thu Sep 17 15:16:54.183385 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/tools/.env"] [unique_id "aqxYxucL08BTTQixEnpsfwAAAEM"]
[Thu Sep 17 15:16:54.225603 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/html/.env"] [unique_id "aqxYxucL08BTTQixEnpsgQAAAEc"]
[Thu Sep 17 15:16:54.318370 2026] [security2:error] [pid 971102:tid 971312] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/scripts/.env"] [unique_id "aqxYxucL08BTTQixEnpsiAAAAE4"]
[Thu Sep 17 15:16:54.348612 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/test.php"] [unique_id "aqxYxucL08BTTQixEnpsiQAAAHQ"]
[Thu Sep 17 15:16:54.381870 2026] [security2:error] [pid 971102:tid 971292] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.bak"] [unique_id "aqxYxucL08BTTQixEnpsiwAAADo"]
[Thu Sep 17 15:16:54.456350 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.backup"] [unique_id "aqxYxucL08BTTQixEnpsjAAAACU"]
[Thu Sep 17 15:16:54.458614 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/live/.env"] [unique_id "aqxYxucL08BTTQixEnpsjQAAAHE"]
[Thu Sep 17 15:16:54.459134 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/bin/.env"] [unique_id "aqxYxucL08BTTQixEnpsjgAAABg"]
[Thu Sep 17 15:16:54.586510 2026] [security2:error] [pid 971102:tid 971264] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.old"] [unique_id "aqxYxucL08BTTQixEnpskQAAAB4"]
[Thu Sep 17 15:16:54.589281 2026] [security2:error] [pid 971102:tid 971341] [client 34.24.217.248:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/p.php"] [unique_id "aqxYxucL08BTTQixEnpskwAAAGs"]
[Thu Sep 17 15:16:54.591291 2026] [security2:error] [pid 971102:tid 971307] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sbin/.env"] [unique_id "aqxYxucL08BTTQixEnpslAAAAEk"]
[Thu Sep 17 15:16:54.700933 2026] [security2:error] [pid 971102:tid 971331] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxYxucL08BTTQixEnpsnQAAAGE"]
[Thu Sep 17 15:16:54.723029 2026] [security2:error] [pid 971102:tid 971295] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/local/.env"] [unique_id "aqxYxucL08BTTQixEnpsnwAAAD0"]
[Thu Sep 17 15:16:54.733963 2026] [security2:error] [pid 971102:tid 971277] [client 186.105.232.15:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxucL08BTTQixEnpsoAAAACs"]
[Thu Sep 17 15:16:54.734087 2026] [security2:error] [pid 971102:tid 971277] [client 186.105.232.15:52718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxucL08BTTQixEnpsoAAAACs"]
[Thu Sep 17 15:16:54.773539 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxYxucL08BTTQixEnpsowAAAGk"]
[Thu Sep 17 15:16:54.847703 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/portal/.env"] [unique_id "aqxYxucL08BTTQixEnpsqAAAAA8"]
[Thu Sep 17 15:16:54.935813 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxYxucL08BTTQixEnpsqwAAAEg"]
[Thu Sep 17 15:16:54.937824 2026] [security2:error] [pid 971102:tid 971240] [client 34.24.217.248:49304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxYxucL08BTTQixEnpsrAAAAAY"]
[Thu Sep 17 15:16:54.977204 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/dashboard/.env"] [unique_id "aqxYxucL08BTTQixEnpsrQAAAC0"]
[Thu Sep 17 15:16:55.104388 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/panel/.env"] [unique_id "aqxYx-cL08BTTQixEnpssQAAAGw"]
[Thu Sep 17 15:16:55.123498 2026] [security2:error] [pid 971102:tid 971358] [client 34.24.217.248:49306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnpssgAAAHw"]
[Thu Sep 17 15:16:55.169914 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxYx-cL08BTTQixEnpstAAAAFM"]
[Thu Sep 17 15:16:55.237925 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/crm/.env"] [unique_id "aqxYx-cL08BTTQixEnpsuAAAAAQ"]
[Thu Sep 17 15:16:55.305389 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnpsuwAAACA"]
[Thu Sep 17 15:16:55.323862 2026] [security2:error] [pid 971102:tid 971315] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.swp"] [unique_id "aqxYx-cL08BTTQixEnpsvAAAAFE"]
[Thu Sep 17 15:16:55.326134 2026] [security2:error] [pid 971102:tid 971296] [client 172.239.147.162:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxYx-cL08BTTQixEnpsvQAAAD4"], referer: binance.com
[Thu Sep 17 15:16:55.365399 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/erp/.env"] [unique_id "aqxYx-cL08BTTQixEnpswgAAAHk"]
[Thu Sep 17 15:16:55.378878 2026] [security2:error] [pid 971102:tid 971345] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env~"] [unique_id "aqxYx-cL08BTTQixEnpswwAAAG8"]
[Thu Sep 17 15:16:55.404512 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/opt/.env"] [unique_id "aqxYx-cL08BTTQixEnpsxQAAABs"]
[Thu Sep 17 15:16:55.448464 2026] [security2:error] [pid 971102:tid 971254] [client 172.239.147.162:59119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxYx-cL08BTTQixEnpsxwAAABQ"], referer: binance.com
[Thu Sep 17 15:16:55.490939 2026] [security2:error] [pid 971102:tid 971242] [client 34.24.217.248:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnpsyQAAAAg"]
[Thu Sep 17 15:16:55.500130 2026] [security2:error] [pid 971102:tid 971243] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/shop/.env"] [unique_id "aqxYx-cL08BTTQixEnpsygAAAAk"]
[Thu Sep 17 15:16:55.628362 2026] [security2:error] [pid 971102:tid 971292] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/store/.env"] [unique_id "aqxYx-cL08BTTQixEnpszgAAADo"]
[Thu Sep 17 15:16:55.636531 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxYx-cL08BTTQixEnpszwAAAFo"]
[Thu Sep 17 15:16:55.668875 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:49346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnps0QAAABk"]
[Thu Sep 17 15:16:55.755470 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/saas/.env"] [unique_id "aqxYx-cL08BTTQixEnps1gAAAHU"]
[Thu Sep 17 15:16:55.845096 2026] [security2:error] [pid 971102:tid 971271] [client 34.24.217.248:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnps3AAAACU"]
[Thu Sep 17 15:16:55.864640 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/symfony/.env"] [unique_id "aqxYx-cL08BTTQixEnps4AAAACc"]
[Thu Sep 17 15:16:55.881617 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/client/.env"] [unique_id "aqxYx-cL08BTTQixEnps4QAAAF4"]
[Thu Sep 17 15:16:55.892394 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/app/.env"] [unique_id "aqxYx-cL08BTTQixEnps4gAAAFA"]
[Thu Sep 17 15:16:55.948619 2026] [security2:error] [pid 971102:tid 971341] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/apps/.env"] [unique_id "aqxYx-cL08BTTQixEnps5QAAAGs"]
[Thu Sep 17 15:16:56.000796 2026] [security2:error] [pid 971102:tid 971339] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/project/.env"] [unique_id "aqxYx-cL08BTTQixEnps6AAAAGk"]
[Thu Sep 17 15:16:56.001828 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/.env"] [unique_id "aqxYyOcL08BTTQixEnps6QAAADY"]
[Thu Sep 17 15:16:56.067633 2026] [security2:error] [pid 971102:tid 971249] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/web/.env"] [unique_id "aqxYyOcL08BTTQixEnps7QAAAA8"]
[Thu Sep 17 15:16:56.068584 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxYyOcL08BTTQixEnps7gAAAFQ"]
[Thu Sep 17 15:16:56.121883 2026] [security2:error] [pid 971102:tid 971321] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/admin-panel/.env"] [unique_id "aqxYyOcL08BTTQixEnps7wAAAFc"]
[Thu Sep 17 15:16:56.135589 2026] [security2:error] [pid 971102:tid 971287] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/site/.env"] [unique_id "aqxYyOcL08BTTQixEnps8AAAADU"]
[Thu Sep 17 15:16:56.207538 2026] [security2:error] [pid 971102:tid 971240] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/public/.env"] [unique_id "aqxYyOcL08BTTQixEnps9AAAAAY"]
[Thu Sep 17 15:16:56.229360 2026] [security2:error] [pid 971102:tid 971257] [client 34.24.217.248:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxYyOcL08BTTQixEnps9QAAABc"]
[Thu Sep 17 15:16:56.249080 2026] [security2:error] [pid 971102:tid 971334] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/control-panel/.env"] [unique_id "aqxYyOcL08BTTQixEnps9gAAAGQ"]
[Thu Sep 17 15:16:56.334405 2026] [security2:error] [pid 971102:tid 971256] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/backend/.env"] [unique_id "aqxYyOcL08BTTQixEnps-AAAABY"]
[Thu Sep 17 15:16:56.377870 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/user-panel/.env"] [unique_id "aqxYyOcL08BTTQixEnps_AAAAHM"]
[Thu Sep 17 15:16:56.392055 2026] [security2:error] [pid 971102:tid 971317] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/server/.env"] [unique_id "aqxYyOcL08BTTQixEnps_QAAAFM"]
[Thu Sep 17 15:16:56.407748 2026] [security2:error] [pid 971102:tid 971360] [client 34.24.217.248:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxYyOcL08BTTQixEnps_gAAAH4"]
[Thu Sep 17 15:16:56.454565 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/frontend/.env"] [unique_id "aqxYyOcL08BTTQixEnps_wAAAGY"]
[Thu Sep 17 15:16:56.504448 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/node/.env"] [unique_id "aqxYyOcL08BTTQixEnptAAAAAAQ"]
[Thu Sep 17 15:16:56.505167 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/src/.env"] [unique_id "aqxYyOcL08BTTQixEnptAQAAAFY"]
[Thu Sep 17 15:16:56.512422 2026] [security2:error] [pid 971102:tid 971276] [client 172.239.147.162:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxYyOcL08BTTQixEnptAgAAACo"], referer: binance.com
[Thu Sep 17 15:16:56.565878 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/wordpress/.env"] [unique_id "aqxYyOcL08BTTQixEnptAwAAAC0"]
[Thu Sep 17 15:16:56.568177 2026] [security2:error] [pid 971102:tid 971319] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/core/.env"] [unique_id "aqxYyOcL08BTTQixEnptBAAAAFU"]
[Thu Sep 17 15:16:56.597108 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxYyOcL08BTTQixEnptBQAAAFE"]
[Thu Sep 17 15:16:56.622364 2026] [security2:error] [pid 971102:tid 971285] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/core/app/.env"] [unique_id "aqxYyOcL08BTTQixEnptBgAAADM"]
[Thu Sep 17 15:16:56.638923 2026] [security2:error] [pid 971102:tid 971323] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/express/.env"] [unique_id "aqxYyOcL08BTTQixEnptBwAAAFk"]
[Thu Sep 17 15:16:56.654688 2026] [security2:error] [pid 971102:tid 971335] [client 172.239.147.162:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxYyOcL08BTTQixEnptCAAAAGU"], referer: binance.com
[Thu Sep 17 15:16:56.677592 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/config/.env"] [unique_id "aqxYyOcL08BTTQixEnptCgAAADE"]
[Thu Sep 17 15:16:56.734719 2026] [security2:error] [pid 971102:tid 971313] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/private/.env"] [unique_id "aqxYyOcL08BTTQixEnptDQAAAE8"]
[Thu Sep 17 15:16:56.761584 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/next/.env"] [unique_id "aqxYyOcL08BTTQixEnptDgAAAEM"]
[Thu Sep 17 15:16:56.778458 2026] [security2:error] [pid 971102:tid 971254] [client 34.24.217.248:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxYyOcL08BTTQixEnptDwAAABQ"]
[Thu Sep 17 15:16:56.787488 2026] [security2:error] [pid 971102:tid 971255] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/application/.env"] [unique_id "aqxYyOcL08BTTQixEnptEAAAABU"]
[Thu Sep 17 15:16:56.799721 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/wp/.env"] [unique_id "aqxYyOcL08BTTQixEnptEQAAAAA"]
[Thu Sep 17 15:16:56.840868 2026] [security2:error] [pid 971102:tid 971305] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/bootstrap/.env"] [unique_id "aqxYyOcL08BTTQixEnptFAAAAEc"]
[Thu Sep 17 15:16:56.884974 2026] [security2:error] [pid 971102:tid 971354] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/nuxt/.env"] [unique_id "aqxYyOcL08BTTQixEnptGAAAAHg"]
[Thu Sep 17 15:16:56.910426 2026] [security2:error] [pid 971102:tid 971343] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/database/.env"] [unique_id "aqxYyOcL08BTTQixEnptHAAAAG0"]
[Thu Sep 17 15:16:56.947682 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxYyOcL08BTTQixEnptHQAAAHQ"]
[Thu Sep 17 15:16:56.961487 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/storage/.env"] [unique_id "aqxYyOcL08BTTQixEnptHgAAABk"]
[Thu Sep 17 15:16:57.005172 2026] [security2:error] [pid 971102:tid 971311] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/nest/.env"] [unique_id "aqxYyecL08BTTQixEnptIAAAAE0"]
[Thu Sep 17 15:16:57.023410 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/var/www/.env"] [unique_id "aqxYyecL08BTTQixEnptIgAAACU"]
[Thu Sep 17 15:16:57.036105 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxYyecL08BTTQixEnptIwAAACc"]
[Thu Sep 17 15:16:57.081488 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/var/www/html/.env"] [unique_id "aqxYyecL08BTTQixEnptJAAAAEE"]
[Thu Sep 17 15:16:57.106446 2026] [security2:error] [pid 971102:tid 971351] [client 181.232.156.2:63654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYyecL08BTTQixEnptIQAAdSc"]
[Thu Sep 17 15:16:57.139103 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/react/.env"] [unique_id "aqxYyecL08BTTQixEnptJgAAABg"]
[Thu Sep 17 15:16:57.141827 2026] [security2:error] [pid 971102:tid 971289] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/current/.env"] [unique_id "aqxYyecL08BTTQixEnptJwAAADc"]
[Thu Sep 17 15:16:57.199613 2026] [security2:error] [pid 971102:tid 971295] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/release/.env"] [unique_id "aqxYyecL08BTTQixEnptKwAAAD0"]
[Thu Sep 17 15:16:57.239157 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYyecL08BTTQixEnptMQAAAGg"]
[Thu Sep 17 15:16:57.265361 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/vue/.env"] [unique_id "aqxYyecL08BTTQixEnptNwAAAA8"]
[Thu Sep 17 15:16:57.268428 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/releases/.env"] [unique_id "aqxYyecL08BTTQixEnptOAAAAFQ"]
[Thu Sep 17 15:16:57.271719 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/drupal/.env"] [unique_id "aqxYyecL08BTTQixEnptOQAAADk"]
[Thu Sep 17 15:16:57.333404 2026] [security2:error] [pid 971102:tid 971257] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/shared/.env"] [unique_id "aqxYyecL08BTTQixEnptOgAAABc"]
[Thu Sep 17 15:16:57.387129 2026] [security2:error] [pid 971102:tid 971310] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/deploy/.env"] [unique_id "aqxYyecL08BTTQixEnptQAAAAEw"]
[Thu Sep 17 15:16:57.396251 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/angular/.env"] [unique_id "aqxYyecL08BTTQixEnptQwAAAAs"]
[Thu Sep 17 15:16:57.413467 2026] [security2:error] [pid 971102:tid 971322] [client 34.24.217.248:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptRQAAAFg"]
[Thu Sep 17 15:16:57.450163 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/build/.env"] [unique_id "aqxYyecL08BTTQixEnptSQAAAGY"]
[Thu Sep 17 15:16:57.465947 2026] [security2:error] [pid 971102:tid 971328] [client 156.192.234.52:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYyecL08BTTQixEnptTAAAAF4"]
[Thu Sep 17 15:16:57.466545 2026] [security2:error] [pid 971102:tid 971328] [client 156.192.234.52:49481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYyecL08BTTQixEnptTAAAAF4"]
[Thu Sep 17 15:16:57.506623 2026] [security2:error] [pid 971102:tid 971285] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/joomla/.env"] [unique_id "aqxYyecL08BTTQixEnptTgAAADM"]
[Thu Sep 17 15:16:57.529131 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/svelte/.env"] [unique_id "aqxYyecL08BTTQixEnptUAAAAHk"]
[Thu Sep 17 15:16:57.530206 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/dist/.env"] [unique_id "aqxYyecL08BTTQixEnptUQAAADE"]
[Thu Sep 17 15:16:57.582951 2026] [security2:error] [pid 971102:tid 971335] [client 34.24.217.248:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptVAAAAGU"]
[Thu Sep 17 15:16:57.593711 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/public_html/.env"] [unique_id "aqxYyecL08BTTQixEnptVQAAACQ"]
[Thu Sep 17 15:16:57.654942 2026] [security2:error] [pid 971102:tid 971242] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/vite/.env"] [unique_id "aqxYyecL08BTTQixEnptVgAAAAg"]
[Thu Sep 17 15:16:57.666305 2026] [security2:error] [pid 971102:tid 971234] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/htdocs/.env"] [unique_id "aqxYyecL08BTTQixEnptVwAAAAA"]
[Thu Sep 17 15:16:57.729026 2026] [security2:error] [pid 971102:tid 971286] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/www/.env"] [unique_id "aqxYyecL08BTTQixEnptWQAAADQ"]
[Thu Sep 17 15:16:57.740258 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/magento/.env"] [unique_id "aqxYyecL08BTTQixEnptXAAAABw"]
[Thu Sep 17 15:16:57.763297 2026] [security2:error] [pid 971102:tid 971274] [client 34.24.217.248:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptXQAAACg"]
[Thu Sep 17 15:16:57.774268 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/backup/.env"] [unique_id "aqxYyecL08BTTQixEnptXwAAAHc"]
[Thu Sep 17 15:16:57.791293 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/html/.env"] [unique_id "aqxYyecL08BTTQixEnptYAAAACU"]
[Thu Sep 17 15:16:57.843234 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/live/.env"] [unique_id "aqxYyecL08BTTQixEnptYQAAAEE"]
[Thu Sep 17 15:16:57.897941 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/prod/.env"] [unique_id "aqxYyecL08BTTQixEnptZQAAAFA"]
[Thu Sep 17 15:16:57.929787 2026] [security2:error] [pid 971102:tid 971295] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/backups/.env"] [unique_id "aqxYyecL08BTTQixEnptbAAAAD0"]
[Thu Sep 17 15:16:57.949748 2026] [security2:error] [pid 971102:tid 971250] [client 172.239.147.162:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxYyecL08BTTQixEnptbQAAABA"], referer: binance.com
[Thu Sep 17 15:16:57.954250 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptbgAAAHU"]
[Thu Sep 17 15:16:57.974141 2026] [security2:error] [pid 971102:tid 971338] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/dev/.env"] [unique_id "aqxYyecL08BTTQixEnptbwAAAGg"]
[Thu Sep 17 15:16:57.976372 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shopify/.env"] [unique_id "aqxYyecL08BTTQixEnptcAAAABI"]
[Thu Sep 17 15:16:58.040826 2026] [security2:error] [pid 971102:tid 971267] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/staging/.env"] [unique_id "aqxYyucL08BTTQixEnptcwAAACE"]
[Thu Sep 17 15:16:58.056307 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/old/.env"] [unique_id "aqxYyucL08BTTQixEnptdAAAAHI"]
[Thu Sep 17 15:16:58.100126 2026] [security2:error] [pid 971102:tid 971332] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/opt/.env"] [unique_id "aqxYyucL08BTTQixEnptdQAAAGI"]
[Thu Sep 17 15:16:58.137307 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYyucL08BTTQixEnptdwAAAAo"]
[Thu Sep 17 15:16:58.153008 2026] [security2:error] [pid 971102:tid 971249] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/laravel/.env"] [unique_id "aqxYyucL08BTTQixEnpteAAAAA8"]
[Thu Sep 17 15:16:58.177100 2026] [security2:error] [pid 971102:tid 971243] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/tmp/.env"] [unique_id "aqxYyucL08BTTQixEnpteQAAAAk"]
[Thu Sep 17 15:16:58.206680 2026] [security2:error] [pid 971102:tid 971321] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/symfony/.env"] [unique_id "aqxYyucL08BTTQixEnptegAAAFc"]
[Thu Sep 17 15:16:58.213800 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/prestashop/.env"] [unique_id "aqxYyucL08BTTQixEnptewAAADU"]
[Thu Sep 17 15:16:58.305358 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/temp/.env"] [unique_id "aqxYyucL08BTTQixEnptgAAAAAs"]
[Thu Sep 17 15:16:58.329255 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYyucL08BTTQixEnptggAAAGQ"]
[Thu Sep 17 15:16:58.387852 2026] [security2:error] [pid 971102:tid 971349] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/wordpress/.env"] [unique_id "aqxYyucL08BTTQixEnpthwAAAHM"]
[Thu Sep 17 15:16:58.429785 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/lab/.env"] [unique_id "aqxYyucL08BTTQixEnptjAAAAF4"]
[Thu Sep 17 15:16:58.439746 2026] [security2:error] [pid 971102:tid 971296] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/wp/.env"] [unique_id "aqxYyucL08BTTQixEnptjQAAAD4"]
[Thu Sep 17 15:16:58.452469 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/codeigniter/.env"] [unique_id "aqxYyucL08BTTQixEnptjgAAAFU"]
[Thu Sep 17 15:16:58.479137 2026] [security2:error] [pid 971102:tid 971322] [client 172.239.147.162:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxYyucL08BTTQixEnptjwAAAFg"], referer: binance.com
[Thu Sep 17 15:16:58.514092 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cms/.env"] [unique_id "aqxYyucL08BTTQixEnptkAAAADE"]
[Thu Sep 17 15:16:58.516018 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYyucL08BTTQixEnptkQAAAFE"]
[Thu Sep 17 15:16:58.553546 2026] [security2:error] [pid 971102:tid 971320] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cronlab/.env"] [unique_id "aqxYyucL08BTTQixEnptkgAAAFY"]
[Thu Sep 17 15:16:58.569358 2026] [security2:error] [pid 971102:tid 971335] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/drupal/.env"] [unique_id "aqxYyucL08BTTQixEnptkwAAAGU"]
[Thu Sep 17 15:16:58.629379 2026] [security2:error] [pid 971102:tid 971323] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/joomla/.env"] [unique_id "aqxYyucL08BTTQixEnptlwAAAFk"]
[Thu Sep 17 15:16:58.689295 2026] [security2:error] [pid 971102:tid 971303] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cron/.env"] [unique_id "aqxYyucL08BTTQixEnptmgAAAEU"]
[Thu Sep 17 15:16:58.691091 2026] [security2:error] [pid 971102:tid 971255] [client 34.24.217.248:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYyucL08BTTQixEnptnAAAABU"]
[Thu Sep 17 15:16:58.691958 2026] [security2:error] [pid 971102:tid 971265] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/magento/.env"] [unique_id "aqxYyucL08BTTQixEnptmwAAAB8"]
[Thu Sep 17 15:16:58.693183 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cakephp/.env"] [unique_id "aqxYyucL08BTTQixEnptnQAAAEc"]
[Thu Sep 17 15:16:58.727676 2026] [security2:error] [pid 971102:tid 971247] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxYyecL08BTTQixEnptHwAAAA0"]
[Thu Sep 17 15:16:58.748947 2026] [security2:error] [pid 971102:tid 971262] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/shopify/.env"] [unique_id "aqxYyucL08BTTQixEnptogAAABw"]
[Thu Sep 17 15:16:58.807544 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/prestashop/.env"] [unique_id "aqxYyucL08BTTQixEnptowAAABk"]
[Thu Sep 17 15:16:58.808226 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/en/.env"] [unique_id "aqxYyucL08BTTQixEnptpAAAAHw"]
[Thu Sep 17 15:16:58.856964 2026] [security2:error] [pid 971102:tid 971273] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/codeigniter/.env"] [unique_id "aqxYyucL08BTTQixEnptpwAAACc"]
[Thu Sep 17 15:16:58.863736 2026] [security2:error] [pid 971102:tid 971354] [client 5.49.0.22:60112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYyucL08BTTQixEnptoQAAeGU"]
[Thu Sep 17 15:16:58.864217 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:49474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYyucL08BTTQixEnptqAAAAHc"]
[Thu Sep 17 15:16:58.903549 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cakephp/.env"] [unique_id "aqxYyucL08BTTQixEnptqgAAAFA"]
[Thu Sep 17 15:16:58.926806 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/zend/.env"] [unique_id "aqxYyucL08BTTQixEnptqwAAAHQ"]
[Thu Sep 17 15:16:58.934499 2026] [security2:error] [pid 971102:tid 971357] [client 34.154.67.31:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxYyucL08BTTQixEnptrAAAAHs"]
[Thu Sep 17 15:16:58.949445 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/zend/.env"] [unique_id "aqxYyucL08BTTQixEnptrgAAAGc"]
[Thu Sep 17 15:16:59.003748 2026] [security2:error] [pid 971102:tid 971300] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/yii/.env"] [unique_id "aqxYy-cL08BTTQixEnptrwAAAEI"]
[Thu Sep 17 15:16:59.029187 2026] [security2:error] [pid 971102:tid 971250] [client 34.24.217.248:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYy-cL08BTTQixEnptsQAAABA"]
[Thu Sep 17 15:16:59.048783 2026] [security2:error] [pid 971102:tid 971277] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/laravel5/.env"] [unique_id "aqxYy-cL08BTTQixEnptsgAAACs"]
[Thu Sep 17 15:16:59.054935 2026] [security2:error] [pid 971102:tid 971359] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/administrator/.env"] [unique_id "aqxYyucL08BTTQixEnptrQAAAH0"]
[Thu Sep 17 15:16:59.090892 2026] [security2:error] [pid 971102:tid 971260] [client 34.154.67.31:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env~"] [unique_id "aqxYy-cL08BTTQixEnptswAAABo"]
[Thu Sep 17 15:16:59.101739 2026] [security2:error] [pid 971102:tid 971267] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/v1/.env"] [unique_id "aqxYy-cL08BTTQixEnpttAAAACE"]
[Thu Sep 17 15:16:59.155052 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/v2/.env"] [unique_id "aqxYy-cL08BTTQixEnpttQAAAE4"]
[Thu Sep 17 15:16:59.156346 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/yii/.env"] [unique_id "aqxYy-cL08BTTQixEnpttgAAAFI"]
[Thu Sep 17 15:16:59.183985 2026] [security2:error] [pid 971102:tid 971341] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/psnlink/.env"] [unique_id "aqxYy-cL08BTTQixEnptuQAAAGs"]
[Thu Sep 17 15:16:59.202196 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnptvAAAAGk"]
[Thu Sep 17 15:16:59.210436 2026] [security2:error] [pid 971102:tid 971332] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/v3/.env"] [unique_id "aqxYy-cL08BTTQixEnptvQAAAGI"]
[Thu Sep 17 15:16:59.268985 2026] [security2:error] [pid 971102:tid 971321] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/v1/.env"] [unique_id "aqxYy-cL08BTTQixEnptwwAAAFc"]
[Thu Sep 17 15:16:59.307227 2026] [security2:error] [pid 971102:tid 971293] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/exapi/.env"] [unique_id "aqxYy-cL08BTTQixEnptxQAAADs"]
[Thu Sep 17 15:16:59.317711 2026] [security2:error] [pid 971102:tid 971287] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/v2/.env"] [unique_id "aqxYy-cL08BTTQixEnptxgAAADU"]
[Thu Sep 17 15:16:59.374049 2026] [security2:error] [pid 971102:tid 971269] [client 34.24.217.248:49504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnptyAAAACM"]
[Thu Sep 17 15:16:59.394145 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/laravel5/.env"] [unique_id "aqxYy-cL08BTTQixEnptyQAAAAc"]
[Thu Sep 17 15:16:59.396115 2026] [security2:error] [pid 971102:tid 971236] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/rest/.env"] [unique_id "aqxYy-cL08BTTQixEnptygAAAAI"]
[Thu Sep 17 15:16:59.437454 2026] [security2:error] [pid 971102:tid 971278] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sitemaps/.env"] [unique_id "aqxYy-cL08BTTQixEnptywAAACw"]
[Thu Sep 17 15:16:59.454595 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/graphql/.env"] [unique_id "aqxYy-cL08BTTQixEnptzAAAAAs"]
[Thu Sep 17 15:16:59.529976 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/gateway/.env"] [unique_id "aqxYy-cL08BTTQixEnptzgAAADY"]
[Thu Sep 17 15:16:59.561825 2026] [security2:error] [pid 971102:tid 971317] [client 34.24.217.248:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnpt0gAAAFM"]
[Thu Sep 17 15:16:59.576702 2026] [security2:error] [pid 971102:tid 971328] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/microservice/.env"] [unique_id "aqxYy-cL08BTTQixEnpt0wAAAF4"]
[Thu Sep 17 15:16:59.624855 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxYy-cL08BTTQixEnpt1QAAACo"]
[Thu Sep 17 15:16:59.627887 2026] [security2:error] [pid 971102:tid 971280] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/service/.env"] [unique_id "aqxYy-cL08BTTQixEnpt1gAAAC4"]
[Thu Sep 17 15:16:59.673584 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/v3/.env"] [unique_id "aqxYy-cL08BTTQixEnpt3QAAAFY"]
[Thu Sep 17 15:16:59.714905 2026] [security2:error] [pid 971102:tid 971349] [client 172.239.147.162:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxYy-cL08BTTQixEnpt3wAAAHM"], referer: binance.com
[Thu Sep 17 15:16:59.727769 2026] [security2:error] [pid 971102:tid 971323] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/dev/.env"] [unique_id "aqxYy-cL08BTTQixEnpt4gAAAFk"]
[Thu Sep 17 15:16:59.728600 2026] [security2:error] [pid 971102:tid 971282] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYy-cL08BTTQixEnpt1AAAADA"]
[Thu Sep 17 15:16:59.732918 2026] [security2:error] [pid 971102:tid 971301] [client 34.24.217.248:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnpt5AAAAEM"]
[Thu Sep 17 15:16:59.773210 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/staging/.env"] [unique_id "aqxYy-cL08BTTQixEnpt6gAAAFo"]
[Thu Sep 17 15:16:59.819951 2026] [security2:error] [pid 971102:tid 971326] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/vendor/.env"] [unique_id "aqxYy-cL08BTTQixEnpt6wAAAFw"]
[Thu Sep 17 15:16:59.857488 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxYy-cL08BTTQixEnpt7gAAABs"]
[Thu Sep 17 15:16:59.865140 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/lib/.env"] [unique_id "aqxYy-cL08BTTQixEnpt8AAAAHw"]
[Thu Sep 17 15:16:59.908250 2026] [security2:error] [pid 971102:tid 971286] [client 34.24.217.248:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnpt9QAAADQ"]
[Thu Sep 17 15:16:59.912830 2026] [security2:error] [pid 971102:tid 971353] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/resources/.env"] [unique_id "aqxYy-cL08BTTQixEnpt9gAAAHc"]
[Thu Sep 17 15:16:59.971060 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/assets/.env"] [unique_id "aqxYy-cL08BTTQixEnpt-QAAAGc"]
[Thu Sep 17 15:17:00.049026 2026] [security2:error] [pid 971102:tid 971250] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/uploads/.env"] [unique_id "aqxYzOcL08BTTQixEnpt_wAAABA"]
[Thu Sep 17 15:17:00.081428 2026] [security2:error] [pid 971102:tid 971300] [client 34.24.217.248:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuAQAAAEI"]
[Thu Sep 17 15:17:00.092120 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxYzOcL08BTTQixEnpuAwAAADo"]
[Thu Sep 17 15:17:00.100008 2026] [security2:error] [pid 971102:tid 971267] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/internal/.env"] [unique_id "aqxYzOcL08BTTQixEnpuBQAAACE"]
[Thu Sep 17 15:17:00.156883 2026] [security2:error] [pid 971102:tid 971239] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/tools/.env"] [unique_id "aqxYzOcL08BTTQixEnpuCQAAAAU"]
[Thu Sep 17 15:17:00.222368 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/scripts/.env"] [unique_id "aqxYzOcL08BTTQixEnpuCgAAAAo"]
[Thu Sep 17 15:17:00.235111 2026] [security2:error] [pid 971102:tid 971316] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuCAAAAFI"]
[Thu Sep 17 15:17:00.280538 2026] [security2:error] [pid 971102:tid 971237] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/bin/.env"] [unique_id "aqxYzOcL08BTTQixEnpuEgAAAAM"]
[Thu Sep 17 15:17:00.283099 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuEwAAAGg"]
[Thu Sep 17 15:17:00.326539 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v1/.env"] [unique_id "aqxYzOcL08BTTQixEnpuFgAAAGY"]
[Thu Sep 17 15:17:00.332868 2026] [security2:error] [pid 971102:tid 971317] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sbin/.env"] [unique_id "aqxYzOcL08BTTQixEnpuFwAAAFM"]
[Thu Sep 17 15:17:00.376774 2026] [security2:error] [pid 971102:tid 971238] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/local/.env"] [unique_id "aqxYzOcL08BTTQixEnpuHAAAAAQ"]
[Thu Sep 17 15:17:00.413021 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/logs/.env"] [unique_id "aqxYzOcL08BTTQixEnpuHgAAAHk"]
[Thu Sep 17 15:17:00.423072 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/portal/.env"] [unique_id "aqxYzOcL08BTTQixEnpuHwAAAEg"]
[Thu Sep 17 15:17:00.458572 2026] [security2:error] [pid 971102:tid 971322] [client 34.24.217.248:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuIgAAAFg"]
[Thu Sep 17 15:17:00.484628 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/dashboard/.env"] [unique_id "aqxYzOcL08BTTQixEnpuJQAAADA"]
[Thu Sep 17 15:17:00.531273 2026] [security2:error] [pid 971102:tid 971361] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/panel/.env"] [unique_id "aqxYzOcL08BTTQixEnpuJgAAAH8"]
[Thu Sep 17 15:17:00.532467 2026] [security2:error] [pid 971102:tid 971265] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cache/.env"] [unique_id "aqxYzOcL08BTTQixEnpuJwAAAB8"]
[Thu Sep 17 15:17:00.557618 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v2/.env"] [unique_id "aqxYzOcL08BTTQixEnpuKAAAAE8"]
[Thu Sep 17 15:17:00.594097 2026] [security2:error] [pid 971102:tid 971262] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/crm/.env"] [unique_id "aqxYzOcL08BTTQixEnpuLQAAABw"]
[Thu Sep 17 15:17:00.620167 2026] [security2:error] [pid 971102:tid 971296] [client 34.24.217.248:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuLwAAAD4"]
[Thu Sep 17 15:17:00.645824 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/erp/.env"] [unique_id "aqxYzOcL08BTTQixEnpuMAAAABk"]
[Thu Sep 17 15:17:00.654748 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailer/.env"] [unique_id "aqxYzOcL08BTTQixEnpuMQAAAHw"]
[Thu Sep 17 15:17:00.722372 2026] [security2:error] [pid 971102:tid 971285] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuMgAAM04"], referer: http://slimmtech.com/blog/
[Thu Sep 17 15:17:00.723757 2026] [security2:error] [pid 971102:tid 971286] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/shop/.env"] [unique_id "aqxYzOcL08BTTQixEnpuMwAAADQ"]
[Thu Sep 17 15:17:00.759545 2026] [security2:error] [pid 971102:tid 971299] [client 5.188.86.234:33344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/blog/wp-login.php"] [unique_id "aqxYzOcL08BTTQixEnpuNwAAAEE"]
[Thu Sep 17 15:17:00.769143 2026] [security2:error] [pid 971102:tid 971350] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/store/.env"] [unique_id "aqxYzOcL08BTTQixEnpuPAAAAHQ"]
[Thu Sep 17 15:17:00.777618 2026] [security2:error] [pid 971102:tid 971357] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mail/.env"] [unique_id "aqxYzOcL08BTTQixEnpuPQAAAHs"]
[Thu Sep 17 15:17:00.786345 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/rest/.env"] [unique_id "aqxYzOcL08BTTQixEnpuPwAAAG4"]
[Thu Sep 17 15:17:00.794446 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:57966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuQAAAAHc"]
[Thu Sep 17 15:17:00.821795 2026] [security2:error] [pid 971102:tid 971252] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/saas/.env"] [unique_id "aqxYzOcL08BTTQixEnpuQQAAABI"]
[Thu Sep 17 15:17:00.848821 2026] [security2:error] [pid 971102:tid 971250] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuQgAAEEQ"], referer: http://slimmtech.com/wordpress/
[Thu Sep 17 15:17:00.878673 2026] [security2:error] [pid 971102:tid 971300] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/client/.env"] [unique_id "aqxYzOcL08BTTQixEnpuRAAAAEI"]
[Thu Sep 17 15:17:00.898442 2026] [security2:error] [pid 971102:tid 971292] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/email/.env"] [unique_id "aqxYzOcL08BTTQixEnpuRQAAADo"]
[Thu Sep 17 15:17:00.931724 2026] [security2:error] [pid 971102:tid 971275] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/project/.env"] [unique_id "aqxYzOcL08BTTQixEnpuSAAAACk"]
[Thu Sep 17 15:17:00.966565 2026] [security2:error] [pid 971102:tid 971325] [client 34.24.217.248:57982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuSQAAAFs"]
[Thu Sep 17 15:17:00.974429 2026] [security2:error] [pid 971102:tid 971348] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuSgAAclA"], referer: http://slimmtech.com/wp/
[Thu Sep 17 15:17:00.992538 2026] [security2:error] [pid 971102:tid 971239] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/admin-panel/.env"] [unique_id "aqxYzOcL08BTTQixEnpuSwAAAAU"]
[Thu Sep 17 15:17:01.014949 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/graphql/.env"] [unique_id "aqxYzecL08BTTQixEnpuTAAAAAY"]
[Thu Sep 17 15:17:01.017388 2026] [security2:error] [pid 971102:tid 971307] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/smtp/.env"] [unique_id "aqxYzecL08BTTQixEnpuTQAAAEk"]
[Thu Sep 17 15:17:01.070090 2026] [security2:error] [pid 971102:tid 971359] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/control-panel/.env"] [unique_id "aqxYzecL08BTTQixEnpuTwAAAH0"]
[Thu Sep 17 15:17:01.114015 2026] [security2:error] [pid 971102:tid 971318] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzecL08BTTQixEnpuUgAAVH4"], referer: http://slimmtech.com/old/
[Thu Sep 17 15:17:01.118648 2026] [security2:error] [pid 971102:tid 971293] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/user-panel/.env"] [unique_id "aqxYzecL08BTTQixEnpuUwAAADs"]
[Thu Sep 17 15:17:01.137649 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailing/.env"] [unique_id "aqxYzecL08BTTQixEnpuVAAAAHU"]
[Thu Sep 17 15:17:01.137655 2026] [security2:error] [pid 971102:tid 971321] [client 34.24.217.248:57988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYzecL08BTTQixEnpuVQAAAFc"]
[Thu Sep 17 15:17:01.181318 2026] [security2:error] [pid 971102:tid 971287] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/node/.env"] [unique_id "aqxYzecL08BTTQixEnpuVgAAADU"]
[Thu Sep 17 15:17:01.212173 2026] [security2:error] [pid 971102:tid 971211] [remote 5.188.86.234:46260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/blog/wp-login.php"] [unique_id "aqxYzecL08BTTQixEnpuWAAAJWo"]
[Thu Sep 17 15:17:01.228118 2026] [security2:error] [pid 971102:tid 971338] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/express/.env"] [unique_id "aqxYzecL08BTTQixEnpuWQAAAGg"]
[Thu Sep 17 15:17:01.248149 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gateway/.env"] [unique_id "aqxYzecL08BTTQixEnpuWgAAABc"]
[Thu Sep 17 15:17:01.250549 2026] [security2:error] [pid 971102:tid 971272] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzecL08BTTQixEnpuXAAAJmQ"], referer: http://slimmtech.com/backup/
[Thu Sep 17 15:17:01.289965 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/next/.env"] [unique_id "aqxYzecL08BTTQixEnpuYwAAADY"]
[Thu Sep 17 15:17:01.313447 2026] [security2:error] [pid 971102:tid 971274] [client 34.24.217.248:58000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYzecL08BTTQixEnpuZAAAACg"]
[Thu Sep 17 15:17:01.344116 2026] [security2:error] [pid 971102:tid 971334] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/nuxt/.env"] [unique_id "aqxYzecL08BTTQixEnpuZgAAAGQ"]
[Thu Sep 17 15:17:01.392124 2026] [security2:error] [pid 971102:tid 971355] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/nest/.env"] [unique_id "aqxYzecL08BTTQixEnpuawAAAHk"]
[Thu Sep 17 15:17:01.437867 2026] [security2:error] [pid 971102:tid 971323] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/react/.env"] [unique_id "aqxYzecL08BTTQixEnpubQAAAFk"]
[Thu Sep 17 15:17:01.467592 2026] [security2:error] [pid 971102:tid 971317] [client 172.239.147.162:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxYzecL08BTTQixEnpubwAAAFM"], referer: binance.com
[Thu Sep 17 15:17:01.477767 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/microservice/.env"] [unique_id "aqxYzecL08BTTQixEnpucAAAAEM"]
[Thu Sep 17 15:17:01.477900 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYzecL08BTTQixEnpucQAAAGA"]
[Thu Sep 17 15:17:01.493905 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/vue/.env"] [unique_id "aqxYzecL08BTTQixEnpucgAAACQ"]
[Thu Sep 17 15:17:01.503485 2026] [security2:error] [pid 971102:tid 971281] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/notifications/.env"] [unique_id "aqxYzecL08BTTQixEnpucwAAAC8"]
[Thu Sep 17 15:17:01.526406 2026] [security2:error] [pid 971102:tid 971303] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzecL08BTTQixEnpudAAARRw"], referer: http://slimmtech.com/new/
[Thu Sep 17 15:17:01.550372 2026] [security2:error] [pid 971102:tid 971342] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/angular/.env"] [unique_id "aqxYzecL08BTTQixEnpudQAAAGw"]
[Thu Sep 17 15:17:01.599709 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/svelte/.env"] [unique_id "aqxYzecL08BTTQixEnpudwAAAFo"]
[Thu Sep 17 15:17:01.622159 2026] [security2:error] [pid 971102:tid 971262] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/notify/.env"] [unique_id "aqxYzecL08BTTQixEnpuewAAABw"]
[Thu Sep 17 15:17:01.624645 2026] [security2:error] [pid 971102:tid 971237] [client 104.28.198.244:22589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzecL08BTTQixEnpufAAAAAM"]
[Thu Sep 17 15:17:01.624748 2026] [security2:error] [pid 971102:tid 971237] [client 104.28.198.244:22589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzecL08BTTQixEnpufAAAAAM"]
[Thu Sep 17 15:17:01.639162 2026] [security2:error] [pid 971102:tid 971326] [client 127.0.0.1:23396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYzecL08BTTQixEnpuegAAAFw"]
[Thu Sep 17 15:17:01.639166 2026] [security2:error] [pid 971102:tid 971313] [client 127.0.0.1:23380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.buliblog.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYzecL08BTTQixEnpueQAAAE8"]
[Thu Sep 17 15:17:01.639264 2026] [security2:error] [pid 971102:tid 971243] [client 74.7.228.58:34334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.buliblog.com"] [uri "/robots.txt"] [unique_id "aqxYzecL08BTTQixEnpueAAACTE"]
[Thu Sep 17 15:17:01.648322 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/vite/.env"] [unique_id "aqxYzecL08BTTQixEnpufQAAAHw"]
[Thu Sep 17 15:17:01.691778 2026] [security2:error] [pid 971102:tid 971247] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/backup/.env"] [unique_id "aqxYzecL08BTTQixEnpufwAAAA0"]
[Thu Sep 17 15:17:01.706015 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/service/.env"] [unique_id "aqxYzecL08BTTQixEnpugwAAADw"]
[Thu Sep 17 15:17:01.734390 2026] [security2:error] [pid 971102:tid 971263] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/backups/.env"] [unique_id "aqxYzecL08BTTQixEnpuhAAAAB0"]
[Thu Sep 17 15:17:01.741898 2026] [security2:error] [pid 971102:tid 971234] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sender/.env"] [unique_id "aqxYzecL08BTTQixEnpuhQAAAAA"]
[Thu Sep 17 15:17:01.784677 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/old/.env"] [unique_id "aqxYzecL08BTTQixEnpuigAAAFY"]
[Thu Sep 17 15:17:01.834838 2026] [security2:error] [pid 971102:tid 971315] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/tmp/.env"] [unique_id "aqxYzecL08BTTQixEnpulQAAAFE"]
[Thu Sep 17 15:17:01.865586 2026] [security2:error] [pid 971102:tid 971343] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/campaign/.env"] [unique_id "aqxYzecL08BTTQixEnpulgAAAG0"]
[Thu Sep 17 15:17:01.877549 2026] [security2:error] [pid 971102:tid 971277] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/temp/.env"] [unique_id "aqxYzecL08BTTQixEnpulwAAACs"]
[Thu Sep 17 15:17:01.924984 2026] [security2:error] [pid 971102:tid 971289] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/lab/.env"] [unique_id "aqxYzecL08BTTQixEnpumwAAADc"]
[Thu Sep 17 15:17:01.934263 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v3/.env"] [unique_id "aqxYzecL08BTTQixEnpunQAAAE4"]
[Thu Sep 17 15:17:01.980953 2026] [security2:error] [pid 971102:tid 971353] [client 172.239.147.162:59599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxYzecL08BTTQixEnpuoAAAAHc"], referer: binance.com
[Thu Sep 17 15:17:01.981273 2026] [security2:error] [pid 971102:tid 971348] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cronlab/.env"] [unique_id "aqxYzecL08BTTQixEnpunwAAAHI"]
[Thu Sep 17 15:17:01.996448 2026] [security2:error] [pid 971102:tid 971240] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/newsletter/.env"] [unique_id "aqxYzecL08BTTQixEnpuoQAAAAY"]
[Thu Sep 17 15:17:02.036841 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cron/.env"] [unique_id "aqxYzucL08BTTQixEnpuowAAAAo"]
[Thu Sep 17 15:17:02.086051 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/en/.env"] [unique_id "aqxYzucL08BTTQixEnpupgAAAFQ"]
[Thu Sep 17 15:17:02.115756 2026] [security2:error] [pid 971102:tid 971287] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/ses/.env"] [unique_id "aqxYzucL08BTTQixEnpuqwAAADU"]
[Thu Sep 17 15:17:02.164048 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/dev/.env"] [unique_id "aqxYzucL08BTTQixEnpurwAAACY"]
[Thu Sep 17 15:17:02.181876 2026] [security2:error] [pid 971102:tid 971339] [client 185.55.149.49:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpusgAAAGk"]
[Thu Sep 17 15:17:02.181961 2026] [security2:error] [pid 971102:tid 971339] [client 185.55.149.49:59480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpusgAAAGk"]
[Thu Sep 17 15:17:02.192391 2026] [security2:error] [pid 971102:tid 971236] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/administrator/.env"] [unique_id "aqxYzucL08BTTQixEnpurQAAAAI"]
[Thu Sep 17 15:17:02.234491 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sendgrid/.env"] [unique_id "aqxYzucL08BTTQixEnputAAAAAs"]
[Thu Sep 17 15:17:02.247258 2026] [security2:error] [pid 971102:tid 971354] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/psnlink/.env"] [unique_id "aqxYzucL08BTTQixEnputwAAAHg"]
[Thu Sep 17 15:17:02.304296 2026] [security2:error] [pid 971102:tid 971301] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/exapi/.env"] [unique_id "aqxYzucL08BTTQixEnpuuwAAAEM"]
[Thu Sep 17 15:17:02.360073 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sparkpost/.env"] [unique_id "aqxYzucL08BTTQixEnpuwgAAABM"]
[Thu Sep 17 15:17:02.360124 2026] [security2:error] [pid 971102:tid 971235] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sitemaps/.env"] [unique_id "aqxYzucL08BTTQixEnpuwQAAAAE"]
[Thu Sep 17 15:17:02.408067 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/staging/.env"] [unique_id "aqxYzucL08BTTQixEnpuyAAAAFU"]
[Thu Sep 17 15:17:02.474800 2026] [security2:error] [pid 971102:tid 971305] [client 127.0.0.1:60170] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYzucL08BTTQixEnpuzAAAAEc"]
[Thu Sep 17 15:17:02.474819 2026] [security2:error] [pid 971102:tid 971290] [client 74.7.244.45:56524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tlschulmanlaw.com"] [uri "/robots.txt"] [unique_id "aqxYzucL08BTTQixEnpuywAAADg"]
[Thu Sep 17 15:17:02.479460 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/postmark/.env"] [unique_id "aqxYzucL08BTTQixEnpuzwAAAAM"]
[Thu Sep 17 15:17:02.553372 2026] [security2:error] [pid 971102:tid 971346] [client 103.131.71.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tab-funkenwerk.org"] [uri "/index.php"] [unique_id "aqxYzucL08BTTQixEnpuxwAAAHA"]
[Thu Sep 17 15:17:02.558182 2026] [security2:error] [pid 971102:tid 971261] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/logs/.env"] [unique_id "aqxYzucL08BTTQixEnpu0QAAABs"]
[Thu Sep 17 15:17:02.600290 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailgun/.env"] [unique_id "aqxYzucL08BTTQixEnpu0gAAABg"]
[Thu Sep 17 15:17:02.607542 2026] [security2:error] [pid 971102:tid 971238] [client 172.239.147.162:49187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxYzucL08BTTQixEnpu1AAAAAQ"], referer: binance.com
[Thu Sep 17 15:17:02.622128 2026] [autoindex:error] [pid 971102:tid 971273] [client 34.24.217.248:58034] AH01276: Cannot serve directory /home1/haatpamy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:17:02.645282 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vendor/.env"] [unique_id "aqxYzucL08BTTQixEnpu1wAAAD4"]
[Thu Sep 17 15:17:02.709406 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpu2QAAAB0"]
[Thu Sep 17 15:17:02.709516 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpu2QAAAB0"]
[Thu Sep 17 15:17:02.720354 2026] [security2:error] [pid 971102:tid 971252] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mandrill/.env"] [unique_id "aqxYzucL08BTTQixEnpu2gAAABI"]
[Thu Sep 17 15:17:02.763761 2026] [security2:error] [pid 971102:tid 971315] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cache/.env"] [unique_id "aqxYzucL08BTTQixEnpu3gAAAFE"]
[Thu Sep 17 15:17:02.812802 2026] [security2:error] [pid 971102:tid 971347] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailer/.env"] [unique_id "aqxYzucL08BTTQixEnpu4QAAAHE"]
[Thu Sep 17 15:17:02.848044 2026] [security2:error] [pid 971102:tid 971304] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailjet/.env"] [unique_id "aqxYzucL08BTTQixEnpu4gAAAEY"]
[Thu Sep 17 15:17:02.862240 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxYzucL08BTTQixEnpu4wAAAB4"]
[Thu Sep 17 15:17:02.870126 2026] [security2:error] [pid 971102:tid 971353] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mail/.env"] [unique_id "aqxYzucL08BTTQixEnpu5AAAAHc"]
[Thu Sep 17 15:17:02.881367 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/lib/.env"] [unique_id "aqxYzucL08BTTQixEnpu5gAAAAU"]
[Thu Sep 17 15:17:02.927238 2026] [security2:error] [pid 971102:tid 971360] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/email/.env"] [unique_id "aqxYzucL08BTTQixEnpu6QAAAH4"]
[Thu Sep 17 15:17:02.969172 2026] [security2:error] [pid 971102:tid 971256] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/brevo/.env"] [unique_id "aqxYzucL08BTTQixEnpu6wAAABY"]
[Thu Sep 17 15:17:02.988032 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/smtp/.env"] [unique_id "aqxYzucL08BTTQixEnpu7AAAAFQ"]
[Thu Sep 17 15:17:03.017101 2026] [security2:error] [pid 971102:tid 971350] [client 172.239.147.162:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxYz-cL08BTTQixEnpu7wAAAHQ"], referer: binance.com
[Thu Sep 17 15:17:03.031177 2026] [security2:error] [pid 971102:tid 971236] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxYz-cL08BTTQixEnpu8QAAAAI"]
[Thu Sep 17 15:17:03.043753 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailing/.env"] [unique_id "aqxYz-cL08BTTQixEnpu8wAAAAs"]
[Thu Sep 17 15:17:03.090409 2026] [security2:error] [pid 971102:tid 971354] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/transactional/.env"] [unique_id "aqxYz-cL08BTTQixEnpu9AAAAHg"]
[Thu Sep 17 15:17:03.097252 2026] [security2:error] [pid 971102:tid 971334] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/notifications/.env"] [unique_id "aqxYz-cL08BTTQixEnpu9QAAAGQ"]
[Thu Sep 17 15:17:03.116617 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/resources/.env"] [unique_id "aqxYz-cL08BTTQixEnpu9wAAAHk"]
[Thu Sep 17 15:17:03.146736 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/notify/.env"] [unique_id "aqxYz-cL08BTTQixEnpu-AAAADY"]
[Thu Sep 17 15:17:03.189906 2026] [security2:error] [pid 971102:tid 971322] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxYz-cL08BTTQixEnpu-gAAAFg"]
[Thu Sep 17 15:17:03.195276 2026] [security2:error] [pid 971102:tid 971278] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sender/.env"] [unique_id "aqxYz-cL08BTTQixEnpu-wAAACw"]
[Thu Sep 17 15:17:03.195651 2026] [security2:error] [pid 971102:tid 971336] [client 43.172.196.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYz-cL08BTTQixEnpu8gAAAGY"]
[Thu Sep 17 15:17:03.210808 2026] [security2:error] [pid 971102:tid 971316] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/bulk/.env"] [unique_id "aqxYz-cL08BTTQixEnpu_AAAAFI"]
[Thu Sep 17 15:17:03.242643 2026] [security2:error] [pid 971102:tid 971253] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/campaign/.env"] [unique_id "aqxYz-cL08BTTQixEnpvAAAAABM"]
[Thu Sep 17 15:17:03.288579 2026] [security2:error] [pid 971102:tid 971260] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/newsletter/.env"] [unique_id "aqxYz-cL08BTTQixEnpvAwAAABo"]
[Thu Sep 17 15:17:03.331020 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/aws/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBAAAAF4"]
[Thu Sep 17 15:17:03.332921 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/ses/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBQAAACQ"]
[Thu Sep 17 15:17:03.345092 2026] [security2:error] [pid 971102:tid 971255] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBgAAABU"]
[Thu Sep 17 15:17:03.345406 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/assets/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBwAAAF0"]
[Thu Sep 17 15:17:03.376255 2026] [security2:error] [pid 971102:tid 971345] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sendgrid/.env"] [unique_id "aqxYz-cL08BTTQixEnpvCAAAAG8"]
[Thu Sep 17 15:17:03.420647 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sparkpost/.env"] [unique_id "aqxYz-cL08BTTQixEnpvCQAAAFo"]
[Thu Sep 17 15:17:03.450102 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/azure/.env"] [unique_id "aqxYz-cL08BTTQixEnpvCgAAAFw"]
[Thu Sep 17 15:17:03.473098 2026] [security2:error] [pid 971102:tid 971246] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/postmark/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDAAAAAw"]
[Thu Sep 17 15:17:03.499832 2026] [security2:error] [pid 971102:tid 971340] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDQAAAGo"]
[Thu Sep 17 15:17:03.523141 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailgun/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDgAAABk"]
[Thu Sep 17 15:17:03.571335 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/gcp/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDwAAAHw"]
[Thu Sep 17 15:17:03.575934 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/uploads/.env"] [unique_id "aqxYz-cL08BTTQixEnpvEAAAAF8"]
[Thu Sep 17 15:17:03.576384 2026] [security2:error] [pid 971102:tid 971262] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mandrill/.env"] [unique_id "aqxYz-cL08BTTQixEnpvEQAAABw"]
[Thu Sep 17 15:17:03.626303 2026] [security2:error] [pid 971102:tid 971286] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailjet/.env"] [unique_id "aqxYz-cL08BTTQixEnpvFQAAADQ"]
[Thu Sep 17 15:17:03.660792 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxYz-cL08BTTQixEnpvFwAAADM"]
[Thu Sep 17 15:17:03.680964 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/brevo/.env"] [unique_id "aqxYz-cL08BTTQixEnpvGAAAACU"]
[Thu Sep 17 15:17:03.695453 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cloud/.env"] [unique_id "aqxYz-cL08BTTQixEnpvGQAAAAQ"]
[Thu Sep 17 15:17:03.737995 2026] [security2:error] [pid 971102:tid 971351] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/transactional/.env"] [unique_id "aqxYz-cL08BTTQixEnpvGgAAAHU"]
[Thu Sep 17 15:17:03.784788 2026] [security2:error] [pid 971102:tid 971234] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/bulk/.env"] [unique_id "aqxYz-cL08BTTQixEnpvHQAAAAA"]
[Thu Sep 17 15:17:03.806307 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/internal/.env"] [unique_id "aqxYz-cL08BTTQixEnpvIAAAAD4"]
[Thu Sep 17 15:17:03.827765 2026] [security2:error] [pid 971102:tid 971250] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/aws/.env"] [unique_id "aqxYz-cL08BTTQixEnpvJAAAABA"]
[Thu Sep 17 15:17:03.844353 2026] [security2:error] [pid 971102:tid 971357] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/infrastructure/.env"] [unique_id "aqxYz-cL08BTTQixEnpvJQAAAHs"]
[Thu Sep 17 15:17:03.895506 2026] [security2:error] [pid 971102:tid 971343] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/azure/.env"] [unique_id "aqxYz-cL08BTTQixEnpvJgAAAG0"]
[Thu Sep 17 15:17:03.947421 2026] [security2:error] [pid 971102:tid 971292] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/gcp/.env"] [unique_id "aqxYz-cL08BTTQixEnpvKAAAADo"]
[Thu Sep 17 15:17:03.976486 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/docker/.env"] [unique_id "aqxYz-cL08BTTQixEnpvLAAAABE"]
[Thu Sep 17 15:17:04.001149 2026] [security2:error] [pid 971102:tid 971341] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cloud/.env"] [unique_id "aqxY0OcL08BTTQixEnpvLQAAAGs"]
[Thu Sep 17 15:17:04.041121 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/tools/.env"] [unique_id "aqxY0OcL08BTTQixEnpvLgAAAHc"]
[Thu Sep 17 15:17:04.053770 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/infrastructure/.env"] [unique_id "aqxY0OcL08BTTQixEnpvLwAAAGc"]
[Thu Sep 17 15:17:04.097907 2026] [security2:error] [pid 971102:tid 971244] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/k8s/.env"] [unique_id "aqxY0OcL08BTTQixEnpvMAAAAAo"]
[Thu Sep 17 15:17:04.107200 2026] [security2:error] [pid 971102:tid 971360] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/docker/.env"] [unique_id "aqxY0OcL08BTTQixEnpvMQAAAH4"]
[Thu Sep 17 15:17:04.159578 2026] [security2:error] [pid 971102:tid 971333] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/k8s/.env"] [unique_id "aqxY0OcL08BTTQixEnpvNAAAAGM"]
[Thu Sep 17 15:17:04.207348 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/kubernetes/.env"] [unique_id "aqxY0OcL08BTTQixEnpvNQAAAFQ"]
[Thu Sep 17 15:17:04.226952 2026] [security2:error] [pid 971102:tid 971287] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/kubernetes/.env"] [unique_id "aqxY0OcL08BTTQixEnpvNgAAADU"]
[Thu Sep 17 15:17:04.257461 2026] [security2:error] [pid 971102:tid 971295] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/terraform/.env"] [unique_id "aqxY0OcL08BTTQixEnpvOwAAAD0"]
[Thu Sep 17 15:17:04.278276 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/scripts/.env"] [unique_id "aqxY0OcL08BTTQixEnpvQQAAAAI"]
[Thu Sep 17 15:17:04.286998 2026] [security2:error] [pid 971102:tid 971252] [client 154.190.208.131:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvQAAAABI"]
[Thu Sep 17 15:17:04.287104 2026] [security2:error] [pid 971102:tid 971252] [client 154.190.208.131:41793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvQAAAABI"]
[Thu Sep 17 15:17:04.307909 2026] [security2:error] [pid 971102:tid 971354] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/ansible/.env"] [unique_id "aqxY0OcL08BTTQixEnpvQwAAAHg"]
[Thu Sep 17 15:17:04.327878 2026] [security2:error] [pid 971102:tid 971254] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRAAAABQ"]
[Thu Sep 17 15:17:04.352403 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/terraform/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRQAAAEQ"]
[Thu Sep 17 15:17:04.359027 2026] [security2:error] [pid 971102:tid 971332] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.git/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRgAAAGI"]
[Thu Sep 17 15:17:04.410518 2026] [security2:error] [pid 971102:tid 971310] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/ci/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRwAAAEw"]
[Thu Sep 17 15:17:04.477491 2026] [security2:error] [pid 971102:tid 971278] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cd/.env"] [unique_id "aqxY0OcL08BTTQixEnpvSQAAACw"]
[Thu Sep 17 15:17:04.477491 2026] [security2:error] [pid 971102:tid 971322] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/ansible/.env"] [unique_id "aqxY0OcL08BTTQixEnpvSgAAAFg"]
[Thu Sep 17 15:17:04.484215 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxY0OcL08BTTQixEnpvSwAAAGY"]
[Thu Sep 17 15:17:04.512426 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bin/.env"] [unique_id "aqxY0OcL08BTTQixEnpvTAAAACY"]
[Thu Sep 17 15:17:04.528473 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/jenkins/.env"] [unique_id "aqxY0OcL08BTTQixEnpvTgAAADA"]
[Thu Sep 17 15:17:04.535872 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvTQAAAGQ"]
[Thu Sep 17 15:17:04.535944 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:63587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvTQAAAGQ"]
[Thu Sep 17 15:17:04.586087 2026] [security2:error] [pid 971102:tid 971301] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/gitlab/.env"] [unique_id "aqxY0OcL08BTTQixEnpvUAAAAEM"]
[Thu Sep 17 15:17:04.604288 2026] [security2:error] [pid 971102:tid 971235] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.git/.env"] [unique_id "aqxY0OcL08BTTQixEnpvUgAAAAE"]
[Thu Sep 17 15:17:04.634543 2026] [security2:error] [pid 971102:tid 971260] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/github/.env"] [unique_id "aqxY0OcL08BTTQixEnpvVgAAABo"]
[Thu Sep 17 15:17:04.641530 2026] [security2:error] [pid 971102:tid 971303] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxY0OcL08BTTQixEnpvWAAAAEU"]
[Thu Sep 17 15:17:04.688504 2026] [security2:error] [pid 971102:tid 971319] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/actions/.env"] [unique_id "aqxY0OcL08BTTQixEnpvWgAAAFU"]
[Thu Sep 17 15:17:04.726586 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/ci/.env"] [unique_id "aqxY0OcL08BTTQixEnpvXQAAAGw"]
[Thu Sep 17 15:17:04.732878 2026] [security2:error] [pid 971102:tid 971280] [client 172.239.147.162:57580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxY0OcL08BTTQixEnpvXgAAAC4"], referer: binance.com
[Thu Sep 17 15:17:04.736077 2026] [security2:error] [pid 971102:tid 971345] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/circleci/.env"] [unique_id "aqxY0OcL08BTTQixEnpvXwAAAG8"]
[Thu Sep 17 15:17:04.742275 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sbin/.env"] [unique_id "aqxY0OcL08BTTQixEnpvYAAAABc"]
[Thu Sep 17 15:17:04.787570 2026] [security2:error] [pid 971102:tid 971305] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/travis/.env"] [unique_id "aqxY0OcL08BTTQixEnpvYwAAAEc"]
[Thu Sep 17 15:17:04.794438 2026] [security2:error] [pid 971102:tid 971324] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxY0OcL08BTTQixEnpvZAAAAFo"]
[Thu Sep 17 15:17:04.847431 2026] [security2:error] [pid 971102:tid 971330] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/buildkite/.env"] [unique_id "aqxY0OcL08BTTQixEnpvZgAAAGA"]
[Thu Sep 17 15:17:04.855460 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cd/.env"] [unique_id "aqxY0OcL08BTTQixEnpvZwAAAAM"]
[Thu Sep 17 15:17:04.903724 2026] [security2:error] [pid 971102:tid 971346] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mysql/.env"] [unique_id "aqxY0OcL08BTTQixEnpvaAAAAHA"]
[Thu Sep 17 15:17:04.950348 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxY0OcL08BTTQixEnpvagAAACU"]
[Thu Sep 17 15:17:04.976506 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/local/.env"] [unique_id "aqxY0OcL08BTTQixEnpvawAAABs"]
[Thu Sep 17 15:17:04.976684 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/postgres/.env"] [unique_id "aqxY0OcL08BTTQixEnpvbAAAAEE"]
[Thu Sep 17 15:17:04.988789 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/jenkins/.env"] [unique_id "aqxY0OcL08BTTQixEnpvbgAAAAQ"]
[Thu Sep 17 15:17:05.021552 2026] [security2:error] [pid 971102:tid 971269] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mongodb/.env"] [unique_id "aqxY0ecL08BTTQixEnpvcgAAACM"]
[Thu Sep 17 15:17:05.074555 2026] [security2:error] [pid 971102:tid 971296] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/redis/.env"] [unique_id "aqxY0ecL08BTTQixEnpvcwAAAD4"]
[Thu Sep 17 15:17:05.105269 2026] [security2:error] [pid 971102:tid 971250] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxY0ecL08BTTQixEnpvdAAAABA"]
[Thu Sep 17 15:17:05.107441 2026] [fcgid:warn] [pid 971102:tid 971263] (70014)End of file found: [client 118.193.32.119:33584] mod_fcgid: can't get data from http client
[Thu Sep 17 15:17:05.122738 2026] [security2:error] [pid 971102:tid 971331] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/elasticsearch/.env"] [unique_id "aqxY0ecL08BTTQixEnpvdgAAAGE"]
[Thu Sep 17 15:17:05.132362 2026] [security2:error] [pid 971102:tid 971343] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/gitlab/.env"] [unique_id "aqxY0ecL08BTTQixEnpvdwAAAG0"]
[Thu Sep 17 15:17:05.183065 2026] [security2:error] [pid 971102:tid 971251] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/rabbitmq/.env"] [unique_id "aqxY0ecL08BTTQixEnpvegAAABE"]
[Thu Sep 17 15:17:05.208915 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/portal/.env"] [unique_id "aqxY0ecL08BTTQixEnpvewAAACc"]
[Thu Sep 17 15:17:05.226355 2026] [security2:error] [pid 971102:tid 971242] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/kafka/.env"] [unique_id "aqxY0ecL08BTTQixEnpvfAAAAAg"]
[Thu Sep 17 15:17:05.257321 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxY0ecL08BTTQixEnpvfgAAAB4"]
[Thu Sep 17 15:17:05.263863 2026] [security2:error] [pid 971102:tid 971304] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/github/.env"] [unique_id "aqxY0ecL08BTTQixEnpvfwAAAEY"]
[Thu Sep 17 15:17:05.278845 2026] [security2:error] [pid 971102:tid 971353] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/queue/.env"] [unique_id "aqxY0ecL08BTTQixEnpvgAAAAHc"]
[Thu Sep 17 15:17:05.338042 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/worker/.env"] [unique_id "aqxY0ecL08BTTQixEnpvggAAAGc"]
[Thu Sep 17 15:17:05.386097 2026] [security2:error] [pid 971102:tid 971300] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/actions/.env"] [unique_id "aqxY0ecL08BTTQixEnpvgwAAAEI"]
[Thu Sep 17 15:17:05.394138 2026] [security2:error] [pid 971102:tid 971333] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/job/.env"] [unique_id "aqxY0ecL08BTTQixEnpvhAAAAGM"]
[Thu Sep 17 15:17:05.409396 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxY0ecL08BTTQixEnpvhgAAADU"]
[Thu Sep 17 15:17:05.445913 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/test/.env"] [unique_id "aqxY0ecL08BTTQixEnpviAAAAAs"]
[Thu Sep 17 15:17:05.445913 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dashboard/.env"] [unique_id "aqxY0ecL08BTTQixEnpvhwAAABI"]
[Thu Sep 17 15:17:05.498004 2026] [security2:error] [pid 971102:tid 971339] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/qa/.env"] [unique_id "aqxY0ecL08BTTQixEnpvjAAAAGk"]
[Thu Sep 17 15:17:05.529063 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/circleci/.env"] [unique_id "aqxY0ecL08BTTQixEnpvjQAAAC0"]
[Thu Sep 17 15:17:05.548888 2026] [security2:error] [pid 971102:tid 971240] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/preview/.env"] [unique_id "aqxY0ecL08BTTQixEnpvjgAAAAY"]
[Thu Sep 17 15:17:05.555126 2026] [security2:error] [pid 971102:tid 971244] [client 172.239.147.162:55584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxY0ecL08BTTQixEnpvjwAAAAo"], referer: binance.com
[Thu Sep 17 15:17:05.566314 2026] [security2:error] [pid 971102:tid 971352] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxY0ecL08BTTQixEnpvkAAAAHY"]
[Thu Sep 17 15:17:05.599230 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/beta/.env"] [unique_id "aqxY0ecL08BTTQixEnpvkgAAAEg"]
[Thu Sep 17 15:17:05.646251 2026] [security2:error] [pid 971102:tid 971309] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/uat/.env"] [unique_id "aqxY0ecL08BTTQixEnpvkwAAAEs"]
[Thu Sep 17 15:17:05.668310 2026] [security2:error] [pid 971102:tid 971322] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/travis/.env"] [unique_id "aqxY0ecL08BTTQixEnpvlQAAAFg"]
[Thu Sep 17 15:17:05.681209 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/panel/.env"] [unique_id "aqxY0ecL08BTTQixEnpvlgAAACw"]
[Thu Sep 17 15:17:05.686074 2026] [security2:error] [pid 971102:tid 971348] [client 186.105.232.15:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0ecL08BTTQixEnpvlwAAAHI"]
[Thu Sep 17 15:17:05.686176 2026] [security2:error] [pid 971102:tid 971348] [client 186.105.232.15:53296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0ecL08BTTQixEnpvlwAAAHI"]
[Thu Sep 17 15:17:05.694654 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/stage/.env"] [unique_id "aqxY0ecL08BTTQixEnpvmAAAAGY"]
[Thu Sep 17 15:17:05.719212 2026] [security2:error] [pid 971102:tid 971272] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxY0ecL08BTTQixEnpvmQAAACY"]
[Thu Sep 17 15:17:05.740219 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/development/.env"] [unique_id "aqxY0ecL08BTTQixEnpvmgAAADA"]
[Thu Sep 17 15:17:05.794043 2026] [security2:error] [pid 971102:tid 971253] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/production/.env"] [unique_id "aqxY0ecL08BTTQixEnpvpgAAABM"]
[Thu Sep 17 15:17:05.801799 2026] [security2:error] [pid 971102:tid 971235] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/buildkite/.env"] [unique_id "aqxY0ecL08BTTQixEnpvpwAAAAE"]
[Thu Sep 17 15:17:05.837524 2026] [security2:error] [pid 971102:tid 971303] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/config/app/.env"] [unique_id "aqxY0ecL08BTTQixEnpvuAAAAEU"]
[Thu Sep 17 15:17:05.872916 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxY0ecL08BTTQixEnpvuQAAACQ"]
[Thu Sep 17 15:17:05.895054 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php"] [unique_id "aqxY0ecL08BTTQixEnpvugAAADY"]
[Thu Sep 17 15:17:05.911477 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/crm/.env"] [unique_id "aqxY0ecL08BTTQixEnpvuwAAAFU"]
[Thu Sep 17 15:17:05.922726 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mysql/.env"] [unique_id "aqxY0ecL08BTTQixEnpvvgAAAGw"]
[Thu Sep 17 15:17:06.026902 2026] [security2:error] [pid 971102:tid 971276] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxY0ucL08BTTQixEnpvzAAAACo"]
[Thu Sep 17 15:17:06.042837 2026] [security2:error] [pid 971102:tid 971330] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/postgres/.env"] [unique_id "aqxY0ucL08BTTQixEnpvzQAAAGA"]
[Thu Sep 17 15:17:06.063634 2026] [security2:error] [pid 971102:tid 971256] [client 8.29.0.172:58301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY0ecL08BTTQixEnpvvwAAFik"]
[Thu Sep 17 15:17:06.071864 2026] [security2:error] [pid 971102:tid 971290] [client 35.202.49.146:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/info.php"] [unique_id "aqxY0ucL08BTTQixEnpvzwAAADg"]
[Thu Sep 17 15:17:06.140333 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/erp/.env"] [unique_id "aqxY0ucL08BTTQixEnpv2QAAAHw"]
[Thu Sep 17 15:17:06.161484 2026] [security2:error] [pid 971102:tid 971294] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mongodb/.env"] [unique_id "aqxY0ucL08BTTQixEnpv4wAAADw"]
[Thu Sep 17 15:17:06.178449 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxY0ucL08BTTQixEnpv5QAAADM"]
[Thu Sep 17 15:17:06.211706 2026] [security2:error] [pid 971102:tid 971241] [client 35.202.49.146:35246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/php.php"] [unique_id "aqxY0ucL08BTTQixEnpv6AAAAAc"]
[Thu Sep 17 15:17:06.292299 2026] [security2:error] [pid 971102:tid 971263] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/redis/.env"] [unique_id "aqxY0ucL08BTTQixEnpv7gAAAB0"]
[Thu Sep 17 15:17:06.332022 2026] [security2:error] [pid 971102:tid 971343] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxY0ucL08BTTQixEnpv8AAAAG0"]
[Thu Sep 17 15:17:06.369872 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shop/.env"] [unique_id "aqxY0ucL08BTTQixEnpv8gAAAHU"]
[Thu Sep 17 15:17:06.397848 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/i.php"] [unique_id "aqxY0ucL08BTTQixEnpv9AAAADE"]
[Thu Sep 17 15:17:06.421686 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/elasticsearch/.env"] [unique_id "aqxY0ucL08BTTQixEnpv-AAAAHc"]
[Thu Sep 17 15:17:06.485011 2026] [security2:error] [pid 971102:tid 971307] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxY0ucL08BTTQixEnpwCAAAAEk"]
[Thu Sep 17 15:17:06.531046 2026] [security2:error] [pid 971102:tid 971333] [client 35.202.49.146:35256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/pi.php"] [unique_id "aqxY0ucL08BTTQixEnpwCwAAAGM"]
[Thu Sep 17 15:17:06.549476 2026] [security2:error] [pid 971102:tid 971310] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/rabbitmq/.env"] [unique_id "aqxY0ucL08BTTQixEnpwDAAAAEw"]
[Thu Sep 17 15:17:06.605489 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/store/.env"] [unique_id "aqxY0ucL08BTTQixEnpwDQAAAHY"]
[Thu Sep 17 15:17:06.638024 2026] [security2:error] [pid 971102:tid 971318] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxY0ucL08BTTQixEnpwDgAAAFQ"]
[Thu Sep 17 15:17:06.669817 2026] [security2:error] [pid 971102:tid 971309] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/kafka/.env"] [unique_id "aqxY0ucL08BTTQixEnpwEQAAAEs"]
[Thu Sep 17 15:17:06.674219 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:35262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/pinfo.php"] [unique_id "aqxY0ucL08BTTQixEnpwEgAAAEg"]
[Thu Sep 17 15:17:06.777995 2026] [security2:error] [pid 971102:tid 971339] [client 172.239.147.162:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxY0ucL08BTTQixEnpwEwAAAGk"], referer: binance.com
[Thu Sep 17 15:17:06.790790 2026] [security2:error] [pid 971102:tid 971334] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxY0ucL08BTTQixEnpwFAAAAGQ"]
[Thu Sep 17 15:17:06.791340 2026] [security2:error] [pid 971102:tid 971335] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/queue/.env"] [unique_id "aqxY0ucL08BTTQixEnpwFQAAAGU"]
[Thu Sep 17 15:17:06.821009 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/test.php"] [unique_id "aqxY0ucL08BTTQixEnpwFgAAADA"]
[Thu Sep 17 15:17:06.840698 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/saas/.env"] [unique_id "aqxY0ucL08BTTQixEnpwGAAAAGg"]
[Thu Sep 17 15:17:06.939715 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/worker/.env"] [unique_id "aqxY0ucL08BTTQixEnpwGQAAAEM"]
[Thu Sep 17 15:17:06.952280 2026] [security2:error] [pid 971102:tid 971268] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxY0ucL08BTTQixEnpwGwAAACI"]
[Thu Sep 17 15:17:06.995407 2026] [security2:error] [pid 971102:tid 971260] [client 35.202.49.146:35288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY0ucL08BTTQixEnpwHgAAABo"]
[Thu Sep 17 15:17:07.058295 2026] [security2:error] [pid 971102:tid 971327] [client 35.202.49.146:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/p.php"] [unique_id "aqxY0-cL08BTTQixEnpwIwAAAF0"]
[Thu Sep 17 15:17:07.062567 2026] [security2:error] [pid 971102:tid 971345] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/job/.env"] [unique_id "aqxY0-cL08BTTQixEnpwJAAAAG8"]
[Thu Sep 17 15:17:07.073572 2026] [security2:error] [pid 971102:tid 971289] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxY0-cL08BTTQixEnpwJQAAADc"]
[Thu Sep 17 15:17:07.105512 2026] [security2:error] [pid 971102:tid 971324] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxY0-cL08BTTQixEnpwJwAAAFo"]
[Thu Sep 17 15:17:07.189120 2026] [security2:error] [pid 971102:tid 971259] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/test/.env"] [unique_id "aqxY0-cL08BTTQixEnpwKwAAABk"]
[Thu Sep 17 15:17:07.208124 2026] [security2:error] [pid 971102:tid 971290] [client 35.202.49.146:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/debug.php"] [unique_id "aqxY0-cL08BTTQixEnpwLAAAADg"]
[Thu Sep 17 15:17:07.262477 2026] [security2:error] [pid 971102:tid 971350] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxY0-cL08BTTQixEnpwLgAAAHQ"]
[Thu Sep 17 15:17:07.314613 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/qa/.env"] [unique_id "aqxY0-cL08BTTQixEnpwLwAAAFw"]
[Thu Sep 17 15:17:07.318813 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/project/.env"] [unique_id "aqxY0-cL08BTTQixEnpwMAAAABs"]
[Thu Sep 17 15:17:07.365322 2026] [security2:error] [pid 971102:tid 971238] [client 35.202.49.146:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwNAAAAAQ"]
[Thu Sep 17 15:17:07.435743 2026] [security2:error] [pid 971102:tid 971314] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/preview/.env"] [unique_id "aqxY0-cL08BTTQixEnpwOAAAAFA"]
[Thu Sep 17 15:17:07.436007 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxY0-cL08BTTQixEnpwOQAAAHU"]
[Thu Sep 17 15:17:07.526085 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:35314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/test/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwQAAAAFY"]
[Thu Sep 17 15:17:07.552240 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/admin-panel/.env"] [unique_id "aqxY0-cL08BTTQixEnpwQQAAAHk"]
[Thu Sep 17 15:17:07.556810 2026] [security2:error] [pid 971102:tid 971341] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/beta/.env"] [unique_id "aqxY0-cL08BTTQixEnpwQgAAAGs"]
[Thu Sep 17 15:17:07.562867 2026] [security2:error] [pid 971102:tid 971305] [client 8.29.0.172:44045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY0-cL08BTTQixEnpwPAAAR0I"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260615191631&hideliu=1&hideminor=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:17:07.593485 2026] [security2:error] [pid 971102:tid 971251] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxY0-cL08BTTQixEnpwRAAAABE"]
[Thu Sep 17 15:17:07.665019 2026] [security2:error] [pid 971102:tid 971249] [client 35.202.49.146:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwRQAAAA8"]
[Thu Sep 17 15:17:07.677422 2026] [security2:error] [pid 971102:tid 971255] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/uat/.env"] [unique_id "aqxY0-cL08BTTQixEnpwRgAAABU"]
[Thu Sep 17 15:17:07.736644 2026] [security2:error] [pid 971102:tid 971262] [client 185.46.77.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxY0ucL08BTTQixEnpv4gAAABw"], referer: https://kidsandlifeot.com/
[Thu Sep 17 15:17:07.745862 2026] [security2:error] [pid 971102:tid 971279] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxY0-cL08BTTQixEnpwSQAAAC0"]
[Thu Sep 17 15:17:07.786485 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/control-panel/.env"] [unique_id "aqxY0-cL08BTTQixEnpwSgAAAHY"]
[Thu Sep 17 15:17:07.807778 2026] [security2:error] [pid 971102:tid 971318] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/stage/.env"] [unique_id "aqxY0-cL08BTTQixEnpwSwAAAFQ"]
[Thu Sep 17 15:17:07.835371 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:35326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/old/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwTAAAAAo"]
[Thu Sep 17 15:17:07.906237 2026] [security2:error] [pid 971102:tid 971278] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxY0-cL08BTTQixEnpwTgAAACw"]
[Thu Sep 17 15:17:07.938313 2026] [security2:error] [pid 971102:tid 971252] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/development/.env"] [unique_id "aqxY0-cL08BTTQixEnpwUQAAABI"]
[Thu Sep 17 15:17:07.974163 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:50093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0-cL08BTTQixEnpwUgAAAAg"]
[Thu Sep 17 15:17:07.975526 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:50093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0-cL08BTTQixEnpwUgAAAAg"]
[Thu Sep 17 15:17:08.019451 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwVQAAAGY"]
[Thu Sep 17 15:17:08.021366 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/user-panel/.env"] [unique_id "aqxY1OcL08BTTQixEnpwVgAAADA"]
[Thu Sep 17 15:17:08.062699 2026] [security2:error] [pid 971102:tid 971299] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxY1OcL08BTTQixEnpwWQAAAEE"]
[Thu Sep 17 15:17:08.064225 2026] [security2:error] [pid 971102:tid 971338] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/production/.env"] [unique_id "aqxY1OcL08BTTQixEnpwWgAAAGg"]
[Thu Sep 17 15:17:08.188675 2026] [security2:error] [pid 971102:tid 971317] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/config/app/.env"] [unique_id "aqxY1OcL08BTTQixEnpwWwAAAFM"]
[Thu Sep 17 15:17:08.191156 2026] [security2:error] [pid 971102:tid 971253] [client 35.202.49.146:35338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/public/phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwXAAAABM"]
[Thu Sep 17 15:17:08.214822 2026] [security2:error] [pid 971102:tid 971289] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxY1OcL08BTTQixEnpwYAAAADc"]
[Thu Sep 17 15:17:08.254853 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/node/.env"] [unique_id "aqxY1OcL08BTTQixEnpwYQAAADg"]
[Thu Sep 17 15:17:08.325696 2026] [security2:error] [pid 971102:tid 971247] [client 34.97.30.29:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwYwAAAA0"]
[Thu Sep 17 15:17:08.333750 2026] [security2:error] [pid 971102:tid 971319] [client 35.202.49.146:35350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY1OcL08BTTQixEnpwZAAAAFU"]
[Thu Sep 17 15:17:08.368834 2026] [security2:error] [pid 971102:tid 971344] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxY1OcL08BTTQixEnpwZQAAAG4"]
[Thu Sep 17 15:17:08.379593 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/php-info.php"] [unique_id "aqxY1OcL08BTTQixEnpwZwAAACQ"]
[Thu Sep 17 15:17:08.488762 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/express/.env"] [unique_id "aqxY1OcL08BTTQixEnpwaAAAADQ"]
[Thu Sep 17 15:17:08.522296 2026] [security2:error] [pid 971102:tid 971346] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxY1OcL08BTTQixEnpwawAAAHA"]
[Thu Sep 17 15:17:08.548179 2026] [security2:error] [pid 971102:tid 971285] [client 35.202.49.146:35360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpversion.php"] [unique_id "aqxY1OcL08BTTQixEnpwbwAAADM"]
[Thu Sep 17 15:17:08.677225 2026] [security2:error] [pid 971102:tid 971243] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxY1OcL08BTTQixEnpwcwAAAAk"]
[Thu Sep 17 15:17:08.705797 2026] [security2:error] [pid 971102:tid 971237] [client 35.202.49.146:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/_phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwdAAAAAM"]
[Thu Sep 17 15:17:08.714067 2026] [security2:error] [pid 971102:tid 971261] [client 34.97.30.29:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/info.php"] [unique_id "aqxY1OcL08BTTQixEnpwdgAAABs"]
[Thu Sep 17 15:17:08.723598 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/next/.env"] [unique_id "aqxY1OcL08BTTQixEnpwdwAAAB0"]
[Thu Sep 17 15:17:08.835332 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxY1OcL08BTTQixEnpweAAAAB4"]
[Thu Sep 17 15:17:08.862342 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/old_phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpweQAAAFA"]
[Thu Sep 17 15:17:08.949268 2026] [security2:error] [pid 971102:tid 971331] [client 172.239.147.162:57475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxY1OcL08BTTQixEnpwfAAAAGE"], referer: binance.com
[Thu Sep 17 15:17:08.958221 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/nuxt/.env"] [unique_id "aqxY1OcL08BTTQixEnpwfwAAAGs"]
[Thu Sep 17 15:17:08.991362 2026] [security2:error] [pid 971102:tid 971251] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxY1OcL08BTTQixEnpwgQAAABE"]
[Thu Sep 17 15:17:09.038379 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/server-info.php"] [unique_id "aqxY1ecL08BTTQixEnpwggAAAE4"]
[Thu Sep 17 15:17:09.090972 2026] [security2:error] [pid 971102:tid 971277] [client 34.97.30.29:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/php.php"] [unique_id "aqxY1ecL08BTTQixEnpwhQAAACs"]
[Thu Sep 17 15:17:09.147137 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxY1ecL08BTTQixEnpwhgAAADU"]
[Thu Sep 17 15:17:09.190137 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/nest/.env"] [unique_id "aqxY1ecL08BTTQixEnpwhwAAAAs"]
[Thu Sep 17 15:17:09.196498 2026] [security2:error] [pid 971102:tid 971295] [client 35.202.49.146:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/server-status.php"] [unique_id "aqxY1ecL08BTTQixEnpwiAAAAD0"]
[Thu Sep 17 15:17:09.300208 2026] [security2:error] [pid 971102:tid 971354] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxY1ecL08BTTQixEnpwigAAAHg"]
[Thu Sep 17 15:17:09.363713 2026] [security2:error] [pid 971102:tid 971254] [client 35.202.49.146:35404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY1ecL08BTTQixEnpwiwAAABQ"]
[Thu Sep 17 15:17:09.419931 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/react/.env"] [unique_id "aqxY1ecL08BTTQixEnpwjgAAADI"]
[Thu Sep 17 15:17:09.452415 2026] [security2:error] [pid 971102:tid 971318] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxY1ecL08BTTQixEnpwkQAAAFQ"]
[Thu Sep 17 15:17:09.457774 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY1ecL08BTTQixEnpwkgAAAAo"]
[Thu Sep 17 15:17:09.462781 2026] [security2:error] [pid 971102:tid 971321] [client 34.97.30.29:42464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/i.php"] [unique_id "aqxY1ecL08BTTQixEnpwkwAAAFc"]
[Thu Sep 17 15:17:09.590136 2026] [security2:error] [pid 971102:tid 971278] [client 35.202.49.146:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxY1ecL08BTTQixEnpwlgAAACw"]
[Thu Sep 17 15:17:09.595293 2026] [security2:error] [pid 971102:tid 971361] [client 172.239.147.162:50221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxY1ecL08BTTQixEnpwlwAAAH8"], referer: binance.com
[Thu Sep 17 15:17:09.609003 2026] [security2:error] [pid 971102:tid 971349] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxY1ecL08BTTQixEnpwmQAAAHM"]
[Thu Sep 17 15:17:09.649788 2026] [security2:error] [pid 971102:tid 971315] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vue/.env"] [unique_id "aqxY1ecL08BTTQixEnpwmgAAAFE"]
[Thu Sep 17 15:17:09.741854 2026] [security2:error] [pid 971102:tid 971335] [client 35.202.49.146:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY1ecL08BTTQixEnpwnAAAAGU"]
[Thu Sep 17 15:17:09.766163 2026] [security2:error] [pid 971102:tid 971299] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxY1ecL08BTTQixEnpwnQAAAEE"]
[Thu Sep 17 15:17:09.852897 2026] [security2:error] [pid 971102:tid 971336] [client 34.97.30.29:42476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/pi.php"] [unique_id "aqxY1ecL08BTTQixEnpwnwAAAGY"]
[Thu Sep 17 15:17:09.878974 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/angular/.env"] [unique_id "aqxY1ecL08BTTQixEnpwoQAAAEM"]
[Thu Sep 17 15:17:09.904889 2026] [security2:error] [pid 971102:tid 971325] [client 35.202.49.146:35428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY1ecL08BTTQixEnpwpQAAAFs"]
[Thu Sep 17 15:17:09.929714 2026] [security2:error] [pid 971102:tid 971311] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxY1ecL08BTTQixEnpwpgAAAE0"]
[Thu Sep 17 15:17:09.931818 2026] [security2:error] [pid 971102:tid 971317] [client 127.0.0.1:60206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxY1ecL08BTTQixEnpwpAAAAFM"]
[Thu Sep 17 15:17:09.931908 2026] [security2:error] [pid 971102:tid 971256] [client 74.7.241.158:42994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wtff.net"] [uri "/robots.txt"] [unique_id "aqxY1ecL08BTTQixEnpwogAAFjI"]
[Thu Sep 17 15:17:10.052779 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY1ucL08BTTQixEnpwqgAAAFo"]
[Thu Sep 17 15:17:10.084183 2026] [security2:error] [pid 971102:tid 971340] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxY1ucL08BTTQixEnpwrQAAAGo"]
[Thu Sep 17 15:17:10.107766 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/svelte/.env"] [unique_id "aqxY1ucL08BTTQixEnpwrgAAAA0"]
[Thu Sep 17 15:17:10.212381 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:35442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY1ucL08BTTQixEnpwsgAAAHw"]
[Thu Sep 17 15:17:10.245555 2026] [security2:error] [pid 971102:tid 971345] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxY1ucL08BTTQixEnpwtAAAAG8"]
[Thu Sep 17 15:17:10.281533 2026] [security2:error] [pid 971102:tid 971344] [client 34.97.30.29:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/pinfo.php"] [unique_id "aqxY1ucL08BTTQixEnpwtQAAAG4"]
[Thu Sep 17 15:17:10.337554 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vite/.env"] [unique_id "aqxY1ucL08BTTQixEnpwtwAAAAk"]
[Thu Sep 17 15:17:10.378231 2026] [security2:error] [pid 971102:tid 971250] [client 35.202.49.146:35448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxY1ucL08BTTQixEnpwuAAAABA"]
[Thu Sep 17 15:17:10.398071 2026] [security2:error] [pid 971102:tid 971269] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxY1ucL08BTTQixEnpwuQAAACM"]
[Thu Sep 17 15:17:10.507030 2026] [security2:error] [pid 971102:tid 971238] [client 172.239.147.162:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxY1ucL08BTTQixEnpwwwAAAAQ"], referer: binance.com
[Thu Sep 17 15:17:10.535831 2026] [security2:error] [pid 971102:tid 971281] [client 35.202.49.146:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php.old"] [unique_id "aqxY1ucL08BTTQixEnpwxQAAAC8"]
[Thu Sep 17 15:17:10.553103 2026] [security2:error] [pid 971102:tid 971331] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxY1ucL08BTTQixEnpwxwAAAGE"]
[Thu Sep 17 15:17:10.582404 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxY1ucL08BTTQixEnpwyAAAAEc"]
[Thu Sep 17 15:17:10.682859 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/test.php"] [unique_id "aqxY1ucL08BTTQixEnpwygAAAAI"]
[Thu Sep 17 15:17:10.710026 2026] [security2:error] [pid 971102:tid 971337] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxY1ucL08BTTQixEnpwywAAAGc"]
[Thu Sep 17 15:17:10.716678 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php~"] [unique_id "aqxY1ucL08BTTQixEnpwzAAAAE4"]
[Thu Sep 17 15:17:10.817348 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backups/.env"] [unique_id "aqxY1ucL08BTTQixEnpwzgAAAAA"]
[Thu Sep 17 15:17:10.862641 2026] [security2:error] [pid 971102:tid 971307] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxY1ucL08BTTQixEnpwzwAAAEk"]
[Thu Sep 17 15:17:10.870759 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/info.php.bak"] [unique_id "aqxY1ucL08BTTQixEnpw0AAAAAs"]
[Thu Sep 17 15:17:11.014872 2026] [security2:error] [pid 971102:tid 971353] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxY1-cL08BTTQixEnpw1wAAAHc"]
[Thu Sep 17 15:17:11.026440 2026] [security2:error] [pid 971102:tid 971357] [client 35.202.49.146:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php.save"] [unique_id "aqxY1-cL08BTTQixEnpw2AAAAHs"]
[Thu Sep 17 15:17:11.051873 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxY1-cL08BTTQixEnpw2QAAAFQ"]
[Thu Sep 17 15:17:11.172833 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxY1-cL08BTTQixEnpw3QAAAH8"]
[Thu Sep 17 15:17:11.175747 2026] [security2:error] [pid 971102:tid 971252] [client 35.202.49.146:35514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw3gAAABI"]
[Thu Sep 17 15:17:11.209035 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY1-cL08BTTQixEnpw4AAAAE8"]
[Thu Sep 17 15:17:11.209143 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY1-cL08BTTQixEnpw4AAAAE8"]
[Thu Sep 17 15:17:11.287554 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/tmp/.env"] [unique_id "aqxY1-cL08BTTQixEnpw5AAAAGU"]
[Thu Sep 17 15:17:11.300515 2026] [security2:error] [pid 971102:tid 971322] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY1-cL08BTTQixEnpw3wAAAFg"]
[Thu Sep 17 15:17:11.327405 2026] [security2:error] [pid 971102:tid 971235] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxY1-cL08BTTQixEnpw5gAAAAE"]
[Thu Sep 17 15:17:11.345334 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw6AAAAEE"]
[Thu Sep 17 15:17:11.492886 2026] [security2:error] [pid 971102:tid 971247] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxY1-cL08BTTQixEnpw8AAAAA0"]
[Thu Sep 17 15:17:11.515908 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:35524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw8gAAAFo"]
[Thu Sep 17 15:17:11.524137 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/temp/.env"] [unique_id "aqxY1-cL08BTTQixEnpw8wAAAG8"]
[Thu Sep 17 15:17:11.575547 2026] [security2:error] [pid 971102:tid 971243] [client 34.97.30.29:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/p.php"] [unique_id "aqxY1-cL08BTTQixEnpw9gAAAAk"]
[Thu Sep 17 15:17:11.655817 2026] [security2:error] [pid 971102:tid 971319] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxY1-cL08BTTQixEnpw-AAAAFU"]
[Thu Sep 17 15:17:11.686503 2026] [security2:error] [pid 971102:tid 971263] [client 35.202.49.146:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw-gAAAB0"]
[Thu Sep 17 15:17:11.766250 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/lab/.env"] [unique_id "aqxY1-cL08BTTQixEnpw_QAAADs"]
[Thu Sep 17 15:17:11.819368 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxY1-cL08BTTQixEnpxAAAAAB4"]
[Thu Sep 17 15:17:11.835714 2026] [security2:error] [pid 971102:tid 971236] [client 35.202.49.146:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpxAQAAAAI"]
[Thu Sep 17 15:17:11.865318 2026] [security2:error] [pid 971102:tid 971326] [client 172.239.147.162:50027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxY1-cL08BTTQixEnpxBAAAAFw"], referer: binance.com
[Thu Sep 17 15:17:11.971927 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:42512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/debug.php"] [unique_id "aqxY1-cL08BTTQixEnpxBwAAAGw"]
[Thu Sep 17 15:17:11.976115 2026] [security2:error] [pid 971102:tid 971275] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxY1-cL08BTTQixEnpxCAAAACk"]
[Thu Sep 17 15:17:12.000985 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cronlab/.env"] [unique_id "aqxY1-cL08BTTQixEnpxCwAAAD8"]
[Thu Sep 17 15:17:12.009904 2026] [security2:error] [pid 971102:tid 971276] [client 35.202.49.146:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/www/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxDAAAACo"]
[Thu Sep 17 15:17:12.128807 2026] [security2:error] [pid 971102:tid 971356] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxY2OcL08BTTQixEnpxEAAAAHo"]
[Thu Sep 17 15:17:12.169765 2026] [security2:error] [pid 971102:tid 971279] [client 35.202.49.146:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxEgAAAC0"]
[Thu Sep 17 15:17:12.236151 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cron/.env"] [unique_id "aqxY2OcL08BTTQixEnpxFAAAAEw"]
[Thu Sep 17 15:17:12.282932 2026] [security2:error] [pid 971102:tid 971272] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxY2OcL08BTTQixEnpxFQAAACY"]
[Thu Sep 17 15:17:12.333042 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxGAAAAEg"]
[Thu Sep 17 15:17:12.369088 2026] [security2:error] [pid 971102:tid 971254] [client 34.97.30.29:42524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxGQAAABQ"]
[Thu Sep 17 15:17:12.435238 2026] [security2:error] [pid 971102:tid 971286] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxY2OcL08BTTQixEnpxGgAAADQ"]
[Thu Sep 17 15:17:12.465535 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/en/.env"] [unique_id "aqxY2OcL08BTTQixEnpxGwAAAGg"]
[Thu Sep 17 15:17:12.479879 2026] [security2:error] [pid 971102:tid 971335] [client 35.202.49.146:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/site/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxHQAAAGU"]
[Thu Sep 17 15:17:12.588969 2026] [security2:error] [pid 971102:tid 971256] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxY2OcL08BTTQixEnpxIwAAABY"]
[Thu Sep 17 15:17:12.639117 2026] [security2:error] [pid 971102:tid 971317] [client 35.202.49.146:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxJAAAAFM"]
[Thu Sep 17 15:17:12.713559 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxY2OcL08BTTQixEnpxJgAAADw"]
[Thu Sep 17 15:17:12.737893 2026] [security2:error] [pid 971102:tid 971260] [client 34.97.30.29:42540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/test/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxJwAAABo"]
[Thu Sep 17 15:17:12.741706 2026] [security2:error] [pid 971102:tid 971332] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxY2OcL08BTTQixEnpxKAAAAGI"]
[Thu Sep 17 15:17:12.803606 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxKgAAAHw"]
[Thu Sep 17 15:17:12.885380 2026] [security2:error] [pid 971102:tid 971360] [client 185.55.149.49:60119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY2OcL08BTTQixEnpxLAAAAH4"]
[Thu Sep 17 15:17:12.885493 2026] [security2:error] [pid 971102:tid 971360] [client 185.55.149.49:60119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY2OcL08BTTQixEnpxLAAAAH4"]
[Thu Sep 17 15:17:12.900030 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxY2OcL08BTTQixEnpxLQAAACU"]
[Thu Sep 17 15:17:12.944391 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/psnlink/.env"] [unique_id "aqxY2OcL08BTTQixEnpxLgAAAG8"]
[Thu Sep 17 15:17:12.961790 2026] [security2:error] [pid 971102:tid 971285] [client 35.202.49.146:35608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxMQAAADM"]
[Thu Sep 17 15:17:13.052743 2026] [security2:error] [pid 971102:tid 971237] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxY2ecL08BTTQixEnpxNQAAAAM"]
[Thu Sep 17 15:17:13.118038 2026] [security2:error] [pid 971102:tid 971238] [client 35.202.49.146:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/core/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxOQAAAAQ"]
[Thu Sep 17 15:17:13.128115 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:42552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxOgAAAEQ"]
[Thu Sep 17 15:17:13.174763 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/exapi/.env"] [unique_id "aqxY2ecL08BTTQixEnpxQAAAAD4"]
[Thu Sep 17 15:17:13.188734 2026] [security2:error] [pid 971102:tid 971330] [client 45.169.98.18:58663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ecL08BTTQixEnpxQwAAAGA"]
[Thu Sep 17 15:17:13.188839 2026] [security2:error] [pid 971102:tid 971330] [client 45.169.98.18:58663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ecL08BTTQixEnpxQwAAAGA"]
[Thu Sep 17 15:17:13.206338 2026] [security2:error] [pid 971102:tid 971290] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxY2ecL08BTTQixEnpxRAAAADg"]
[Thu Sep 17 15:17:13.238187 2026] [security2:error] [pid 971102:tid 971140] [remote 111.225.148.157:26768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/"] [unique_id "aqxY2ecL08BTTQixEnpxRgAAHiQ"]
[Thu Sep 17 15:17:13.276998 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:35614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxSAAAAE4"]
[Thu Sep 17 15:17:13.360716 2026] [security2:error] [pid 971102:tid 971333] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxY2ecL08BTTQixEnpxTAAAAGM"]
[Thu Sep 17 15:17:13.407105 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sitemaps/.env"] [unique_id "aqxY2ecL08BTTQixEnpxTgAAACw"]
[Thu Sep 17 15:17:13.423589 2026] [security2:error] [pid 971102:tid 971252] [client 134.185.85.61:64652] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "slimmtech.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxY2ecL08BTTQixEnpxUQAAABI"]
[Thu Sep 17 15:17:13.446868 2026] [security2:error] [pid 971102:tid 971258] [client 35.202.49.146:35628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY2ecL08BTTQixEnpxVgAAABg"]
[Thu Sep 17 15:17:13.506057 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:42564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/old/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxXAAAAHI"]
[Thu Sep 17 15:17:13.535387 2026] [security2:error] [pid 971102:tid 971286] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxY2ecL08BTTQixEnpxXgAAADQ"]
[Thu Sep 17 15:17:13.615073 2026] [security2:error] [pid 971102:tid 971315] [client 172.239.147.162:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxY2ecL08BTTQixEnpxYwAAAFE"], referer: binance.com
[Thu Sep 17 15:17:13.688517 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxY2ecL08BTTQixEnpxaQAAAGY"]
[Thu Sep 17 15:17:13.805685 2026] [security2:error] [pid 971102:tid 971360] [client 134.185.85.61:61214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "slimmtech.com"] [uri "/media/system/js/core.js"] [unique_id "aqxY2ecL08BTTQixEnpxegAAAH4"]
[Thu Sep 17 15:17:13.844961 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxY2ecL08BTTQixEnpxfQAAADM"]
[Thu Sep 17 15:17:13.875581 2026] [security2:error] [pid 971102:tid 971332] [client 34.97.30.29:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxfwAAAGI"]
[Thu Sep 17 15:17:14.004292 2026] [security2:error] [pid 971102:tid 971320] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxY2ucL08BTTQixEnpxiQAAAFY"]
[Thu Sep 17 15:17:14.161304 2026] [security2:error] [pid 971102:tid 971236] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxY2ucL08BTTQixEnpxkAAAAAI"]
[Thu Sep 17 15:17:14.197966 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/logs/.env"] [unique_id "aqxY2ucL08BTTQixEnpxkgAAAGw"]
[Thu Sep 17 15:17:14.247704 2026] [security2:error] [pid 971102:tid 971282] [client 34.97.30.29:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/public/phpinfo.php"] [unique_id "aqxY2ucL08BTTQixEnpxkwAAADA"]
[Thu Sep 17 15:17:14.315681 2026] [security2:error] [pid 971102:tid 971266] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxY2ucL08BTTQixEnpxmAAAACA"]
[Thu Sep 17 15:17:14.407155 2026] [security2:error] [pid 971102:tid 971129] [remote 110.249.202.132:61972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christiansoncampusnlc.com"] [uri "/"] [unique_id "aqxY2ucL08BTTQixEnpxmgAAKRk"]
[Thu Sep 17 15:17:14.468346 2026] [security2:error] [pid 971102:tid 971244] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxY2ucL08BTTQixEnpxnQAAAAo"]
[Thu Sep 17 15:17:14.620814 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxY2ucL08BTTQixEnpxpgAAAHU"]
[Thu Sep 17 15:17:14.704485 2026] [security2:error] [pid 971102:tid 971278] [client 172.239.147.162:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxY2ucL08BTTQixEnpxqwAAACw"], referer: binance.com
[Thu Sep 17 15:17:14.781854 2026] [security2:error] [pid 971102:tid 971301] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxY2ucL08BTTQixEnpxrAAAAEM"]
[Thu Sep 17 15:17:14.785468 2026] [security2:error] [pid 971102:tid 971316] [client 154.190.208.131:42403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ucL08BTTQixEnpxrgAAAFI"]
[Thu Sep 17 15:17:14.794894 2026] [security2:error] [pid 971102:tid 971316] [client 154.190.208.131:42403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ucL08BTTQixEnpxrgAAAFI"]
[Thu Sep 17 15:17:14.830564 2026] [security2:error] [pid 971102:tid 971354] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY2ucL08BTTQixEnpxqQAAAHg"]
[Thu Sep 17 15:17:14.890634 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cache/.env"] [unique_id "aqxY2ucL08BTTQixEnpxsAAAAGU"]
[Thu Sep 17 15:17:14.936840 2026] [security2:error] [pid 971102:tid 971256] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxY2ucL08BTTQixEnpxsQAAABY"]
[Thu Sep 17 15:17:15.093380 2026] [security2:error] [pid 971102:tid 971247] [client 34.97.30.29:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/php-info.php"] [unique_id "aqxY2-cL08BTTQixEnpxtgAAAA0"]
[Thu Sep 17 15:17:15.099382 2026] [security2:error] [pid 971102:tid 971272] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxY2-cL08BTTQixEnpxtwAAACY"]
[Thu Sep 17 15:17:15.119816 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailer/.env"] [unique_id "aqxY2-cL08BTTQixEnpxuQAAADo"]
[Thu Sep 17 15:17:15.135432 2026] [security2:error] [pid 971102:tid 971303] [client 172.239.147.162:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxY2-cL08BTTQixEnpxugAAAEU"], referer: binance.com
[Thu Sep 17 15:17:15.214860 2026] [security2:error] [pid 971102:tid 971245] [client 192.71.12.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxY2ucL08BTTQixEnpxlwAAAAs"], referer: http://iradtech.com/robots.txt
[Thu Sep 17 15:17:15.252959 2026] [security2:error] [pid 971102:tid 971241] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxY2-cL08BTTQixEnpxvQAAAAc"]
[Thu Sep 17 15:17:15.349519 2026] [security2:error] [pid 971102:tid 971267] [client 114.198.138.124:64235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2-cL08BTTQixEnpxwAAAACE"]
[Thu Sep 17 15:17:15.349610 2026] [security2:error] [pid 971102:tid 971267] [client 114.198.138.124:64235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2-cL08BTTQixEnpxwAAAACE"]
[Thu Sep 17 15:17:15.351019 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mail/.env"] [unique_id "aqxY2-cL08BTTQixEnpxvwAAAB0"]
[Thu Sep 17 15:17:15.407170 2026] [security2:error] [pid 971102:tid 971269] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxY2-cL08BTTQixEnpxxgAAACM"]
[Thu Sep 17 15:17:15.473008 2026] [security2:error] [pid 971102:tid 971285] [client 34.97.30.29:59770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpversion.php"] [unique_id "aqxY2-cL08BTTQixEnpxyQAAADM"]
[Thu Sep 17 15:17:15.520108 2026] [security2:error] [pid 971102:tid 971319] [client 93.152.209.11:43096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.commonearthjc.com"] [uri "/.env"] [unique_id "aqxY2-cL08BTTQixEnpxzgAAAFU"]
[Thu Sep 17 15:17:15.560139 2026] [security2:error] [pid 971102:tid 971273] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxY2-cL08BTTQixEnpx0QAAACc"]
[Thu Sep 17 15:17:15.585623 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/email/.env"] [unique_id "aqxY2-cL08BTTQixEnpx0gAAAHs"]
[Thu Sep 17 15:17:15.704249 2026] [security2:error] [pid 971102:tid 971106] [remote 93.152.209.11:34704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.commonearthjc.com"] [uri "/.env"] [unique_id "aqxY2-cL08BTTQixEnpx1gAAZAI"]
[Thu Sep 17 15:17:15.714180 2026] [security2:error] [pid 971102:tid 971309] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxY2-cL08BTTQixEnpx2AAAAEs"]
[Thu Sep 17 15:17:15.815330 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/smtp/.env"] [unique_id "aqxY2-cL08BTTQixEnpx3gAAABs"]
[Thu Sep 17 15:17:15.845746 2026] [security2:error] [pid 971102:tid 971314] [client 34.97.30.29:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/_phpinfo.php"] [unique_id "aqxY2-cL08BTTQixEnpx3wAAAFA"]
[Thu Sep 17 15:17:15.874266 2026] [security2:error] [pid 971102:tid 971266] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxY2-cL08BTTQixEnpx4AAAACA"]
[Thu Sep 17 15:17:16.031651 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxY3OcL08BTTQixEnpx6gAAAH8"]
[Thu Sep 17 15:17:16.048637 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailing/.env"] [unique_id "aqxY3OcL08BTTQixEnpx6wAAABQ"]
[Thu Sep 17 15:17:16.260966 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/old_phpinfo.php"] [unique_id "aqxY3OcL08BTTQixEnpx7wAAAC0"]
[Thu Sep 17 15:17:16.287697 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/notifications/.env"] [unique_id "aqxY3OcL08BTTQixEnpx8gAAADU"]
[Thu Sep 17 15:17:16.354593 2026] [fcgid:warn] [pid 971102:tid 971329] (70014)End of file found: [client 152.32.215.226:44956] mod_fcgid: can't get data from http client
[Thu Sep 17 15:17:16.433336 2026] [security2:error] [pid 971102:tid 971352] [client 114.119.134.110:56779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.silverstaterealty.com"] [uri "/robots.txt"] [unique_id "aqxY3OcL08BTTQixEnpx-QAAAHY"], referer: https://www.silverstaterealty.com/robots.txt
[Thu Sep 17 15:17:16.507255 2026] [security2:error] [pid 971102:tid 971354] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxY3OcL08BTTQixEnpx_wAAAHg"]
[Thu Sep 17 15:17:16.533397 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/notify/.env"] [unique_id "aqxY3OcL08BTTQixEnpyAAAAAFc"]
[Thu Sep 17 15:17:16.637992 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3OcL08BTTQixEnpyBAAAABg"]
[Thu Sep 17 15:17:16.638140 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:53901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3OcL08BTTQixEnpyBAAAABg"]
[Thu Sep 17 15:17:16.641295 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:59804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/server-info.php"] [unique_id "aqxY3OcL08BTTQixEnpyBQAAABM"]
[Thu Sep 17 15:17:16.663847 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxY3OcL08BTTQixEnpyBgAAADw"]
[Thu Sep 17 15:17:16.664776 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:56420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3OcL08BTTQixEnpyBwAAABo"]
[Thu Sep 17 15:17:16.716645 2026] [security2:error] [pid 971102:tid 971280] [client 172.239.147.162:60513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxY3OcL08BTTQixEnpyCAAAAC4"], referer: binance.com
[Thu Sep 17 15:17:16.771083 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sender/.env"] [unique_id "aqxY3OcL08BTTQixEnpyCgAAAAc"]
[Thu Sep 17 15:17:16.826841 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxY3OcL08BTTQixEnpyCwAAACU"]
[Thu Sep 17 15:17:16.983671 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxY3OcL08BTTQixEnpyEAAAADM"]
[Thu Sep 17 15:17:17.007507 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/campaign/.env"] [unique_id "aqxY3ecL08BTTQixEnpyFAAAADE"]
[Thu Sep 17 15:17:17.014091 2026] [security2:error] [pid 971102:tid 971263] [client 179.6.165.237:6510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY3OcL08BTTQixEnpyDAAAHSE"]
[Thu Sep 17 15:17:17.035206 2026] [security2:error] [pid 971102:tid 971239] [client 172.239.147.162:60539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxY3ecL08BTTQixEnpyFwAAAAU"], referer: binance.com
[Thu Sep 17 15:17:17.056176 2026] [security2:error] [pid 971102:tid 971267] [client 34.97.30.29:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/server-status.php"] [unique_id "aqxY3ecL08BTTQixEnpyGQAAACE"]
[Thu Sep 17 15:17:17.140647 2026] [security2:error] [pid 971102:tid 971257] [client 34.151.157.242:56436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3ecL08BTTQixEnpyHwAAABc"]
[Thu Sep 17 15:17:17.144550 2026] [security2:error] [pid 971102:tid 971334] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxY3ecL08BTTQixEnpyIAAAAGQ"]
[Thu Sep 17 15:17:17.181835 2026] [security2:error] [pid 971102:tid 971302] [client 136.116.35.245:59724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "moorekuehn.com"] [uri "/.env"] [unique_id "aqxY3ecL08BTTQixEnpyIgAAAEQ"]
[Thu Sep 17 15:17:17.244263 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/newsletter/.env"] [unique_id "aqxY3ecL08BTTQixEnpyJAAAACQ"]
[Thu Sep 17 15:17:17.268131 2026] [security2:error] [pid 971102:tid 971320] [client 5.133.215.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxY3ecL08BTTQixEnpyGgAAAFY"], referer: http://iradtech.com/llms.txt
[Thu Sep 17 15:17:17.312429 2026] [security2:error] [pid 971102:tid 971261] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxY3ecL08BTTQixEnpyJgAAABs"]
[Thu Sep 17 15:17:17.415457 2026] [security2:error] [pid 971102:tid 971288] [client 136.116.35.245:52760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "moorekuehn.com"] [uri "/.env"] [unique_id "aqxY3ecL08BTTQixEnpyJwAAADY"]
[Thu Sep 17 15:17:17.471792 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxY3ecL08BTTQixEnpyLAAAAHU"]
[Thu Sep 17 15:17:17.480722 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ses/.env"] [unique_id "aqxY3ecL08BTTQixEnpyLQAAABQ"]
[Thu Sep 17 15:17:17.606999 2026] [security2:error] [pid 971102:tid 971312] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY3ecL08BTTQixEnpyMAAAAE4"]
[Thu Sep 17 15:17:17.617514 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:56446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3ecL08BTTQixEnpyMgAAABI"]
[Thu Sep 17 15:17:17.627974 2026] [security2:error] [pid 971102:tid 971277] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxY3ecL08BTTQixEnpyNAAAACs"]
[Thu Sep 17 15:17:17.717221 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sendgrid/.env"] [unique_id "aqxY3ecL08BTTQixEnpyNQAAAGk"]
[Thu Sep 17 15:17:17.784992 2026] [security2:error] [pid 971102:tid 971295] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxY3ecL08BTTQixEnpyOAAAAD0"]
[Thu Sep 17 15:17:17.943648 2026] [security2:error] [pid 971102:tid 971299] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxY3ecL08BTTQixEnpyPQAAAEE"]
[Thu Sep 17 15:17:17.953156 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sparkpost/.env"] [unique_id "aqxY3ecL08BTTQixEnpyQAAAAFc"]
[Thu Sep 17 15:17:18.109766 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY3ecL08BTTQixEnpyRAAAAEM"]
[Thu Sep 17 15:17:18.121859 2026] [security2:error] [pid 971102:tid 971258] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxY3ucL08BTTQixEnpySgAAABg"]
[Thu Sep 17 15:17:18.193621 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/postmark/.env"] [unique_id "aqxY3ucL08BTTQixEnpyTQAAADk"]
[Thu Sep 17 15:17:18.280302 2026] [security2:error] [pid 971102:tid 971268] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxY3ucL08BTTQixEnpyTgAAACI"]
[Thu Sep 17 15:17:18.302706 2026] [security2:error] [pid 971102:tid 971306] [client 34.97.30.29:59816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY3ucL08BTTQixEnpyUAAAAEg"]
[Thu Sep 17 15:17:18.424122 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailgun/.env"] [unique_id "aqxY3ucL08BTTQixEnpyUQAAAG4"]
[Thu Sep 17 15:17:18.439493 2026] [security2:error] [pid 971102:tid 971319] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxY3ucL08BTTQixEnpyUgAAAFU"]
[Thu Sep 17 15:17:18.480749 2026] [security2:error] [pid 971102:tid 971289] [client 172.239.147.162:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxY3ucL08BTTQixEnpyVgAAADc"], referer: binance.com
[Thu Sep 17 15:17:18.553214 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3ucL08BTTQixEnpyWgAAAAs"]
[Thu Sep 17 15:17:18.555376 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:50724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3ucL08BTTQixEnpyWgAAAAs"]
[Thu Sep 17 15:17:18.597783 2026] [security2:error] [pid 971102:tid 971350] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxY3ucL08BTTQixEnpyXAAAAHQ"]
[Thu Sep 17 15:17:18.654967 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mandrill/.env"] [unique_id "aqxY3ucL08BTTQixEnpyXwAAAGQ"]
[Thu Sep 17 15:17:18.719480 2026] [security2:error] [pid 971102:tid 971331] [client 34.97.30.29:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxY3ucL08BTTQixEnpyYgAAAGE"]
[Thu Sep 17 15:17:18.760519 2026] [security2:error] [pid 971102:tid 971243] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxY3ucL08BTTQixEnpyYwAAAAk"]
[Thu Sep 17 15:17:18.887377 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailjet/.env"] [unique_id "aqxY3ucL08BTTQixEnpyZwAAAFw"]
[Thu Sep 17 15:17:18.917589 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxY3ucL08BTTQixEnpyaQAAAB4"]
[Thu Sep 17 15:17:19.023711 2026] [security2:error] [pid 971102:tid 971269] [client 91.95.13.55:51638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY3ucL08BTTQixEnpyaAAAI3c"]
[Thu Sep 17 15:17:19.089124 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxY3-cL08BTTQixEnpybgAAADY"]
[Thu Sep 17 15:17:19.120561 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/brevo/.env"] [unique_id "aqxY3-cL08BTTQixEnpybwAAABw"]
[Thu Sep 17 15:17:19.150161 2026] [security2:error] [pid 971102:tid 971266] [client 34.97.30.29:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY3-cL08BTTQixEnpycAAAACA"]
[Thu Sep 17 15:17:19.183158 2026] [security2:error] [pid 971102:tid 971358] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY3ucL08BTTQixEnpyTAAAAHw"]
[Thu Sep 17 15:17:19.209992 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY3OcL08BTTQixEnpyAgAAACo"]
[Thu Sep 17 15:17:19.245884 2026] [security2:error] [pid 971102:tid 971313] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxY3-cL08BTTQixEnpydQAAAE8"]
[Thu Sep 17 15:17:19.350970 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/transactional/.env"] [unique_id "aqxY3-cL08BTTQixEnpydwAAACY"]
[Thu Sep 17 15:17:19.405334 2026] [security2:error] [pid 971102:tid 971301] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxY3-cL08BTTQixEnpyhAAAAEM"]
[Thu Sep 17 15:17:19.500069 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:56448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3-cL08BTTQixEnpyiwAAAEo"]
[Thu Sep 17 15:17:19.522889 2026] [security2:error] [pid 971102:tid 971279] [client 3.82.141.143:28768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyegAAAC0"]
[Thu Sep 17 15:17:19.526037 2026] [security2:error] [pid 971102:tid 971287] [client 3.82.141.143:28736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfAAAADU"]
[Thu Sep 17 15:17:19.527339 2026] [security2:error] [pid 971102:tid 971317] [client 3.82.141.143:28724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfgAAAFM"]
[Thu Sep 17 15:17:19.533981 2026] [security2:error] [pid 971102:tid 971349] [client 3.82.141.143:28716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpygAAAAHM"]
[Thu Sep 17 15:17:19.534244 2026] [security2:error] [pid 971102:tid 971310] [client 3.82.141.143:28696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfQAAAEw"]
[Thu Sep 17 15:17:19.537031 2026] [security2:error] [pid 971102:tid 971316] [client 3.82.141.143:28732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfwAAAFI"]
[Thu Sep 17 15:17:19.538425 2026] [security2:error] [pid 971102:tid 971242] [client 3.82.141.143:28704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyeQAAAAg"]
[Thu Sep 17 15:17:19.540711 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY3-cL08BTTQixEnpykQAAABM"]
[Thu Sep 17 15:17:19.549337 2026] [security2:error] [pid 971102:tid 971295] [client 3.82.141.143:28714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpygQAAAD0"]
[Thu Sep 17 15:17:19.549380 2026] [security2:error] [pid 971102:tid 971329] [client 3.82.141.143:28758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyggAAAF8"]
[Thu Sep 17 15:17:19.553047 2026] [security2:error] [pid 971102:tid 971347] [client 3.82.141.143:28684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyeAAAAHE"]
[Thu Sep 17 15:17:19.558877 2026] [security2:error] [pid 971102:tid 971355] [client 3.82.141.143:28738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpygwAAAHk"]
[Thu Sep 17 15:17:19.563943 2026] [security2:error] [pid 971102:tid 971241] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxY3-cL08BTTQixEnpylQAAAAc"]
[Thu Sep 17 15:17:19.566521 2026] [security2:error] [pid 971102:tid 971339] [client 3.82.141.143:28710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyewAAAGk"]
[Thu Sep 17 15:17:19.581710 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bulk/.env"] [unique_id "aqxY3-cL08BTTQixEnpylgAAAH4"]
[Thu Sep 17 15:17:19.670164 2026] [security2:error] [pid 971102:tid 971289] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env"] [unique_id "aqxY3-cL08BTTQixEnpynAAAADc"]
[Thu Sep 17 15:17:19.726111 2026] [security2:error] [pid 971102:tid 971257] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxY3-cL08BTTQixEnpynwAAABc"]
[Thu Sep 17 15:17:19.812573 2026] [security2:error] [pid 971102:tid 971331] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxY3-cL08BTTQixEnpyoAAAAGE"]
[Thu Sep 17 15:17:19.834738 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:55431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxY3-cL08BTTQixEnpyowAAABY"], referer: binance.com
[Thu Sep 17 15:17:19.889099 2026] [security2:error] [pid 971102:tid 971320] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxY3-cL08BTTQixEnpypgAAAFY"]
[Thu Sep 17 15:17:19.928650 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY3-cL08BTTQixEnpypwAAAAM"]
[Thu Sep 17 15:17:19.960988 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpypAAAAAA"]
[Thu Sep 17 15:17:19.974183 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env"] [unique_id "aqxY3-cL08BTTQixEnpyqgAAAHs"]
[Thu Sep 17 15:17:20.050359 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/azure/.env"] [unique_id "aqxY4OcL08BTTQixEnpyrAAAAHo"]
[Thu Sep 17 15:17:20.052490 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxY4OcL08BTTQixEnpyrQAAADY"]
[Thu Sep 17 15:17:20.211918 2026] [security2:error] [pid 971102:tid 971302] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxY4OcL08BTTQixEnpytAAAAEQ"]
[Thu Sep 17 15:17:20.280817 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gcp/.env"] [unique_id "aqxY4OcL08BTTQixEnpyvQAAAGM"]
[Thu Sep 17 15:17:20.304164 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpysQAAAEU"]
[Thu Sep 17 15:17:20.345784 2026] [security2:error] [pid 971102:tid 971325] [client 34.97.30.29:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY4OcL08BTTQixEnpywAAAAFs"]
[Thu Sep 17 15:17:20.369265 2026] [security2:error] [pid 971102:tid 971338] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxY4OcL08BTTQixEnpywQAAAGg"]
[Thu Sep 17 15:17:20.412375 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpyvgAAADA"]
[Thu Sep 17 15:17:20.511173 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cloud/.env"] [unique_id "aqxY4OcL08BTTQixEnpyxgAAAC0"]
[Thu Sep 17 15:17:20.551714 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxY4OcL08BTTQixEnpyxwAAADU"]
[Thu Sep 17 15:17:20.705556 2026] [security2:error] [pid 971102:tid 971268] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxY4OcL08BTTQixEnpyzwAAACI"]
[Thu Sep 17 15:17:20.725337 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpyzQAAABM"]
[Thu Sep 17 15:17:20.728643 2026] [security2:error] [pid 971102:tid 971310] [client 34.97.30.29:59874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxY4OcL08BTTQixEnpy0QAAAEw"]
[Thu Sep 17 15:17:20.740878 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/infrastructure/.env"] [unique_id "aqxY4OcL08BTTQixEnpy0gAAAAc"]
[Thu Sep 17 15:17:20.768874 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpyzgAAADg"]
[Thu Sep 17 15:17:20.870260 2026] [security2:error] [pid 971102:tid 971263] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxY4OcL08BTTQixEnpy1wAAAB0"]
[Thu Sep 17 15:17:20.971762 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/docker/.env"] [unique_id "aqxY4OcL08BTTQixEnpy4QAAAHQ"]
[Thu Sep 17 15:17:21.012698 2026] [security2:error] [pid 971102:tid 971319] [client 92.99.250.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpy1QAAAFU"]
[Thu Sep 17 15:17:21.034284 2026] [security2:error] [pid 971102:tid 971260] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxY4ecL08BTTQixEnpy5QAAABo"]
[Thu Sep 17 15:17:21.043840 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpy2wAAAC8"]
[Thu Sep 17 15:17:21.086073 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpy3wAAAAs"]
[Thu Sep 17 15:17:21.149405 2026] [security2:error] [pid 971102:tid 971334] [client 34.97.30.29:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php.old"] [unique_id "aqxY4ecL08BTTQixEnpy6gAAAGQ"]
[Thu Sep 17 15:17:21.200861 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/k8s/.env"] [unique_id "aqxY4ecL08BTTQixEnpy7gAAAD4"]
[Thu Sep 17 15:17:21.382188 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpy9AAAAAM"]
[Thu Sep 17 15:17:21.430856 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/kubernetes/.env"] [unique_id "aqxY4ecL08BTTQixEnpzAAAAAE4"]
[Thu Sep 17 15:17:21.436851 2026] [security2:error] [pid 971102:tid 971288] [client 162.241.226.11:10278] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxY4ecL08BTTQixEnpy_AAAADY"]
[Thu Sep 17 15:17:21.442425 2026] [security2:error] [pid 971102:tid 971249] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpy9gAAAA8"]
[Thu Sep 17 15:17:21.559979 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php~"] [unique_id "aqxY4ecL08BTTQixEnpzCQAAAEQ"]
[Thu Sep 17 15:17:21.661848 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/terraform/.env"] [unique_id "aqxY4ecL08BTTQixEnpzEAAAAEE"]
[Thu Sep 17 15:17:21.742503 2026] [security2:error] [pid 971102:tid 971286] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpzDwAAADQ"]
[Thu Sep 17 15:17:21.794511 2026] [security2:error] [pid 971102:tid 971321] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpzEQAAAFc"]
[Thu Sep 17 15:17:21.898082 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ansible/.env"] [unique_id "aqxY4ecL08BTTQixEnpzGAAAAD0"]
[Thu Sep 17 15:17:21.898559 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.bak"] [unique_id "aqxY4ecL08BTTQixEnpzGQAAAF8"]
[Thu Sep 17 15:17:22.000832 2026] [security2:error] [pid 971102:tid 971272] [client 34.97.30.29:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/info.php.bak"] [unique_id "aqxY4ecL08BTTQixEnpzIwAAACY"]
[Thu Sep 17 15:17:22.003714 2026] [security2:error] [pid 971102:tid 971291] [client 172.239.147.162:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxY4ucL08BTTQixEnpzJQAAADk"], referer: binance.com
[Thu Sep 17 15:17:22.020371 2026] [security2:error] [pid 971102:tid 971276] [client 103.131.71.43:52719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpzGwAAACo"]
[Thu Sep 17 15:17:22.049611 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.backup"] [unique_id "aqxY4ucL08BTTQixEnpzJgAAADg"]
[Thu Sep 17 15:17:22.130372 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.git/.env"] [unique_id "aqxY4ucL08BTTQixEnpzLAAAAHI"]
[Thu Sep 17 15:17:22.208867 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzKQAAADE"]
[Thu Sep 17 15:17:22.257575 2026] [security2:error] [pid 971102:tid 971274] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxY4ucL08BTTQixEnpzMQAAACg"]
[Thu Sep 17 15:17:22.366320 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ci/.env"] [unique_id "aqxY4ucL08BTTQixEnpzNAAAAF4"]
[Thu Sep 17 15:17:22.373754 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.bak"] [unique_id "aqxY4ucL08BTTQixEnpzNQAAAAs"]
[Thu Sep 17 15:17:22.413444 2026] [security2:error] [pid 971102:tid 971246] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxY4ucL08BTTQixEnpzNwAAAAw"]
[Thu Sep 17 15:17:22.433306 2026] [security2:error] [pid 971102:tid 971244] [client 92.99.250.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzJwAAAAo"]
[Thu Sep 17 15:17:22.444458 2026] [security2:error] [pid 971102:tid 971265] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzMwAAAB8"]
[Thu Sep 17 15:17:22.480139 2026] [security2:error] [pid 971102:tid 971331] [client 34.97.30.29:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php.save"] [unique_id "aqxY4ucL08BTTQixEnpzPAAAAGE"]
[Thu Sep 17 15:17:22.544088 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.backup"] [unique_id "aqxY4ucL08BTTQixEnpzPQAAAGs"]
[Thu Sep 17 15:17:22.570845 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxY4ucL08BTTQixEnpzPgAAACQ"]
[Thu Sep 17 15:17:22.600266 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cd/.env"] [unique_id "aqxY4ucL08BTTQixEnpzQAAAAAA"]
[Thu Sep 17 15:17:22.627471 2026] [security2:error] [pid 971102:tid 971258] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.old"] [unique_id "aqxY4ucL08BTTQixEnpzRAAAABg"]
[Thu Sep 17 15:17:22.728840 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxY4ucL08BTTQixEnpzSAAAADY"]
[Thu Sep 17 15:17:22.828684 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzSQAAAE4"]
[Thu Sep 17 15:17:22.830951 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/jenkins/.env"] [unique_id "aqxY4ucL08BTTQixEnpzTQAAAGM"]
[Thu Sep 17 15:17:22.902960 2026] [security2:error] [pid 971102:tid 971302] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxY4ucL08BTTQixEnpzTwAAAEQ"]
[Thu Sep 17 15:17:22.917714 2026] [security2:error] [pid 971102:tid 971261] [client 34.97.30.29:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxY4ucL08BTTQixEnpzUQAAABs"]
[Thu Sep 17 15:17:22.933632 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzTgAAACk"]
[Thu Sep 17 15:17:22.994083 2026] [security2:error] [pid 971102:tid 971262] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.old"] [unique_id "aqxY4ucL08BTTQixEnpzVQAAABw"]
[Thu Sep 17 15:17:23.060953 2026] [security2:error] [pid 971102:tid 971352] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxY4-cL08BTTQixEnpzVwAAAHY"]
[Thu Sep 17 15:17:23.060953 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gitlab/.env"] [unique_id "aqxY4-cL08BTTQixEnpzWAAAAGg"]
[Thu Sep 17 15:17:23.225450 2026] [security2:error] [pid 971102:tid 971279] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxY4-cL08BTTQixEnpzXwAAAC0"]
[Thu Sep 17 15:17:23.256806 2026] [security2:error] [pid 971102:tid 971294] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzXQAAADw"]
[Thu Sep 17 15:17:23.302992 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/github/.env"] [unique_id "aqxY4-cL08BTTQixEnpzYwAAADU"]
[Thu Sep 17 15:17:23.351197 2026] [security2:error] [pid 971102:tid 971273] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzYAAAACc"]
[Thu Sep 17 15:17:23.381832 2026] [security2:error] [pid 971102:tid 971323] [client 34.97.30.29:59928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxY4-cL08BTTQixEnpzZwAAAFk"]
[Thu Sep 17 15:17:23.382765 2026] [security2:error] [pid 971102:tid 971321] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxY4-cL08BTTQixEnpzZgAAAFc"]
[Thu Sep 17 15:17:23.532710 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/actions/.env"] [unique_id "aqxY4-cL08BTTQixEnpzcQAAADg"]
[Thu Sep 17 15:17:23.536720 2026] [security2:error] [pid 971102:tid 971316] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxY4-cL08BTTQixEnpzcgAAAFI"]
[Thu Sep 17 15:17:23.578770 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzbAAAAF8"]
[Thu Sep 17 15:17:23.648359 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzcwAAAHI"]
[Thu Sep 17 15:17:23.657677 2026] [security2:error] [pid 971102:tid 971250] [client 185.55.149.49:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzdwAAABA"]
[Thu Sep 17 15:17:23.657784 2026] [security2:error] [pid 971102:tid 971250] [client 185.55.149.49:53594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzdwAAABA"]
[Thu Sep 17 15:17:23.678544 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzegAAAAg"]
[Thu Sep 17 15:17:23.678651 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:59230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzegAAAAg"]
[Thu Sep 17 15:17:23.692083 2026] [security2:error] [pid 971102:tid 971238] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxY4-cL08BTTQixEnpzewAAAAQ"]
[Thu Sep 17 15:17:23.766436 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/circleci/.env"] [unique_id "aqxY4-cL08BTTQixEnpzgAAAABE"]
[Thu Sep 17 15:17:23.850576 2026] [security2:error] [pid 971102:tid 971296] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxY4-cL08BTTQixEnpzhAAAAD4"]
[Thu Sep 17 15:17:23.868360 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxY4-cL08BTTQixEnpzhgAAAAs"]
[Thu Sep 17 15:17:23.891217 2026] [security2:error] [pid 971102:tid 971244] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzgQAAAAo"]
[Thu Sep 17 15:17:23.944845 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxY4-cL08BTTQixEnpziAAAABY"], referer: binance.com
[Thu Sep 17 15:17:23.983486 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzhwAAAFY"]
[Thu Sep 17 15:17:23.997382 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/travis/.env"] [unique_id "aqxY4-cL08BTTQixEnpziwAAAGs"]
[Thu Sep 17 15:17:24.007462 2026] [security2:error] [pid 971102:tid 971322] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxY5OcL08BTTQixEnpzjAAAAFg"]
[Thu Sep 17 15:17:24.161513 2026] [security2:error] [pid 971102:tid 971240] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxY5OcL08BTTQixEnpzlgAAAAY"]
[Thu Sep 17 15:17:24.171973 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzkQAAACA"]
[Thu Sep 17 15:17:24.227530 2026] [security2:error] [pid 971102:tid 971277] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/buildkite/.env"] [unique_id "aqxY5OcL08BTTQixEnpznQAAACs"]
[Thu Sep 17 15:17:24.279434 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzmwAAAEY"]
[Thu Sep 17 15:17:24.316273 2026] [security2:error] [pid 971102:tid 971275] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxY5OcL08BTTQixEnpzogAAACk"]
[Thu Sep 17 15:17:24.325774 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:57008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxY5OcL08BTTQixEnpzowAAAGw"]
[Thu Sep 17 15:17:24.438954 2026] [security2:error] [pid 971102:tid 971261] [client 92.99.250.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzoQAAABs"]
[Thu Sep 17 15:17:24.458445 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mysql/.env"] [unique_id "aqxY5OcL08BTTQixEnpzrAAAAHc"]
[Thu Sep 17 15:17:24.468517 2026] [security2:error] [pid 971102:tid 971302] [client 172.239.147.162:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxY5OcL08BTTQixEnpzrQAAAEQ"], referer: binance.com
[Thu Sep 17 15:17:24.469840 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxY5OcL08BTTQixEnpzrgAAADw"]
[Thu Sep 17 15:17:24.504242 2026] [security2:error] [pid 971102:tid 971280] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzqwAAAC4"]
[Thu Sep 17 15:17:24.636258 2026] [security2:error] [pid 971102:tid 971355] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxY5OcL08BTTQixEnpzuAAAAHk"]
[Thu Sep 17 15:17:24.688696 2026] [security2:error] [pid 971102:tid 971286] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpztgAAADQ"]
[Thu Sep 17 15:17:24.696139 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/postgres/.env"] [unique_id "aqxY5OcL08BTTQixEnpzuQAAAHg"]
[Thu Sep 17 15:17:24.793831 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxY5OcL08BTTQixEnpzvgAAAHI"]
[Thu Sep 17 15:17:24.805460 2026] [security2:error] [pid 971102:tid 971310] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxY5OcL08BTTQixEnpzvwAAAEw"]
[Thu Sep 17 15:17:24.871481 2026] [security2:error] [pid 971102:tid 971251] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzvQAAABE"]
[Thu Sep 17 15:17:24.937601 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mongodb/.env"] [unique_id "aqxY5OcL08BTTQixEnpzxQAAAG4"]
[Thu Sep 17 15:17:24.965328 2026] [security2:error] [pid 971102:tid 971322] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxY5OcL08BTTQixEnpzxwAAAFg"]
[Thu Sep 17 15:17:25.103151 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzyQAAAGs"]
[Thu Sep 17 15:17:25.126018 2026] [security2:error] [pid 971102:tid 971278] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxY5ecL08BTTQixEnpz0gAAACw"]
[Thu Sep 17 15:17:25.168850 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/redis/.env"] [unique_id "aqxY5ecL08BTTQixEnpz1AAAAB4"]
[Thu Sep 17 15:17:25.228161 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/www/phpinfo.php"] [unique_id "aqxY5ecL08BTTQixEnpz2AAAABg"]
[Thu Sep 17 15:17:25.243402 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz0wAAACA"]
[Thu Sep 17 15:17:25.284130 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxY5ecL08BTTQixEnpz2gAAAH8"]
[Thu Sep 17 15:17:25.306911 2026] [security2:error] [pid 971102:tid 971246] [client 154.190.208.131:41661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnpz3QAAAAw"]
[Thu Sep 17 15:17:25.310561 2026] [security2:error] [pid 971102:tid 971246] [client 154.190.208.131:41661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnpz3QAAAAw"]
[Thu Sep 17 15:17:25.319779 2026] [security2:error] [pid 971102:tid 971245] [client 24.162.197.107:37225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz1wAACwg"]
[Thu Sep 17 15:17:25.398364 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/elasticsearch/.env"] [unique_id "aqxY5ecL08BTTQixEnpz4AAAABs"]
[Thu Sep 17 15:17:25.449949 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxY5ecL08BTTQixEnpz5wAAADU"]
[Thu Sep 17 15:17:25.464611 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz3gAAAFs"]
[Thu Sep 17 15:17:25.578138 2026] [security2:error] [pid 971102:tid 971273] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz6gAAACc"]
[Thu Sep 17 15:17:25.605129 2026] [security2:error] [pid 971102:tid 971253] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxY5ecL08BTTQixEnpz7wAAABM"]
[Thu Sep 17 15:17:25.631056 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/rabbitmq/.env"] [unique_id "aqxY5ecL08BTTQixEnpz8QAAAHQ"]
[Thu Sep 17 15:17:25.648607 2026] [security2:error] [pid 971102:tid 971303] [client 34.97.30.29:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxY5ecL08BTTQixEnpz8wAAAEU"]
[Thu Sep 17 15:17:25.762839 2026] [security2:error] [pid 971102:tid 971241] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxY5ecL08BTTQixEnpz-wAAAAc"]
[Thu Sep 17 15:17:25.827418 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz9gAAACY"]
[Thu Sep 17 15:17:25.861856 2026] [security2:error] [pid 971102:tid 971268] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/kafka/.env"] [unique_id "aqxY5ecL08BTTQixEnp0AQAAACI"]
[Thu Sep 17 15:17:25.875137 2026] [security2:error] [pid 971102:tid 971355] [client 114.198.138.124:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnp0AwAAAHk"]
[Thu Sep 17 15:17:25.875301 2026] [security2:error] [pid 971102:tid 971355] [client 114.198.138.124:64865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnp0AwAAAHk"]
[Thu Sep 17 15:17:25.919510 2026] [security2:error] [pid 971102:tid 971256] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxY5ecL08BTTQixEnp0BwAAABY"]
[Thu Sep 17 15:17:25.980918 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnp0AAAAABI"]
[Thu Sep 17 15:17:25.994918 2026] [security2:error] [pid 971102:tid 971348] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz_AAAckI"]
[Thu Sep 17 15:17:26.075545 2026] [security2:error] [pid 971102:tid 971237] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxY5ucL08BTTQixEnp0EgAAAAM"]
[Thu Sep 17 15:17:26.098011 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/queue/.env"] [unique_id "aqxY5ucL08BTTQixEnp0FgAAACA"]
[Thu Sep 17 15:17:26.111522 2026] [security2:error] [pid 971102:tid 971357] [client 34.97.30.29:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxY5ucL08BTTQixEnp0FwAAAHs"]
[Thu Sep 17 15:17:26.170824 2026] [security2:error] [pid 971102:tid 971341] [client 47.79.4.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0DgAAAGs"]
[Thu Sep 17 15:17:26.224081 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0GAAAAEM"]
[Thu Sep 17 15:17:26.231376 2026] [security2:error] [pid 971102:tid 971246] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxY5ucL08BTTQixEnp0HwAAAAw"]
[Thu Sep 17 15:17:26.294118 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0HQAAACk"]
[Thu Sep 17 15:17:26.328707 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/worker/.env"] [unique_id "aqxY5ucL08BTTQixEnp0IAAAABw"]
[Thu Sep 17 15:17:26.377060 2026] [security2:error] [pid 971102:tid 971360] [client 172.239.147.162:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxY5ucL08BTTQixEnp0JQAAAH4"], referer: binance.com
[Thu Sep 17 15:17:26.389351 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxY5ucL08BTTQixEnp0JwAAADw"]
[Thu Sep 17 15:17:26.468973 2026] [security2:error] [pid 971102:tid 971350] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.swp"] [unique_id "aqxY5ucL08BTTQixEnp0LAAAAHQ"]
[Thu Sep 17 15:17:26.551236 2026] [security2:error] [pid 971102:tid 971356] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxY5ucL08BTTQixEnp0NAAAAHo"]
[Thu Sep 17 15:17:26.552733 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:57052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/site/phpinfo.php"] [unique_id "aqxY5ucL08BTTQixEnp0NgAAAHc"]
[Thu Sep 17 15:17:26.558065 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/job/.env"] [unique_id "aqxY5ucL08BTTQixEnp0NwAAABA"]
[Thu Sep 17 15:17:26.562009 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0KwAAABM"]
[Thu Sep 17 15:17:26.578763 2026] [security2:error] [pid 971102:tid 971321] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0JgAAVyM"]
[Thu Sep 17 15:17:26.620041 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env~"] [unique_id "aqxY5ucL08BTTQixEnp0OAAAADo"]
[Thu Sep 17 15:17:26.661090 2026] [security2:error] [pid 971102:tid 971254] [client 202.46.62.14:37426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0MgAAFDU"]
[Thu Sep 17 15:17:26.715833 2026] [security2:error] [pid 971102:tid 971347] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxY5ucL08BTTQixEnp0OwAAAHE"]
[Thu Sep 17 15:17:26.787770 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxY5ucL08BTTQixEnp0QAAAAHY"]
[Thu Sep 17 15:17:26.871731 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0PgAAAEg"]
[Thu Sep 17 15:17:26.878218 2026] [security2:error] [pid 971102:tid 971355] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxY5ucL08BTTQixEnp0RAAAAHk"]
[Thu Sep 17 15:17:26.986381 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxY5ucL08BTTQixEnp0SQAAABE"]
[Thu Sep 17 15:17:27.018028 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/qa/.env"] [unique_id "aqxY5-cL08BTTQixEnp0TAAAAGk"]
[Thu Sep 17 15:17:27.034409 2026] [security2:error] [pid 971102:tid 971283] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxY5-cL08BTTQixEnp0TQAAADE"]
[Thu Sep 17 15:17:27.039246 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0RQAAAB0"]
[Thu Sep 17 15:17:27.071521 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.swp"] [unique_id "aqxY5-cL08BTTQixEnp0TwAAACw"]
[Thu Sep 17 15:17:27.089097 2026] [security2:error] [pid 971102:tid 971346] [client 172.239.147.162:52073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxY5-cL08BTTQixEnp0UAAAAHA"], referer: binance.com
[Thu Sep 17 15:17:27.090495 2026] [security2:error] [pid 971102:tid 971235] [client 24.162.197.107:45317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0SwAAAQ0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821154343&hideanons=1&limit=500&target=The_Lord_Of_Dwarves&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:17:27.179915 2026] [security2:error] [pid 971102:tid 971285] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0SAAAMy8"]
[Thu Sep 17 15:17:27.187837 2026] [security2:error] [pid 971102:tid 971312] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxY5-cL08BTTQixEnp0UwAAAE4"]
[Thu Sep 17 15:17:27.226570 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env~"] [unique_id "aqxY5-cL08BTTQixEnp0VgAAAEk"]
[Thu Sep 17 15:17:27.249742 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/preview/.env"] [unique_id "aqxY5-cL08BTTQixEnp0WgAAAFg"]
[Thu Sep 17 15:17:27.344981 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxY5-cL08BTTQixEnp0XAAAADY"]
[Thu Sep 17 15:17:27.346045 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0WwAAAFA"]
[Thu Sep 17 15:17:27.414114 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxY5-cL08BTTQixEnp0YAAAAAs"]
[Thu Sep 17 15:17:27.481488 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/beta/.env"] [unique_id "aqxY5-cL08BTTQixEnp0YgAAADs"]
[Thu Sep 17 15:17:27.501009 2026] [security2:error] [pid 971102:tid 971327] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxY5-cL08BTTQixEnp0YwAAAF0"]
[Thu Sep 17 15:17:27.539546 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0YQAAAGE"]
[Thu Sep 17 15:17:27.637488 2026] [security2:error] [pid 971102:tid 971315] [client 186.105.232.15:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5-cL08BTTQixEnp0bQAAAFE"]
[Thu Sep 17 15:17:27.637641 2026] [security2:error] [pid 971102:tid 971315] [client 186.105.232.15:54622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5-cL08BTTQixEnp0bQAAAFE"]
[Thu Sep 17 15:17:27.658451 2026] [security2:error] [pid 971102:tid 971305] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxY5-cL08BTTQixEnp0cwAAAEc"]
[Thu Sep 17 15:17:27.712496 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/uat/.env"] [unique_id "aqxY5-cL08BTTQixEnp0dgAAABM"]
[Thu Sep 17 15:17:27.753467 2026] [security2:error] [pid 971102:tid 971284] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0aAAAADI"]
[Thu Sep 17 15:17:27.814251 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxY5-cL08BTTQixEnp0ewAAAGY"]
[Thu Sep 17 15:17:27.836572 2026] [security2:error] [pid 971102:tid 971274] [client 34.97.30.29:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxY5-cL08BTTQixEnp0fAAAACg"]
[Thu Sep 17 15:17:27.881519 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0egAAADo"]
[Thu Sep 17 15:17:27.944052 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/stage/.env"] [unique_id "aqxY5-cL08BTTQixEnp0gAAAAD4"]
[Thu Sep 17 15:17:27.962172 2026] [security2:error] [pid 971102:tid 971239] [client 172.239.147.162:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxY5-cL08BTTQixEnp0ggAAAAU"], referer: binance.com
[Thu Sep 17 15:17:27.971098 2026] [security2:error] [pid 971102:tid 971355] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxY5-cL08BTTQixEnp0gwAAAHk"]
[Thu Sep 17 15:17:28.041317 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0gQAAACY"]
[Thu Sep 17 15:17:28.127505 2026] [security2:error] [pid 971102:tid 971310] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxY6OcL08BTTQixEnp0jgAAAEw"]
[Thu Sep 17 15:17:28.176344 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/development/.env"] [unique_id "aqxY6OcL08BTTQixEnp0kAAAAB4"]
[Thu Sep 17 15:17:28.186259 2026] [security2:error] [pid 971102:tid 971249] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0iwAAAA8"]
[Thu Sep 17 15:17:28.283164 2026] [security2:error] [pid 971102:tid 971341] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxY6OcL08BTTQixEnp0kwAAAGs"]
[Thu Sep 17 15:17:28.306903 2026] [security2:error] [pid 971102:tid 971235] [client 34.97.30.29:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/core/phpinfo.php"] [unique_id "aqxY6OcL08BTTQixEnp0lgAAAAE"]
[Thu Sep 17 15:17:28.321192 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:56412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0kQAAACU"]
[Thu Sep 17 15:17:28.407383 2026] [security2:error] [pid 971102:tid 971340] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxY6OcL08BTTQixEnp0mgAAAGo"]
[Thu Sep 17 15:17:28.443179 2026] [security2:error] [pid 971102:tid 971269] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxY6OcL08BTTQixEnp0mwAAACM"]
[Thu Sep 17 15:17:28.462354 2026] [security2:error] [pid 971102:tid 971307] [client 172.239.147.162:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-view-config-data.php"] [unique_id "aqxY6OcL08BTTQixEnp0nQAAAEk"], referer: binance.com
[Thu Sep 17 15:17:28.509031 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0mQAAAFA"]
[Thu Sep 17 15:17:28.603378 2026] [security2:error] [pid 971102:tid 971359] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0pQAAAH0"]
[Thu Sep 17 15:17:28.607355 2026] [security2:error] [pid 971102:tid 971281] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxY6OcL08BTTQixEnp0qAAAAC8"]
[Thu Sep 17 15:17:28.612790 2026] [security2:error] [pid 971102:tid 971312] [client 202.46.62.118:2212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0oAAAAE4"]
[Thu Sep 17 15:17:28.637646 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/config/app/.env"] [unique_id "aqxY6OcL08BTTQixEnp0qwAAAEc"]
[Thu Sep 17 15:17:28.705640 2026] [security2:error] [pid 971102:tid 971331] [client 34.97.30.29:57084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxY6OcL08BTTQixEnp0rQAAAGE"]
[Thu Sep 17 15:17:28.764415 2026] [security2:error] [pid 971102:tid 971286] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxY6OcL08BTTQixEnp0rwAAADQ"]
[Thu Sep 17 15:17:28.774156 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:56458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0rAAAABA"]
[Thu Sep 17 15:17:28.882975 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.218.131:47948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxY6OcL08BTTQixEnp0twAAAAQ"]
[Thu Sep 17 15:17:28.917354 2026] [security2:error] [pid 971102:tid 971274] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxY6OcL08BTTQixEnp0ugAAACg"]
[Thu Sep 17 15:17:28.938201 2026] [security2:error] [pid 971102:tid 971287] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0tgAAADU"]
[Thu Sep 17 15:17:29.076529 2026] [security2:error] [pid 971102:tid 971259] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxY6ecL08BTTQixEnp0xAAAABk"]
[Thu Sep 17 15:17:29.105875 2026] [security2:error] [pid 971102:tid 971309] [client 79.177.151.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0wQAAAEs"], referer: https://languageandsociety.co.il/wp-content/uploads/2022/12/conf15_short_3-7-2016.pdf?utm_source=chatgpt.com
[Thu Sep 17 15:17:29.122391 2026] [security2:error] [pid 971102:tid 971265] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/app/.env"] [unique_id "aqxY6ecL08BTTQixEnp0xwAAAB8"]
[Thu Sep 17 15:17:29.153439 2026] [security2:error] [pid 971102:tid 971342] [client 156.192.234.52:51350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY6ecL08BTTQixEnp0ywAAAGw"]
[Thu Sep 17 15:17:29.154836 2026] [security2:error] [pid 971102:tid 971342] [client 156.192.234.52:51350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY6ecL08BTTQixEnp0ywAAAGw"]
[Thu Sep 17 15:17:29.229323 2026] [security2:error] [pid 971102:tid 971255] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxY6ecL08BTTQixEnp0zgAAABU"]
[Thu Sep 17 15:17:29.247237 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6ecL08BTTQixEnp0ygAAAEg"]
[Thu Sep 17 15:17:29.279142 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/apps/.env"] [unique_id "aqxY6ecL08BTTQixEnp00AAAAAI"]
[Thu Sep 17 15:17:29.389458 2026] [security2:error] [pid 971102:tid 971243] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxY6ecL08BTTQixEnp01AAAAAk"]
[Thu Sep 17 15:17:29.437483 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/.env"] [unique_id "aqxY6ecL08BTTQixEnp03gAAAAE"]
[Thu Sep 17 15:17:29.468004 2026] [access_compat:error] [pid 971102:tid 971252] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/jixo-5-mask-parade-collectors-edition
[Thu Sep 17 15:17:29.545113 2026] [core:error] [pid 971102:tid 971348] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:17:29.545136 2026] [core:error] [pid 971102:tid 971348] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:17:29.546963 2026] [security2:error] [pid 971102:tid 971327] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxY6ecL08BTTQixEnp06wAAAF0"]
[Thu Sep 17 15:17:29.564702 2026] [security2:error] [pid 971102:tid 971251] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6ecL08BTTQixEnp03wAAABE"]
[Thu Sep 17 15:17:29.580626 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.218.131:50086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/info.php"] [unique_id "aqxY6ecL08BTTQixEnp07QAAAA8"]
[Thu Sep 17 15:17:29.605372 2026] [security2:error] [pid 971102:tid 971335] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/web/.env"] [unique_id "aqxY6ecL08BTTQixEnp07gAAAGU"]
[Thu Sep 17 15:17:29.702360 2026] [security2:error] [pid 971102:tid 971305] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxY6ecL08BTTQixEnp08QAAAEc"]
[Thu Sep 17 15:17:29.718785 2026] [security2:error] [pid 971102:tid 971313] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY6ecL08BTTQixEnp06QAAT10"]
[Thu Sep 17 15:17:29.758479 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/site/.env"] [unique_id "aqxY6ecL08BTTQixEnp09AAAAFI"]
[Thu Sep 17 15:17:29.779302 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/app/.env"] [unique_id "aqxY6ecL08BTTQixEnp09QAAAFw"]
[Thu Sep 17 15:17:29.856401 2026] [security2:error] [pid 971102:tid 971282] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxY6ecL08BTTQixEnp0_AAAADA"]
[Thu Sep 17 15:17:29.913846 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/public/.env"] [unique_id "aqxY6ecL08BTTQixEnp0_wAAABo"]
[Thu Sep 17 15:17:29.940764 2026] [security2:error] [pid 971102:tid 971238] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/apps/.env"] [unique_id "aqxY6ecL08BTTQixEnp1AAAAAAQ"]
[Thu Sep 17 15:17:30.009307 2026] [security2:error] [pid 971102:tid 971350] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxY6ucL08BTTQixEnp1CAAAAHQ"]
[Thu Sep 17 15:17:30.095930 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/.env"] [unique_id "aqxY6ucL08BTTQixEnp1EAAAAHs"]
[Thu Sep 17 15:17:30.164369 2026] [security2:error] [pid 971102:tid 971292] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxY6ucL08BTTQixEnp1EwAAADo"]
[Thu Sep 17 15:17:30.208292 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6ucL08BTTQixEnp1DwAAAAg"]
[Thu Sep 17 15:17:30.272102 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.218.131:39532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/php.php"] [unique_id "aqxY6ucL08BTTQixEnp1FwAAAFM"]
[Thu Sep 17 15:17:30.272251 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/web/.env"] [unique_id "aqxY6ucL08BTTQixEnp1FgAAAAY"]
[Thu Sep 17 15:17:30.323194 2026] [security2:error] [pid 971102:tid 971297] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxY6ucL08BTTQixEnp1GwAAAD8"]
[Thu Sep 17 15:17:30.349358 2026] [security2:error] [pid 971102:tid 971342] [client 172.239.147.162:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxY6ucL08BTTQixEnp1HAAAAGw"], referer: binance.com
[Thu Sep 17 15:17:30.396042 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/backend/.env"] [unique_id "aqxY6ucL08BTTQixEnp1IQAAAB4"]
[Thu Sep 17 15:17:30.400121 2026] [authz_core:error] [pid 971102:tid 971267] [client 5.189.145.112:51627] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:30.427867 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/site/.env"] [unique_id "aqxY6ucL08BTTQixEnp1IgAAAEU"]
[Thu Sep 17 15:17:30.450335 2026] [security2:error] [pid 971102:tid 971334] [client 172.239.147.162:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxY6ucL08BTTQixEnp1IwAAAGQ"], referer: binance.com
[Thu Sep 17 15:17:30.494095 2026] [security2:error] [pid 971102:tid 971328] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxY6ucL08BTTQixEnp1JwAAAF4"]
[Thu Sep 17 15:17:30.552034 2026] [security2:error] [pid 971102:tid 971257] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/server/.env"] [unique_id "aqxY6ucL08BTTQixEnp1KgAAABc"]
[Thu Sep 17 15:17:30.596275 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/public/.env"] [unique_id "aqxY6ucL08BTTQixEnp1LQAAACU"]
[Thu Sep 17 15:17:30.648907 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxY6ucL08BTTQixEnp1MAAAAHU"]
[Thu Sep 17 15:17:30.708801 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/frontend/.env"] [unique_id "aqxY6ucL08BTTQixEnp1MQAAAAA"]
[Thu Sep 17 15:17:30.812235 2026] [security2:error] [pid 971102:tid 971341] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxY6ucL08BTTQixEnp1NgAAAGs"]
[Thu Sep 17 15:17:30.861708 2026] [security2:error] [pid 971102:tid 971289] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/src/.env"] [unique_id "aqxY6ucL08BTTQixEnp1NwAAADc"]
[Thu Sep 17 15:17:30.962165 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.218.131:39546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/i.php"] [unique_id "aqxY6ucL08BTTQixEnp1PAAAAA8"]
[Thu Sep 17 15:17:30.971774 2026] [security2:error] [pid 971102:tid 971359] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxY6ucL08BTTQixEnp1PQAAAH0"]
[Thu Sep 17 15:17:31.000507 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6ucL08BTTQixEnp1OQAAAFE"]
[Thu Sep 17 15:17:31.013268 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/core/.env"] [unique_id "aqxY6-cL08BTTQixEnp1QAAAAGA"]
[Thu Sep 17 15:17:31.125406 2026] [security2:error] [pid 971102:tid 971260] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxY6-cL08BTTQixEnp1RQAAABo"]
[Thu Sep 17 15:17:31.168142 2026] [security2:error] [pid 971102:tid 971238] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/core/app/.env"] [unique_id "aqxY6-cL08BTTQixEnp1RgAAAAQ"]
[Thu Sep 17 15:17:31.185709 2026] [security2:error] [pid 971102:tid 971244] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/backend/.env"] [unique_id "aqxY6-cL08BTTQixEnp1SAAAAAo"]
[Thu Sep 17 15:17:31.279440 2026] [security2:error] [pid 971102:tid 971259] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxY6-cL08BTTQixEnp1TAAAABk"]
[Thu Sep 17 15:17:31.304434 2026] [security2:error] [pid 971102:tid 971350] [client 127.0.0.1:10178] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxY6-cL08BTTQixEnp1SwAAAHQ"]
[Thu Sep 17 15:17:31.304455 2026] [security2:error] [pid 971102:tid 971302] [client 74.7.175.161:48914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.comfortspecialist.info"] [uri "/robots.txt"] [unique_id "aqxY6-cL08BTTQixEnp1SgAARH4"]
[Thu Sep 17 15:17:31.329935 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/config/.env"] [unique_id "aqxY6-cL08BTTQixEnp1TQAAAHs"]
[Thu Sep 17 15:17:31.347096 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/server/.env"] [unique_id "aqxY6-cL08BTTQixEnp1TgAAAD4"]
[Thu Sep 17 15:17:31.433933 2026] [security2:error] [pid 971102:tid 971319] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxY6-cL08BTTQixEnp1UgAAAFU"]
[Thu Sep 17 15:17:31.489168 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/private/.env"] [unique_id "aqxY6-cL08BTTQixEnp1VgAAAAY"]
[Thu Sep 17 15:17:31.503967 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/frontend/.env"] [unique_id "aqxY6-cL08BTTQixEnp1VwAAAAU"]
[Thu Sep 17 15:17:31.588722 2026] [security2:error] [pid 971102:tid 971310] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxY6-cL08BTTQixEnp1XAAAAEw"]
[Thu Sep 17 15:17:31.643562 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/application/.env"] [unique_id "aqxY6-cL08BTTQixEnp1XgAAAAM"]
[Thu Sep 17 15:17:31.657776 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.218.131:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxY6-cL08BTTQixEnp1XwAAABU"]
[Thu Sep 17 15:17:31.659100 2026] [security2:error] [pid 971102:tid 971241] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/src/.env"] [unique_id "aqxY6-cL08BTTQixEnp1YAAAAAc"]
[Thu Sep 17 15:17:31.742305 2026] [security2:error] [pid 971102:tid 971267] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxY6-cL08BTTQixEnp1YwAAACE"]
[Thu Sep 17 15:17:31.797065 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/bootstrap/.env"] [unique_id "aqxY6-cL08BTTQixEnp1ZwAAAEU"]
[Thu Sep 17 15:17:31.816017 2026] [security2:error] [pid 971102:tid 971334] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/core/.env"] [unique_id "aqxY6-cL08BTTQixEnp1aAAAAGQ"]
[Thu Sep 17 15:17:31.897632 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxY6-cL08BTTQixEnp1agAAACU"]
[Thu Sep 17 15:17:31.966900 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/database/.env"] [unique_id "aqxY6-cL08BTTQixEnp1bgAAAB0"]
[Thu Sep 17 15:17:31.977554 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/core/app/.env"] [unique_id "aqxY6-cL08BTTQixEnp1cAAAAHI"]
[Thu Sep 17 15:17:32.155189 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/config/.env"] [unique_id "aqxY7OcL08BTTQixEnp1eQAAAGs"]
[Thu Sep 17 15:17:32.158847 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/storage/.env"] [unique_id "aqxY7OcL08BTTQixEnp1egAAAE4"]
[Thu Sep 17 15:17:32.321046 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/var/www/.env"] [unique_id "aqxY7OcL08BTTQixEnp1fAAAAEc"]
[Thu Sep 17 15:17:32.363582 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxY7OcL08BTTQixEnp1fQAAADw"]
[Thu Sep 17 15:17:32.365099 2026] [security2:error] [pid 971102:tid 971304] [client 34.154.67.31:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/info.php"] [unique_id "aqxY7OcL08BTTQixEnp1fwAAAEY"]
[Thu Sep 17 15:17:32.365651 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/private/.env"] [unique_id "aqxY7OcL08BTTQixEnp1fgAAAE8"]
[Thu Sep 17 15:17:32.429254 2026] [security2:error] [pid 971102:tid 971261] [client 172.239.147.162:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxY7OcL08BTTQixEnp1ggAAABs"], referer: binance.com
[Thu Sep 17 15:17:32.493375 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/var/www/html/.env"] [unique_id "aqxY7OcL08BTTQixEnp1hAAAAGA"]
[Thu Sep 17 15:17:32.536509 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/application/.env"] [unique_id "aqxY7OcL08BTTQixEnp1igAAACw"]
[Thu Sep 17 15:17:32.603958 2026] [security2:error] [pid 971102:tid 971315] [client 172.239.147.162:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxY7OcL08BTTQixEnp1iwAAAFE"], referer: binance.com
[Thu Sep 17 15:17:32.674267 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/current/.env"] [unique_id "aqxY7OcL08BTTQixEnp1jgAAAGY"]
[Thu Sep 17 15:17:32.723098 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/bootstrap/.env"] [unique_id "aqxY7OcL08BTTQixEnp1jwAAAG4"]
[Thu Sep 17 15:17:32.855704 2026] [security2:error] [pid 971102:tid 971279] [client 34.154.67.31:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/php.php"] [unique_id "aqxY7OcL08BTTQixEnp1kQAAAC0"]
[Thu Sep 17 15:17:32.877856 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/release/.env"] [unique_id "aqxY7OcL08BTTQixEnp1kgAAAD4"]
[Thu Sep 17 15:17:32.900922 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/database/.env"] [unique_id "aqxY7OcL08BTTQixEnp1kwAAAH4"]
[Thu Sep 17 15:17:33.047278 2026] [security2:error] [pid 971102:tid 971273] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/releases/.env"] [unique_id "aqxY7ecL08BTTQixEnp1mAAAACc"]
[Thu Sep 17 15:17:33.056215 2026] [security2:error] [pid 971102:tid 971302] [client 34.166.218.131:39568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/test.php"] [unique_id "aqxY7ecL08BTTQixEnp1mQAAAEQ"]
[Thu Sep 17 15:17:33.078997 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/storage/.env"] [unique_id "aqxY7ecL08BTTQixEnp1mwAAADA"]
[Thu Sep 17 15:17:33.165338 2026] [security2:error] [pid 971102:tid 971323] [client 157.90.156.63:19016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxY7ecL08BTTQixEnp1nQAAAFk"], referer: https://eris.media
[Thu Sep 17 15:17:33.245167 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/var/www/.env"] [unique_id "aqxY7ecL08BTTQixEnp1ngAAAAU"]
[Thu Sep 17 15:17:33.250358 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/shared/.env"] [unique_id "aqxY7ecL08BTTQixEnp1nwAAAA0"]
[Thu Sep 17 15:17:33.331089 2026] [security2:error] [pid 971102:tid 971240] [client 34.154.67.31:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/i.php"] [unique_id "aqxY7ecL08BTTQixEnp1ogAAAAY"]
[Thu Sep 17 15:17:33.404978 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/var/www/html/.env"] [unique_id "aqxY7ecL08BTTQixEnp1owAAAB4"]
[Thu Sep 17 15:17:33.415150 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/deploy/.env"] [unique_id "aqxY7ecL08BTTQixEnp1pAAAAAg"]
[Thu Sep 17 15:17:33.520603 2026] [security2:error] [pid 971102:tid 971284] [client 104.28.198.244:22762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ecL08BTTQixEnp1qAAAADI"]
[Thu Sep 17 15:17:33.520728 2026] [security2:error] [pid 971102:tid 971284] [client 104.28.198.244:22762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ecL08BTTQixEnp1qAAAADI"]
[Thu Sep 17 15:17:33.572531 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/current/.env"] [unique_id "aqxY7ecL08BTTQixEnp1qwAAAAk"]
[Thu Sep 17 15:17:33.621550 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/build/.env"] [unique_id "aqxY7ecL08BTTQixEnp1rQAAABY"]
[Thu Sep 17 15:17:33.681431 2026] [security2:error] [pid 971102:tid 971272] [client 172.239.147.162:55405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxY7ecL08BTTQixEnp1sQAAACY"], referer: binance.com
[Thu Sep 17 15:17:33.738802 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/release/.env"] [unique_id "aqxY7ecL08BTTQixEnp1swAAAEg"]
[Thu Sep 17 15:17:33.790010 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/dist/.env"] [unique_id "aqxY7ecL08BTTQixEnp1tgAAABM"]
[Thu Sep 17 15:17:33.795490 2026] [security2:error] [pid 971102:tid 971257] [client 34.154.67.31:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxY7ecL08BTTQixEnp1twAAABc"]
[Thu Sep 17 15:17:33.919366 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/releases/.env"] [unique_id "aqxY7ecL08BTTQixEnp1ugAAAGs"]
[Thu Sep 17 15:17:33.955674 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/public_html/.env"] [unique_id "aqxY7ecL08BTTQixEnp1vAAAAHE"]
[Thu Sep 17 15:17:34.006068 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.208.101:41724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY7ucL08BTTQixEnp1vwAAAEk"]
[Thu Sep 17 15:17:34.061968 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/p.php"] [unique_id "aqxY7ucL08BTTQixEnp1wQAAABs"]
[Thu Sep 17 15:17:34.087766 2026] [security2:error] [pid 971102:tid 971359] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/shared/.env"] [unique_id "aqxY7ucL08BTTQixEnp1wgAAAH0"]
[Thu Sep 17 15:17:34.109572 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/htdocs/.env"] [unique_id "aqxY7ucL08BTTQixEnp1wwAAAFw"]
[Thu Sep 17 15:17:34.136713 2026] [security2:error] [pid 971102:tid 971305] [client 172.239.147.162:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxY7ucL08BTTQixEnp1xQAAAEc"], referer: binance.com
[Thu Sep 17 15:17:34.152975 2026] [security2:error] [pid 971102:tid 971294] [client 45.169.98.18:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp1xwAAADw"]
[Thu Sep 17 15:17:34.153075 2026] [security2:error] [pid 971102:tid 971294] [client 45.169.98.18:59793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp1xwAAADw"]
[Thu Sep 17 15:17:34.255761 2026] [security2:error] [pid 971102:tid 971330] [client 34.154.67.31:34804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxY7ucL08BTTQixEnp1zAAAAGA"]
[Thu Sep 17 15:17:34.283667 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/www/.env"] [unique_id "aqxY7ucL08BTTQixEnp1zQAAAD0"]
[Thu Sep 17 15:17:34.305354 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/deploy/.env"] [unique_id "aqxY7ucL08BTTQixEnp1zgAAAG4"]
[Thu Sep 17 15:17:34.365807 2026] [security2:error] [pid 971102:tid 971308] [client 185.55.149.49:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp10AAAAEo"]
[Thu Sep 17 15:17:34.365914 2026] [security2:error] [pid 971102:tid 971308] [client 185.55.149.49:54225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp10AAAAEo"]
[Thu Sep 17 15:17:34.443280 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/html/.env"] [unique_id "aqxY7ucL08BTTQixEnp10QAAAG0"]
[Thu Sep 17 15:17:34.470220 2026] [security2:error] [pid 971102:tid 971259] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/build/.env"] [unique_id "aqxY7ucL08BTTQixEnp10wAAABk"]
[Thu Sep 17 15:17:34.611354 2026] [security2:error] [pid 971102:tid 971329] [client 78.46.190.63:55926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxY7ucL08BTTQixEnp12AAAAF8"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:17:34.619004 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/live/.env"] [unique_id "aqxY7ucL08BTTQixEnp12QAAAEQ"]
[Thu Sep 17 15:17:34.639025 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/dist/.env"] [unique_id "aqxY7ucL08BTTQixEnp12gAAADA"]
[Thu Sep 17 15:17:34.698709 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.208.101:55870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY7ucL08BTTQixEnp13gAAAFI"]
[Thu Sep 17 15:17:34.752332 2026] [security2:error] [pid 971102:tid 971273] [client 34.154.67.31:34806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/test.php"] [unique_id "aqxY7ucL08BTTQixEnp13wAAACc"]
[Thu Sep 17 15:17:34.757653 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.218.131:39598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxY7ucL08BTTQixEnp14AAAAAs"]
[Thu Sep 17 15:17:34.778484 2026] [security2:error] [pid 971102:tid 971317] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/prod/.env"] [unique_id "aqxY7ucL08BTTQixEnp14QAAAFM"]
[Thu Sep 17 15:17:34.812793 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/public_html/.env"] [unique_id "aqxY7ucL08BTTQixEnp14gAAAFo"]
[Thu Sep 17 15:17:34.849472 2026] [security2:error] [pid 971102:tid 971254] [client 44.239.144.77:55346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxY7OcL08BTTQixEnp1lwAAABQ"], referer: http://worthtranslations.com/new
[Thu Sep 17 15:17:34.934330 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/dev/.env"] [unique_id "aqxY7ucL08BTTQixEnp15gAAAAM"]
[Thu Sep 17 15:17:34.984327 2026] [security2:error] [pid 971102:tid 971267] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/htdocs/.env"] [unique_id "aqxY7ucL08BTTQixEnp16wAAACE"]
[Thu Sep 17 15:17:35.066701 2026] [security2:error] [pid 971102:tid 971349] [client 34.95.173.223:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php"] [unique_id "aqxY7-cL08BTTQixEnp17AAAAHM"]
[Thu Sep 17 15:17:35.087495 2026] [security2:error] [pid 971102:tid 971319] [client 78.46.190.63:55940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxY7-cL08BTTQixEnp17QAAAFU"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:17:35.108833 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/staging/.env"] [unique_id "aqxY7-cL08BTTQixEnp17wAAAAk"]
[Thu Sep 17 15:17:35.187292 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/www/.env"] [unique_id "aqxY7-cL08BTTQixEnp18QAAAHU"]
[Thu Sep 17 15:17:35.243226 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxY7-cL08BTTQixEnp19gAAABY"], referer: binance.com
[Thu Sep 17 15:17:35.261918 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/opt/.env"] [unique_id "aqxY7-cL08BTTQixEnp19wAAABM"]
[Thu Sep 17 15:17:35.359839 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/html/.env"] [unique_id "aqxY7-cL08BTTQixEnp1-AAAACs"]
[Thu Sep 17 15:17:35.399986 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.208.101:55884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY7-cL08BTTQixEnp1-QAAACY"]
[Thu Sep 17 15:17:35.423139 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/laravel/.env"] [unique_id "aqxY7-cL08BTTQixEnp1-gAAAAE"]
[Thu Sep 17 15:17:35.460973 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.218.131:39608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxY7-cL08BTTQixEnp1-wAAAEs"]
[Thu Sep 17 15:17:35.529795 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/live/.env"] [unique_id "aqxY7-cL08BTTQixEnp1_gAAACQ"]
[Thu Sep 17 15:17:35.578066 2026] [security2:error] [pid 971102:tid 971266] [client 34.95.173.223:42246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/info.php"] [unique_id "aqxY7-cL08BTTQixEnp2AQAAACA"]
[Thu Sep 17 15:17:35.586053 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/symfony/.env"] [unique_id "aqxY7-cL08BTTQixEnp2AgAAAHE"]
[Thu Sep 17 15:17:35.657401 2026] [security2:error] [pid 971102:tid 971236] [client 172.239.147.162:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxY7-cL08BTTQixEnp2AwAAAAI"], referer: binance.com
[Thu Sep 17 15:17:35.687336 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/prod/.env"] [unique_id "aqxY7-cL08BTTQixEnp2BQAAAE8"]
[Thu Sep 17 15:17:35.754418 2026] [security2:error] [pid 971102:tid 971246] [client 34.154.67.31:34818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/p.php"] [unique_id "aqxY7-cL08BTTQixEnp2CAAAAAw"]
[Thu Sep 17 15:17:35.857850 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/dev/.env"] [unique_id "aqxY7-cL08BTTQixEnp2DAAAADo"]
[Thu Sep 17 15:17:35.858377 2026] [security2:error] [pid 971102:tid 971327] [client 154.190.208.131:42269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7-cL08BTTQixEnp2DQAAAF0"]
[Thu Sep 17 15:17:35.864574 2026] [security2:error] [pid 971102:tid 971327] [client 154.190.208.131:42269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7-cL08BTTQixEnp2DQAAAF0"]
[Thu Sep 17 15:17:36.023172 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/staging/.env"] [unique_id "aqxY8OcL08BTTQixEnp2EgAAAEo"]
[Thu Sep 17 15:17:36.067380 2026] [security2:error] [pid 971102:tid 971330] [client 34.95.173.223:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/php.php"] [unique_id "aqxY8OcL08BTTQixEnp2EwAAAGA"]
[Thu Sep 17 15:17:36.110890 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/wordpress/.env"] [unique_id "aqxY8OcL08BTTQixEnp2FwAAACw"]
[Thu Sep 17 15:17:36.140928 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.218.131:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxY8OcL08BTTQixEnp2GAAAAFs"]
[Thu Sep 17 15:17:36.194618 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/opt/.env"] [unique_id "aqxY8OcL08BTTQixEnp2GwAAAH4"]
[Thu Sep 17 15:17:36.234699 2026] [security2:error] [pid 971102:tid 971343] [client 34.154.67.31:34508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxY8OcL08BTTQixEnp2HQAAAG0"]
[Thu Sep 17 15:17:36.277371 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/wp/.env"] [unique_id "aqxY8OcL08BTTQixEnp2HgAAAEQ"]
[Thu Sep 17 15:17:36.348092 2026] [security2:error] [pid 971102:tid 971296] [client 172.239.147.162:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxY8OcL08BTTQixEnp2IQAAAD4"], referer: binance.com
[Thu Sep 17 15:17:36.362891 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/laravel/.env"] [unique_id "aqxY8OcL08BTTQixEnp2IgAAAAs"]
[Thu Sep 17 15:17:36.448527 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cms/.env"] [unique_id "aqxY8OcL08BTTQixEnp2JAAAAAM"]
[Thu Sep 17 15:17:36.540461 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.208.101:55898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY8OcL08BTTQixEnp2KAAAAEU"]
[Thu Sep 17 15:17:36.553650 2026] [security2:error] [pid 971102:tid 971349] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/symfony/.env"] [unique_id "aqxY8OcL08BTTQixEnp2KQAAAHM"]
[Thu Sep 17 15:17:36.566745 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.173.223:42268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/i.php"] [unique_id "aqxY8OcL08BTTQixEnp2KgAAABQ"]
[Thu Sep 17 15:17:36.585427 2026] [security2:error] [pid 971102:tid 971251] [client 114.198.138.124:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8OcL08BTTQixEnp2KwAAABE"]
[Thu Sep 17 15:17:36.585520 2026] [security2:error] [pid 971102:tid 971251] [client 114.198.138.124:65504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8OcL08BTTQixEnp2KwAAABE"]
[Thu Sep 17 15:17:36.627003 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/drupal/.env"] [unique_id "aqxY8OcL08BTTQixEnp2LQAAADY"]
[Thu Sep 17 15:17:36.717008 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/wordpress/.env"] [unique_id "aqxY8OcL08BTTQixEnp2LwAAAEY"]
[Thu Sep 17 15:17:36.719902 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxY8OcL08BTTQixEnp2MAAAACU"]
[Thu Sep 17 15:17:36.799638 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/joomla/.env"] [unique_id "aqxY8OcL08BTTQixEnp2MgAAABM"]
[Thu Sep 17 15:17:36.829082 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxY8OcL08BTTQixEnp2NQAAAHY"]
[Thu Sep 17 15:17:36.903870 2026] [security2:error] [pid 971102:tid 971301] [client 217.138.10.135:15352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.10.138.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxY8OcL08BTTQixEnp2NgAAAEM"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:17:36.904020 2026] [security2:error] [pid 971102:tid 971301] [client 217.138.10.135:15352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxY8OcL08BTTQixEnp2NgAAAEM"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:17:36.907103 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/wp/.env"] [unique_id "aqxY8OcL08BTTQixEnp2NwAAAAY"]
[Thu Sep 17 15:17:36.971294 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/magento/.env"] [unique_id "aqxY8OcL08BTTQixEnp2OAAAACs"]
[Thu Sep 17 15:17:37.068923 2026] [security2:error] [pid 971102:tid 971354] [client 34.95.173.223:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/pi.php"] [unique_id "aqxY8ecL08BTTQixEnp2OwAAAHg"]
[Thu Sep 17 15:17:37.092964 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cms/.env"] [unique_id "aqxY8ecL08BTTQixEnp2PAAAACA"]
[Thu Sep 17 15:17:37.129044 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/shopify/.env"] [unique_id "aqxY8ecL08BTTQixEnp2PwAAAE8"]
[Thu Sep 17 15:17:37.198232 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2QQAAAH8"]
[Thu Sep 17 15:17:37.254677 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env"] [unique_id "aqxY8ecL08BTTQixEnp2QgAAAAE"]
[Thu Sep 17 15:17:37.277092 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/drupal/.env"] [unique_id "aqxY8ecL08BTTQixEnp2QwAAAFw"]
[Thu Sep 17 15:17:37.285698 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/prestashop/.env"] [unique_id "aqxY8ecL08BTTQixEnp2RAAAAEc"]
[Thu Sep 17 15:17:37.442604 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/joomla/.env"] [unique_id "aqxY8ecL08BTTQixEnp2RgAAABA"]
[Thu Sep 17 15:17:37.449294 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/codeigniter/.env"] [unique_id "aqxY8ecL08BTTQixEnp2RwAAADo"]
[Thu Sep 17 15:17:37.514328 2026] [security2:error] [pid 971102:tid 971294] [client 172.239.147.162:59902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxY8ecL08BTTQixEnp2SgAAADw"], referer: binance.com
[Thu Sep 17 15:17:37.522484 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2SwAAABI"]
[Thu Sep 17 15:17:37.553596 2026] [security2:error] [pid 971102:tid 971264] [client 34.95.173.223:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/pinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2TgAAAB4"]
[Thu Sep 17 15:17:37.623684 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/magento/.env"] [unique_id "aqxY8ecL08BTTQixEnp2UAAAAHk"]
[Thu Sep 17 15:17:37.632317 2026] [security2:error] [pid 971102:tid 971337] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cakephp/.env"] [unique_id "aqxY8ecL08BTTQixEnp2UQAAAGc"]
[Thu Sep 17 15:17:37.633218 2026] [security2:error] [pid 971102:tid 971110] [remote 111.225.148.196:24980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/224-Scavenger-Hunt-300x225.jpg"] [unique_id "aqxY8ecL08BTTQixEnp2UgAAXQY"]
[Thu Sep 17 15:17:37.683801 2026] [security2:error] [pid 971102:tid 971234] [client 34.154.67.31:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2UwAAAAA"]
[Thu Sep 17 15:17:37.809172 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/zend/.env"] [unique_id "aqxY8ecL08BTTQixEnp2VwAAAF8"]
[Thu Sep 17 15:17:37.963693 2026] [security2:error] [pid 971102:tid 971317] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/yii/.env"] [unique_id "aqxY8ecL08BTTQixEnp2XwAAAFM"]
[Thu Sep 17 15:17:38.040440 2026] [security2:error] [pid 971102:tid 971262] [client 34.95.173.223:42296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/test.php"] [unique_id "aqxY8ucL08BTTQixEnp2YgAAABw"]
[Thu Sep 17 15:17:38.129408 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/laravel5/.env"] [unique_id "aqxY8ucL08BTTQixEnp2ZwAAAGY"]
[Thu Sep 17 15:17:38.143623 2026] [security2:error] [pid 971102:tid 971344] [client 34.154.67.31:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2aAAAAG4"]
[Thu Sep 17 15:17:38.177582 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/shopify/.env"] [unique_id "aqxY8ucL08BTTQixEnp2aQAAAAU"]
[Thu Sep 17 15:17:38.219297 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.218.131:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2bAAAADE"]
[Thu Sep 17 15:17:38.300209 2026] [security2:error] [pid 971102:tid 971346] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/v1/.env"] [unique_id "aqxY8ucL08BTTQixEnp2bgAAAHA"]
[Thu Sep 17 15:17:38.375791 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/prestashop/.env"] [unique_id "aqxY8ucL08BTTQixEnp2cAAAAB0"]
[Thu Sep 17 15:17:38.450257 2026] [security2:error] [pid 971102:tid 971288] [client 172.239.147.162:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxY8ucL08BTTQixEnp2cgAAADY"], referer: binance.com
[Thu Sep 17 15:17:38.469168 2026] [security2:error] [pid 971102:tid 971352] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/v2/.env"] [unique_id "aqxY8ucL08BTTQixEnp2dQAAAHY"]
[Thu Sep 17 15:17:38.515481 2026] [security2:error] [pid 971102:tid 971297] [client 186.105.232.15:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8ucL08BTTQixEnp2dgAAAD8"]
[Thu Sep 17 15:17:38.515671 2026] [security2:error] [pid 971102:tid 971297] [client 186.105.232.15:55279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8ucL08BTTQixEnp2dgAAAD8"]
[Thu Sep 17 15:17:38.535410 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/codeigniter/.env"] [unique_id "aqxY8ucL08BTTQixEnp2eAAAAEM"]
[Thu Sep 17 15:17:38.633522 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/v3/.env"] [unique_id "aqxY8ucL08BTTQixEnp2ewAAAAg"]
[Thu Sep 17 15:17:38.634679 2026] [security2:error] [pid 971102:tid 971274] [client 34.154.67.31:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2fAAAACg"]
[Thu Sep 17 15:17:38.714352 2026] [security2:error] [pid 971102:tid 971345] [client 34.95.173.223:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/p.php"] [unique_id "aqxY8ucL08BTTQixEnp2gwAAAG8"]
[Thu Sep 17 15:17:38.723608 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cakephp/.env"] [unique_id "aqxY8ucL08BTTQixEnp2hAAAAE8"]
[Thu Sep 17 15:17:38.803112 2026] [security2:error] [pid 971102:tid 971361] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/v1/.env"] [unique_id "aqxY8ucL08BTTQixEnp2hQAAAH8"]
[Thu Sep 17 15:17:38.901052 2026] [security2:error] [pid 971102:tid 971238] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/zend/.env"] [unique_id "aqxY8ucL08BTTQixEnp2iQAAAAQ"]
[Thu Sep 17 15:17:38.919505 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.218.131:39642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2igAAACA"]
[Thu Sep 17 15:17:38.959139 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/v2/.env"] [unique_id "aqxY8ucL08BTTQixEnp2jAAAAFE"]
[Thu Sep 17 15:17:39.078527 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/yii/.env"] [unique_id "aqxY8-cL08BTTQixEnp2jwAAAF0"]
[Thu Sep 17 15:17:39.105969 2026] [security2:error] [pid 971102:tid 971292] [client 34.154.67.31:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxY8-cL08BTTQixEnp2kAAAADo"]
[Thu Sep 17 15:17:39.118171 2026] [security2:error] [pid 971102:tid 971268] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/rest/.env"] [unique_id "aqxY8-cL08BTTQixEnp2kQAAACI"]
[Thu Sep 17 15:17:39.130434 2026] [autoindex:error] [pid 971102:tid 971355] [client 164.92.74.247:46866] AH01276: Cannot serve directory /home1/zcktjlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:17:39.167317 2026] [security2:error] [pid 971102:tid 971341] [client 172.239.147.162:57625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxY8-cL08BTTQixEnp2kwAAAGs"], referer: binance.com
[Thu Sep 17 15:17:39.215801 2026] [security2:error] [pid 971102:tid 971337] [client 34.95.173.223:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/debug.php"] [unique_id "aqxY8-cL08BTTQixEnp2lAAAAGc"]
[Thu Sep 17 15:17:39.238940 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/laravel5/.env"] [unique_id "aqxY8-cL08BTTQixEnp2lwAAAH4"]
[Thu Sep 17 15:17:39.281026 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/graphql/.env"] [unique_id "aqxY8-cL08BTTQixEnp2mQAAABU"]
[Thu Sep 17 15:17:39.425638 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/v1/.env"] [unique_id "aqxY8-cL08BTTQixEnp2ngAAAD0"]
[Thu Sep 17 15:17:39.441371 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/gateway/.env"] [unique_id "aqxY8-cL08BTTQixEnp2nwAAAGY"]
[Thu Sep 17 15:17:39.441579 2026] [security2:error] [pid 971102:tid 971245] [client 45.187.111.151:38229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY8-cL08BTTQixEnp2mgAACz0"]
[Thu Sep 17 15:17:39.585174 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/v2/.env"] [unique_id "aqxY8-cL08BTTQixEnp2pgAAAFY"]
[Thu Sep 17 15:17:39.597585 2026] [security2:error] [pid 971102:tid 971349] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/microservice/.env"] [unique_id "aqxY8-cL08BTTQixEnp2pwAAAHM"]
[Thu Sep 17 15:17:39.757189 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.173.223:42312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxY8-cL08BTTQixEnp2sAAAAC0"]
[Thu Sep 17 15:17:39.762215 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/service/.env"] [unique_id "aqxY8-cL08BTTQixEnp2swAAABY"]
[Thu Sep 17 15:17:39.762240 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/v3/.env"] [unique_id "aqxY8-cL08BTTQixEnp2sgAAACU"]
[Thu Sep 17 15:17:39.773967 2026] [security2:error] [pid 971102:tid 971236] [client 156.192.234.52:51972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8-cL08BTTQixEnp2sQAAAAI"]
[Thu Sep 17 15:17:39.774090 2026] [security2:error] [pid 971102:tid 971236] [client 156.192.234.52:51972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8-cL08BTTQixEnp2sQAAAAI"]
[Thu Sep 17 15:17:39.901332 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.218.131:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxY8-cL08BTTQixEnp2tQAAAHI"]
[Thu Sep 17 15:17:39.923104 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/v1/.env"] [unique_id "aqxY8-cL08BTTQixEnp2tgAAAAY"]
[Thu Sep 17 15:17:39.924567 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/v3/.env"] [unique_id "aqxY8-cL08BTTQixEnp2twAAAEY"]
[Thu Sep 17 15:17:40.074259 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/v2/.env"] [unique_id "aqxY9OcL08BTTQixEnp2uQAAAAg"]
[Thu Sep 17 15:17:40.084878 2026] [security2:error] [pid 971102:tid 971345] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/dev/.env"] [unique_id "aqxY9OcL08BTTQixEnp2uwAAAG8"]
[Thu Sep 17 15:17:40.103092 2026] [security2:error] [pid 971102:tid 971258] [client 34.154.67.31:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxY9OcL08BTTQixEnp2vAAAABg"]
[Thu Sep 17 15:17:40.157239 2026] [security2:error] [pid 971102:tid 971361] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxY9OcL08BTTQixEnp2vQAAAH8"]
[Thu Sep 17 15:17:40.231083 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/rest/.env"] [unique_id "aqxY9OcL08BTTQixEnp2wQAAACY"]
[Thu Sep 17 15:17:40.239144 2026] [security2:error] [pid 971102:tid 971246] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/staging/.env"] [unique_id "aqxY9OcL08BTTQixEnp2wgAAAAw"]
[Thu Sep 17 15:17:40.244715 2026] [security2:error] [pid 971102:tid 971285] [client 34.95.173.223:42322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/test/phpinfo.php"] [unique_id "aqxY9OcL08BTTQixEnp2wwAAADM"]
[Thu Sep 17 15:17:40.383969 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/graphql/.env"] [unique_id "aqxY9OcL08BTTQixEnp2yQAAAFE"]
[Thu Sep 17 15:17:40.389063 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxY9OcL08BTTQixEnp2ygAAAF4"]
[Thu Sep 17 15:17:40.397966 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/vendor/.env"] [unique_id "aqxY9OcL08BTTQixEnp2ywAAACs"]
[Thu Sep 17 15:17:40.540874 2026] [security2:error] [pid 971102:tid 971261] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/gateway/.env"] [unique_id "aqxY9OcL08BTTQixEnp2zQAAABs"]
[Thu Sep 17 15:17:40.559625 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/lib/.env"] [unique_id "aqxY9OcL08BTTQixEnp2zgAAAHk"]
[Thu Sep 17 15:17:40.567984 2026] [security2:error] [pid 971102:tid 971311] [client 172.239.147.162:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxY9OcL08BTTQixEnp2zwAAAE0"], referer: binance.com
[Thu Sep 17 15:17:40.583718 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxY9OcL08BTTQixEnp20AAAADw"]
[Thu Sep 17 15:17:40.588500 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.218.131:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxY9OcL08BTTQixEnp20QAAAAQ"]
[Thu Sep 17 15:17:40.707423 2026] [security2:error] [pid 971102:tid 971286] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/microservice/.env"] [unique_id "aqxY9OcL08BTTQixEnp21wAAADQ"]
[Thu Sep 17 15:17:40.715562 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/resources/.env"] [unique_id "aqxY9OcL08BTTQixEnp22QAAAC8"]
[Thu Sep 17 15:17:40.750336 2026] [security2:error] [pid 971102:tid 971307] [client 34.95.173.223:42330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxY9OcL08BTTQixEnp22gAAAEk"]
[Thu Sep 17 15:17:40.858492 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/service/.env"] [unique_id "aqxY9OcL08BTTQixEnp23gAAAD0"]
[Thu Sep 17 15:17:40.868174 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/assets/.env"] [unique_id "aqxY9OcL08BTTQixEnp23wAAAAs"]
[Thu Sep 17 15:17:40.906356 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxY9OcL08BTTQixEnp24AAAACc"], referer: binance.com
[Thu Sep 17 15:17:40.995309 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxY9OcL08BTTQixEnp24wAAAAM"]
[Thu Sep 17 15:17:41.014368 2026] [security2:error] [pid 971102:tid 971349] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/v3/.env"] [unique_id "aqxY9ecL08BTTQixEnp25AAAAHM"]
[Thu Sep 17 15:17:41.025082 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/uploads/.env"] [unique_id "aqxY9ecL08BTTQixEnp25QAAADE"]
[Thu Sep 17 15:17:41.100673 2026] [security2:error] [pid 971102:tid 971324] [client 34.154.67.31:34598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp25gAAAFo"]
[Thu Sep 17 15:17:41.169087 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/dev/.env"] [unique_id "aqxY9ecL08BTTQixEnp26QAAAGI"]
[Thu Sep 17 15:17:41.181343 2026] [security2:error] [pid 971102:tid 971279] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/internal/.env"] [unique_id "aqxY9ecL08BTTQixEnp26wAAAC0"]
[Thu Sep 17 15:17:41.267855 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.173.223:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/old/phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp28gAAAHA"]
[Thu Sep 17 15:17:41.291838 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.218.131:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp28wAAAA0"]
[Thu Sep 17 15:17:41.332576 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/staging/.env"] [unique_id "aqxY9ecL08BTTQixEnp29QAAADY"]
[Thu Sep 17 15:17:41.342745 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/tools/.env"] [unique_id "aqxY9ecL08BTTQixEnp29gAAAFA"]
[Thu Sep 17 15:17:41.487799 2026] [security2:error] [pid 971102:tid 971297] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/vendor/.env"] [unique_id "aqxY9ecL08BTTQixEnp2-gAAAD8"]
[Thu Sep 17 15:17:41.501944 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/scripts/.env"] [unique_id "aqxY9ecL08BTTQixEnp2-wAAAGE"]
[Thu Sep 17 15:17:41.579171 2026] [security2:error] [pid 971102:tid 971338] [client 34.154.67.31:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp2_QAAAGg"]
[Thu Sep 17 15:17:41.651485 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/lib/.env"] [unique_id "aqxY9ecL08BTTQixEnp2_wAAAAg"]
[Thu Sep 17 15:17:41.660695 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/bin/.env"] [unique_id "aqxY9ecL08BTTQixEnp3AQAAAHE"]
[Thu Sep 17 15:17:41.761676 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.173.223:42354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp3BwAAABM"]
[Thu Sep 17 15:17:41.779498 2026] [security2:error] [pid 971102:tid 971274] [client 189.168.49.126:59613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY9ecL08BTTQixEnp3AAAAKCo"]
[Thu Sep 17 15:17:41.809796 2026] [security2:error] [pid 971102:tid 971354] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/resources/.env"] [unique_id "aqxY9ecL08BTTQixEnp3CgAAAHg"]
[Thu Sep 17 15:17:41.812922 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sbin/.env"] [unique_id "aqxY9ecL08BTTQixEnp3CwAAACA"]
[Thu Sep 17 15:17:41.964855 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/assets/.env"] [unique_id "aqxY9ecL08BTTQixEnp3DgAAAF0"]
[Thu Sep 17 15:17:41.967390 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/local/.env"] [unique_id "aqxY9ecL08BTTQixEnp3DwAAABI"]
[Thu Sep 17 15:17:41.968123 2026] [security2:error] [pid 971102:tid 971316] [client 74.7.175.189:36630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hbz.rgg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY8ecL08BTTQixEnp2WgAAUmA"]
[Thu Sep 17 15:17:42.007785 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.218.131:48762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxY9ucL08BTTQixEnp3EQAAACk"]
[Thu Sep 17 15:17:42.052742 2026] [security2:error] [pid 971102:tid 971328] [client 34.154.67.31:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxY9ucL08BTTQixEnp3EgAAAF4"]
[Thu Sep 17 15:17:42.116953 2026] [security2:error] [pid 971102:tid 971227] [remote 216.73.217.142:15074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxY9ucL08BTTQixEnp3FQAAG3o"]
[Thu Sep 17 15:17:42.125675 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/uploads/.env"] [unique_id "aqxY9ucL08BTTQixEnp3FgAAAGA"]
[Thu Sep 17 15:17:42.126386 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/portal/.env"] [unique_id "aqxY9ucL08BTTQixEnp3FwAAAEs"]
[Thu Sep 17 15:17:42.265908 2026] [security2:error] [pid 971102:tid 971268] [client 34.95.173.223:42366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/public/phpinfo.php"] [unique_id "aqxY9ucL08BTTQixEnp3HQAAACI"]
[Thu Sep 17 15:17:42.282008 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/internal/.env"] [unique_id "aqxY9ucL08BTTQixEnp3HgAAABU"]
[Thu Sep 17 15:17:42.282273 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/dashboard/.env"] [unique_id "aqxY9ucL08BTTQixEnp3HwAAAEk"]
[Thu Sep 17 15:17:42.433151 2026] [security2:error] [pid 971102:tid 971329] [client 172.239.147.162:55505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/icons.php"] [unique_id "aqxY9ucL08BTTQixEnp3IgAAAF8"], referer: binance.com
[Thu Sep 17 15:17:42.436167 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/panel/.env"] [unique_id "aqxY9ucL08BTTQixEnp3IwAAAHs"]
[Thu Sep 17 15:17:42.439149 2026] [security2:error] [pid 971102:tid 971262] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/tools/.env"] [unique_id "aqxY9ucL08BTTQixEnp3JAAAABw"]
[Thu Sep 17 15:17:42.517703 2026] [security2:error] [pid 971102:tid 971265] [client 34.154.67.31:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxY9ucL08BTTQixEnp3KQAAAB8"]
[Thu Sep 17 15:17:42.590881 2026] [security2:error] [pid 971102:tid 971280] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/crm/.env"] [unique_id "aqxY9ucL08BTTQixEnp3LQAAAC4"]
[Thu Sep 17 15:17:42.595066 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/scripts/.env"] [unique_id "aqxY9ucL08BTTQixEnp3LwAAAG0"]
[Thu Sep 17 15:17:42.714813 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.218.131:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxY9ucL08BTTQixEnp3MwAAAAM"]
[Thu Sep 17 15:17:42.748226 2026] [security2:error] [pid 971102:tid 971352] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/erp/.env"] [unique_id "aqxY9ucL08BTTQixEnp3NQAAAHY"]
[Thu Sep 17 15:17:42.751985 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/bin/.env"] [unique_id "aqxY9ucL08BTTQixEnp3NgAAAGw"]
[Thu Sep 17 15:17:42.908189 2026] [security2:error] [pid 971102:tid 971339] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sbin/.env"] [unique_id "aqxY9ucL08BTTQixEnp3OwAAAGk"]
[Thu Sep 17 15:17:42.909239 2026] [security2:error] [pid 971102:tid 971257] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/shop/.env"] [unique_id "aqxY9ucL08BTTQixEnp3PAAAABc"]
[Thu Sep 17 15:17:42.928158 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.173.223:42368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/php-info.php"] [unique_id "aqxY9ucL08BTTQixEnp3PgAAAHc"]
[Thu Sep 17 15:17:43.026877 2026] [security2:error] [pid 971102:tid 971301] [client 57.141.14.51:58956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxY9ucL08BTTQixEnp3OQAAQ3k"]
[Thu Sep 17 15:17:43.064500 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/store/.env"] [unique_id "aqxY9-cL08BTTQixEnp3RAAAAFw"]
[Thu Sep 17 15:17:43.064504 2026] [security2:error] [pid 971102:tid 971345] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/local/.env"] [unique_id "aqxY9-cL08BTTQixEnp3QwAAAG8"]
[Thu Sep 17 15:17:43.228189 2026] [security2:error] [pid 971102:tid 971354] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/saas/.env"] [unique_id "aqxY9-cL08BTTQixEnp3SwAAAHg"]
[Thu Sep 17 15:17:43.228230 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/portal/.env"] [unique_id "aqxY9-cL08BTTQixEnp3TAAAACA"]
[Thu Sep 17 15:17:43.383167 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/client/.env"] [unique_id "aqxY9-cL08BTTQixEnp3UwAAAE8"]
[Thu Sep 17 15:17:43.385633 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/dashboard/.env"] [unique_id "aqxY9-cL08BTTQixEnp3VAAAABo"]
[Thu Sep 17 15:17:43.421782 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.173.223:42374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpversion.php"] [unique_id "aqxY9-cL08BTTQixEnp3VQAAABQ"]
[Thu Sep 17 15:17:43.422557 2026] [security2:error] [pid 971102:tid 971246] [client 34.166.218.131:48776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxY9-cL08BTTQixEnp3VgAAAAw"]
[Thu Sep 17 15:17:43.563546 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/panel/.env"] [unique_id "aqxY9-cL08BTTQixEnp3WwAAAEc"]
[Thu Sep 17 15:17:43.563546 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/project/.env"] [unique_id "aqxY9-cL08BTTQixEnp3WgAAAEs"]
[Thu Sep 17 15:17:43.725255 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/admin-panel/.env"] [unique_id "aqxY9-cL08BTTQixEnp3YgAAAEo"]
[Thu Sep 17 15:17:43.725288 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/crm/.env"] [unique_id "aqxY9-cL08BTTQixEnp3YwAAABA"]
[Thu Sep 17 15:17:43.885894 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/control-panel/.env"] [unique_id "aqxY9-cL08BTTQixEnp3ZgAAAF8"]
[Thu Sep 17 15:17:43.888725 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/erp/.env"] [unique_id "aqxY9-cL08BTTQixEnp3ZwAAAHs"]
[Thu Sep 17 15:17:43.931626 2026] [security2:error] [pid 971102:tid 971291] [client 34.95.173.223:42384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/_phpinfo.php"] [unique_id "aqxY9-cL08BTTQixEnp3aAAAADk"]
[Thu Sep 17 15:17:44.044846 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/user-panel/.env"] [unique_id "aqxY-OcL08BTTQixEnp3aQAAAFY"]
[Thu Sep 17 15:17:44.057180 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/shop/.env"] [unique_id "aqxY-OcL08BTTQixEnp3agAAAG0"]
[Thu Sep 17 15:17:44.062974 2026] [security2:error] [pid 971102:tid 971273] [client 34.154.67.31:34656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY-OcL08BTTQixEnp3awAAACc"]
[Thu Sep 17 15:17:44.108109 2026] [security2:error] [pid 971102:tid 971355] [client 172.239.147.162:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxY-OcL08BTTQixEnp3bAAAAHk"], referer: binance.com
[Thu Sep 17 15:17:44.198686 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/node/.env"] [unique_id "aqxY-OcL08BTTQixEnp3dAAAAA0"]
[Thu Sep 17 15:17:44.213403 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/store/.env"] [unique_id "aqxY-OcL08BTTQixEnp3dgAAADY"]
[Thu Sep 17 15:17:44.352295 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/express/.env"] [unique_id "aqxY-OcL08BTTQixEnp3ewAAAFo"]
[Thu Sep 17 15:17:44.363257 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/saas/.env"] [unique_id "aqxY-OcL08BTTQixEnp3fAAAAG4"]
[Thu Sep 17 15:17:44.429021 2026] [security2:error] [pid 971102:tid 971321] [client 34.95.173.223:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/old_phpinfo.php"] [unique_id "aqxY-OcL08BTTQixEnp3fwAAAFc"]
[Thu Sep 17 15:17:44.512113 2026] [security2:error] [pid 971102:tid 971358] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/next/.env"] [unique_id "aqxY-OcL08BTTQixEnp3gwAAAHw"]
[Thu Sep 17 15:17:44.519927 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/client/.env"] [unique_id "aqxY-OcL08BTTQixEnp3hQAAAEM"]
[Thu Sep 17 15:17:44.542602 2026] [security2:error] [pid 971102:tid 971297] [client 34.154.67.31:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxY-OcL08BTTQixEnp3hgAAAD8"]
[Thu Sep 17 15:17:44.657994 2026] [security2:error] [pid 971102:tid 971353] [client 45.169.98.18:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-OcL08BTTQixEnp3iQAAAHc"]
[Thu Sep 17 15:17:44.658142 2026] [security2:error] [pid 971102:tid 971353] [client 45.169.98.18:60358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-OcL08BTTQixEnp3iQAAAHc"]
[Thu Sep 17 15:17:44.666655 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/nuxt/.env"] [unique_id "aqxY-OcL08BTTQixEnp3igAAAFw"]
[Thu Sep 17 15:17:44.678078 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/project/.env"] [unique_id "aqxY-OcL08BTTQixEnp3iwAAABM"]
[Thu Sep 17 15:17:44.694592 2026] [security2:error] [pid 971102:tid 971235] [client 34.166.218.131:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY-OcL08BTTQixEnp3jgAAAAE"]
[Thu Sep 17 15:17:44.745374 2026] [security2:error] [pid 971102:tid 971267] [client 172.239.147.162:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/json-schema.php"] [unique_id "aqxY-OcL08BTTQixEnp3kAAAACE"], referer: binance.com
[Thu Sep 17 15:17:44.825321 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/nest/.env"] [unique_id "aqxY-OcL08BTTQixEnp3kQAAACY"]
[Thu Sep 17 15:17:44.843208 2026] [security2:error] [pid 971102:tid 971317] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/admin-panel/.env"] [unique_id "aqxY-OcL08BTTQixEnp3kgAAAFM"]
[Thu Sep 17 15:17:44.945719 2026] [security2:error] [pid 971102:tid 971313] [client 34.95.173.223:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/server-info.php"] [unique_id "aqxY-OcL08BTTQixEnp3lgAAAE8"]
[Thu Sep 17 15:17:44.981540 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/react/.env"] [unique_id "aqxY-OcL08BTTQixEnp3lwAAACs"]
[Thu Sep 17 15:17:45.003210 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/control-panel/.env"] [unique_id "aqxY-ecL08BTTQixEnp3mAAAAF4"]
[Thu Sep 17 15:17:45.011686 2026] [security2:error] [pid 971102:tid 971327] [client 34.154.67.31:34664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3mQAAAF0"]
[Thu Sep 17 15:17:45.061980 2026] [security2:error] [pid 971102:tid 971359] [client 185.55.149.49:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY-ecL08BTTQixEnp3nQAAAH0"]
[Thu Sep 17 15:17:45.062095 2026] [security2:error] [pid 971102:tid 971359] [client 185.55.149.49:54897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY-ecL08BTTQixEnp3nQAAAH0"]
[Thu Sep 17 15:17:45.089647 2026] [security2:error] [pid 971102:tid 971251] [client 216.73.217.138:33114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nlfephrata.org"] [uri "/index.php"] [unique_id "aqxY9ucL08BTTQixEnp3MAAAEQU"]
[Thu Sep 17 15:17:45.135727 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/vue/.env"] [unique_id "aqxY-ecL08BTTQixEnp3owAAACw"]
[Thu Sep 17 15:17:45.157947 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/user-panel/.env"] [unique_id "aqxY-ecL08BTTQixEnp3pAAAAEk"]
[Thu Sep 17 15:17:45.293472 2026] [security2:error] [pid 971102:tid 971337] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/angular/.env"] [unique_id "aqxY-ecL08BTTQixEnp3qwAAAGc"]
[Thu Sep 17 15:17:45.320113 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/node/.env"] [unique_id "aqxY-ecL08BTTQixEnp3rAAAAE4"]
[Thu Sep 17 15:17:45.384900 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.218.131:48786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3rQAAAH8"]
[Thu Sep 17 15:17:45.432945 2026] [security2:error] [pid 971102:tid 971289] [client 34.95.173.223:37232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/server-status.php"] [unique_id "aqxY-ecL08BTTQixEnp3rgAAADc"]
[Thu Sep 17 15:17:45.450109 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/svelte/.env"] [unique_id "aqxY-ecL08BTTQixEnp3rwAAAG0"]
[Thu Sep 17 15:17:45.465130 2026] [security2:error] [pid 971102:tid 971329] [client 172.239.147.162:50438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxY-ecL08BTTQixEnp3sAAAAF8"], referer: binance.com
[Thu Sep 17 15:17:45.483000 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/express/.env"] [unique_id "aqxY-ecL08BTTQixEnp3sQAAAHk"]
[Thu Sep 17 15:17:45.513286 2026] [security2:error] [pid 971102:tid 971357] [client 34.154.67.31:34678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3sgAAAHs"]
[Thu Sep 17 15:17:45.612747 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxY-ecL08BTTQixEnp3swAAAFk"]
[Thu Sep 17 15:17:45.613285 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/vite/.env"] [unique_id "aqxY-ecL08BTTQixEnp3tAAAAH4"]
[Thu Sep 17 15:17:45.646374 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/next/.env"] [unique_id "aqxY-ecL08BTTQixEnp3tQAAAA0"]
[Thu Sep 17 15:17:45.770335 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/backup/.env"] [unique_id "aqxY-ecL08BTTQixEnp3uQAAAFo"]
[Thu Sep 17 15:17:45.808864 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/nuxt/.env"] [unique_id "aqxY-ecL08BTTQixEnp3ugAAAGY"]
[Thu Sep 17 15:17:45.847560 2026] [security2:error] [pid 971102:tid 971331] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env~"] [unique_id "aqxY-ecL08BTTQixEnp3vAAAAGE"]
[Thu Sep 17 15:17:45.930969 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/backups/.env"] [unique_id "aqxY-ecL08BTTQixEnp3vQAAACU"]
[Thu Sep 17 15:17:45.965385 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/nest/.env"] [unique_id "aqxY-ecL08BTTQixEnp3vwAAABY"]
[Thu Sep 17 15:17:45.999073 2026] [security2:error] [pid 971102:tid 971321] [client 34.154.67.31:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3wAAAAFc"]
[Thu Sep 17 15:17:46.088823 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.218.131:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp3wgAAAGk"]
[Thu Sep 17 15:17:46.090765 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/old/.env"] [unique_id "aqxY-ucL08BTTQixEnp3wwAAAEM"]
[Thu Sep 17 15:17:46.140056 2026] [security2:error] [pid 971102:tid 971284] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/react/.env"] [unique_id "aqxY-ucL08BTTQixEnp3xgAAADI"]
[Thu Sep 17 15:17:46.205029 2026] [authz_core:error] [pid 971102:tid 971303] [client 5.189.145.112:56782] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:46.248748 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/tmp/.env"] [unique_id "aqxY-ucL08BTTQixEnp3zAAAAEY"]
[Thu Sep 17 15:17:46.288544 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.173.223:37236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY-ucL08BTTQixEnp3zQAAAFw"]
[Thu Sep 17 15:17:46.295081 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/vue/.env"] [unique_id "aqxY-ucL08BTTQixEnp3zgAAABM"]
[Thu Sep 17 15:17:46.405429 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-ucL08BTTQixEnp30QAAAHY"]
[Thu Sep 17 15:17:46.405531 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:41534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-ucL08BTTQixEnp30QAAAHY"]
[Thu Sep 17 15:17:46.414687 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/temp/.env"] [unique_id "aqxY-ucL08BTTQixEnp30gAAABo"]
[Thu Sep 17 15:17:46.463807 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/angular/.env"] [unique_id "aqxY-ucL08BTTQixEnp31AAAACY"]
[Thu Sep 17 15:17:46.478074 2026] [security2:error] [pid 971102:tid 971235] [client 34.154.67.31:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp31gAAAAE"]
[Thu Sep 17 15:17:46.574767 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/lab/.env"] [unique_id "aqxY-ucL08BTTQixEnp33AAAAE8"]
[Thu Sep 17 15:17:46.622655 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/svelte/.env"] [unique_id "aqxY-ucL08BTTQixEnp33gAAAF0"]
[Thu Sep 17 15:17:46.687468 2026] [security2:error] [pid 971102:tid 971244] [client 172.239.147.162:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxY-ucL08BTTQixEnp34QAAAAo"], referer: binance.com
[Thu Sep 17 15:17:46.732553 2026] [security2:error] [pid 971102:tid 971311] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cronlab/.env"] [unique_id "aqxY-ucL08BTTQixEnp34wAAAE0"]
[Thu Sep 17 15:17:46.779076 2026] [security2:error] [pid 971102:tid 971277] [client 34.95.173.223:37248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp35wAAACs"]
[Thu Sep 17 15:17:46.780177 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/vite/.env"] [unique_id "aqxY-ucL08BTTQixEnp36AAAACw"]
[Thu Sep 17 15:17:46.796023 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.218.131:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp36QAAAFs"]
[Thu Sep 17 15:17:46.898166 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cron/.env"] [unique_id "aqxY-ucL08BTTQixEnp36wAAAEQ"]
[Thu Sep 17 15:17:46.940533 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/backup/.env"] [unique_id "aqxY-ucL08BTTQixEnp37QAAAB4"]
[Thu Sep 17 15:17:46.949088 2026] [security2:error] [pid 971102:tid 971307] [client 34.154.67.31:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxY-ucL08BTTQixEnp37wAAAEk"]
[Thu Sep 17 15:17:47.056474 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/en/.env"] [unique_id "aqxY--cL08BTTQixEnp38AAAADg"]
[Thu Sep 17 15:17:47.092049 2026] [security2:error] [pid 971102:tid 971282] [client 114.198.138.124:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY--cL08BTTQixEnp38QAAADA"]
[Thu Sep 17 15:17:47.092151 2026] [security2:error] [pid 971102:tid 971282] [client 114.198.138.124:55745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY--cL08BTTQixEnp38QAAADA"]
[Thu Sep 17 15:17:47.096097 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/backups/.env"] [unique_id "aqxY--cL08BTTQixEnp38gAAAC8"]
[Thu Sep 17 15:17:47.258463 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/old/.env"] [unique_id "aqxY--cL08BTTQixEnp3-QAAADo"]
[Thu Sep 17 15:17:47.268445 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.173.223:37252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY--cL08BTTQixEnp3_QAAAAk"]
[Thu Sep 17 15:17:47.318636 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/administrator/.env"] [unique_id "aqxY--cL08BTTQixEnp3-gAAADY"]
[Thu Sep 17 15:17:47.425067 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/tmp/.env"] [unique_id "aqxY--cL08BTTQixEnp4BAAAAAA"]
[Thu Sep 17 15:17:47.433475 2026] [security2:error] [pid 971102:tid 971323] [client 34.154.67.31:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxY--cL08BTTQixEnp4BQAAAFk"]
[Thu Sep 17 15:17:47.445578 2026] [security2:error] [pid 971102:tid 971310] [client 172.239.147.162:55399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxY--cL08BTTQixEnp4BgAAAEw"], referer: binance.com
[Thu Sep 17 15:17:47.485466 2026] [security2:error] [pid 971102:tid 971350] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/psnlink/.env"] [unique_id "aqxY--cL08BTTQixEnp4CAAAAHQ"]
[Thu Sep 17 15:17:47.486357 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.218.131:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY--cL08BTTQixEnp4CQAAAHs"]
[Thu Sep 17 15:17:47.580938 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/temp/.env"] [unique_id "aqxY--cL08BTTQixEnp4CwAAAFI"]
[Thu Sep 17 15:17:47.658863 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/exapi/.env"] [unique_id "aqxY--cL08BTTQixEnp4DwAAAEY"]
[Thu Sep 17 15:17:47.745632 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/lab/.env"] [unique_id "aqxY--cL08BTTQixEnp4FAAAABM"]
[Thu Sep 17 15:17:47.757031 2026] [security2:error] [pid 971102:tid 971303] [client 34.95.173.223:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY--cL08BTTQixEnp4FQAAAEU"]
[Thu Sep 17 15:17:47.811543 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sitemaps/.env"] [unique_id "aqxY--cL08BTTQixEnp4FgAAACA"]
[Thu Sep 17 15:17:47.902715 2026] [security2:error] [pid 971102:tid 971326] [client 34.154.67.31:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxY--cL08BTTQixEnp4GwAAAFw"]
[Thu Sep 17 15:17:47.905488 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cronlab/.env"] [unique_id "aqxY--cL08BTTQixEnp4HAAAACY"]
[Thu Sep 17 15:17:48.058169 2026] [security2:error] [pid 971102:tid 971274] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cron/.env"] [unique_id "aqxY_OcL08BTTQixEnp4IQAAACg"]
[Thu Sep 17 15:17:48.106171 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY--cL08BTTQixEnp4IAAAAEg"]
[Thu Sep 17 15:17:48.167088 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.218.131:48818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY_OcL08BTTQixEnp4LQAAAE8"]
[Thu Sep 17 15:17:48.216006 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/en/.env"] [unique_id "aqxY_OcL08BTTQixEnp4MwAAAB4"]
[Thu Sep 17 15:17:48.242085 2026] [security2:error] [pid 971102:tid 971309] [client 34.95.173.223:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY_OcL08BTTQixEnp4NQAAAEs"]
[Thu Sep 17 15:17:48.280183 2026] [security2:error] [pid 971102:tid 971359] [client 192.178.6.4:61863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxY_OcL08BTTQixEnp4NAAAAH0"]
[Thu Sep 17 15:17:48.368522 2026] [security2:error] [pid 971102:tid 971330] [client 34.154.67.31:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxY_OcL08BTTQixEnp4NgAAAGA"]
[Thu Sep 17 15:17:48.372099 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/administrator/.env"] [unique_id "aqxY_OcL08BTTQixEnp4NwAAABA"]
[Thu Sep 17 15:17:48.515504 2026] [security2:error] [pid 971102:tid 971320] [client 162.241.226.11:42776] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxY_OcL08BTTQixEnp4PAAAAFY"]
[Thu Sep 17 15:17:48.532678 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/psnlink/.env"] [unique_id "aqxY_OcL08BTTQixEnp4PgAAADY"]
[Thu Sep 17 15:17:48.537564 2026] [security2:error] [pid 971102:tid 971332] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxY_OcL08BTTQixEnp4PwAAAGI"]
[Thu Sep 17 15:17:48.578363 2026] [security2:error] [pid 971102:tid 971361] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY_OcL08BTTQixEnp4OgAAAH8"]
[Thu Sep 17 15:17:48.683656 2026] [security2:error] [pid 971102:tid 971323] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/exapi/.env"] [unique_id "aqxY_OcL08BTTQixEnp4QQAAAFk"]
[Thu Sep 17 15:17:48.727794 2026] [security2:error] [pid 971102:tid 971283] [client 34.95.173.223:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY_OcL08BTTQixEnp4QwAAADE"]
[Thu Sep 17 15:17:48.769979 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxY_OcL08BTTQixEnp4RAAAAHs"]
[Thu Sep 17 15:17:48.780989 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/logs/.env"] [unique_id "aqxY_OcL08BTTQixEnp4RQAAACU"]
[Thu Sep 17 15:17:48.837727 2026] [security2:error] [pid 971102:tid 971360] [client 34.154.67.31:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxY_OcL08BTTQixEnp4RwAAAH4"]
[Thu Sep 17 15:17:48.847187 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sitemaps/.env"] [unique_id "aqxY_OcL08BTTQixEnp4SAAAAHI"]
[Thu Sep 17 15:17:48.870064 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.218.131:48826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxY_OcL08BTTQixEnp4SQAAAG0"]
[Thu Sep 17 15:17:48.886120 2026] [security2:error] [pid 971102:tid 971305] [client 172.239.147.162:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxY_OcL08BTTQixEnp4SgAAAEc"], referer: binance.com
[Thu Sep 17 15:17:49.003946 2026] [security2:error] [pid 971102:tid 971329] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxY_ecL08BTTQixEnp4TAAAAF8"]
[Thu Sep 17 15:17:49.028716 2026] [security2:error] [pid 971102:tid 971341] [client 190.5.36.152:52504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY_OcL08BTTQixEnp4SwAAa0g"]
[Thu Sep 17 15:17:49.227998 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY_ecL08BTTQixEnp4UgAAABM"]
[Thu Sep 17 15:17:49.230451 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.173.223:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxY_ecL08BTTQixEnp4WwAAAEY"]
[Thu Sep 17 15:17:49.235885 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxY_ecL08BTTQixEnp4XAAAAFw"]
[Thu Sep 17 15:17:49.276123 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cache/.env"] [unique_id "aqxY_ecL08BTTQixEnp4XgAAAEU"]
[Thu Sep 17 15:17:49.302261 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:51860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxY_ecL08BTTQixEnp4XwAAACQ"]
[Thu Sep 17 15:17:49.432759 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailer/.env"] [unique_id "aqxY_ecL08BTTQixEnp4ZQAAACk"]
[Thu Sep 17 15:17:49.471835 2026] [security2:error] [pid 971102:tid 971311] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxY_ecL08BTTQixEnp4ZwAAAE0"]
[Thu Sep 17 15:17:49.548961 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.218.131:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxY_ecL08BTTQixEnp4aAAAAHo"]
[Thu Sep 17 15:17:49.597400 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mail/.env"] [unique_id "aqxY_ecL08BTTQixEnp4awAAAEs"]
[Thu Sep 17 15:17:49.614823 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:55928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ecL08BTTQixEnp4bAAAABg"]
[Thu Sep 17 15:17:49.614943 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:55928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ecL08BTTQixEnp4bAAAABg"]
[Thu Sep 17 15:17:49.709162 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxY_ecL08BTTQixEnp4cgAAAAM"]
[Thu Sep 17 15:17:49.732368 2026] [security2:error] [pid 971102:tid 971264] [client 34.95.173.223:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php.old"] [unique_id "aqxY_ecL08BTTQixEnp4cwAAAB4"]
[Thu Sep 17 15:17:49.754975 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/email/.env"] [unique_id "aqxY_ecL08BTTQixEnp4dgAAACw"]
[Thu Sep 17 15:17:49.782832 2026] [security2:error] [pid 971102:tid 971285] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY_ecL08BTTQixEnp4cQAAADM"]
[Thu Sep 17 15:17:49.915706 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/smtp/.env"] [unique_id "aqxY_ecL08BTTQixEnp4fAAAADg"]
[Thu Sep 17 15:17:50.012919 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/logs/.env"] [unique_id "aqxY_ucL08BTTQixEnp4gAAAAFY"]
[Thu Sep 17 15:17:50.076536 2026] [security2:error] [pid 971102:tid 971358] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailing/.env"] [unique_id "aqxY_ucL08BTTQixEnp4gwAAAHw"]
[Thu Sep 17 15:17:50.156846 2026] [security2:error] [pid 971102:tid 971281] [client 34.154.67.31:51872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxY_ucL08BTTQixEnp4iwAAAC8"]
[Thu Sep 17 15:17:50.170223 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cache/.env"] [unique_id "aqxY_ucL08BTTQixEnp4jQAAAAY"]
[Thu Sep 17 15:17:50.209765 2026] [security2:error] [pid 971102:tid 971289] [client 172.239.147.162:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxY_ucL08BTTQixEnp4kAAAADc"], referer: binance.com
[Thu Sep 17 15:17:50.228776 2026] [security2:error] [pid 971102:tid 971292] [client 34.95.173.223:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php~"] [unique_id "aqxY_ucL08BTTQixEnp4kQAAADo"]
[Thu Sep 17 15:17:50.234236 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/notifications/.env"] [unique_id "aqxY_ucL08BTTQixEnp4kgAAAG4"]
[Thu Sep 17 15:17:50.241626 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.218.131:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxY_ucL08BTTQixEnp4kwAAAB8"]
[Thu Sep 17 15:17:50.266367 2026] [security2:error] [pid 971102:tid 971250] [client 156.192.234.52:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ucL08BTTQixEnp4lAAAABA"]
[Thu Sep 17 15:17:50.269496 2026] [security2:error] [pid 971102:tid 971250] [client 156.192.234.52:52587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ucL08BTTQixEnp4lAAAABA"]
[Thu Sep 17 15:17:50.333558 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailer/.env"] [unique_id "aqxY_ucL08BTTQixEnp4lQAAAEc"]
[Thu Sep 17 15:17:50.350008 2026] [security2:error] [pid 971102:tid 971321] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY_ucL08BTTQixEnp4lgAAAFc"]
[Thu Sep 17 15:17:50.402436 2026] [security2:error] [pid 971102:tid 971310] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/notify/.env"] [unique_id "aqxY_ucL08BTTQixEnp4lwAAAEw"]
[Thu Sep 17 15:17:50.484123 2026] [security2:error] [pid 971102:tid 971338] [client 185.213.175.37:38354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env"] [unique_id "aqxY_ucL08BTTQixEnp4mAAAAGg"]
[Thu Sep 17 15:17:50.486643 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mail/.env"] [unique_id "aqxY_ucL08BTTQixEnp4mQAAABM"]
[Thu Sep 17 15:17:50.563326 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sender/.env"] [unique_id "aqxY_ucL08BTTQixEnp4mwAAAFo"]
[Thu Sep 17 15:17:50.580927 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxY_ucL08BTTQixEnp4nAAAAAE"]
[Thu Sep 17 15:17:50.598207 2026] [security2:error] [pid 971102:tid 971303] [client 185.213.175.37:38370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxY_ucL08BTTQixEnp4nQAAAEU"]
[Thu Sep 17 15:17:50.645386 2026] [security2:error] [pid 971102:tid 971341] [client 34.154.67.31:51878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxY_ucL08BTTQixEnp4oAAAAGs"]
[Thu Sep 17 15:17:50.649935 2026] [security2:error] [pid 971102:tid 971352] [client 185.213.175.37:38354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxY_ucL08BTTQixEnp4oQAAAHY"]
[Thu Sep 17 15:17:50.650948 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/email/.env"] [unique_id "aqxY_ucL08BTTQixEnp4ogAAAAI"]
[Thu Sep 17 15:17:50.654593 2026] [security2:error] [pid 971102:tid 971328] [client 74.7.241.151:42240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.oqz.eln.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxY_ucL08BTTQixEnp4nwAAAF4"]
[Thu Sep 17 15:17:50.716765 2026] [security2:error] [pid 971102:tid 971272] [client 34.95.173.223:37304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/info.php.bak"] [unique_id "aqxY_ucL08BTTQixEnp4pQAAACY"]
[Thu Sep 17 15:17:50.718823 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/campaign/.env"] [unique_id "aqxY_ucL08BTTQixEnp4pgAAAAg"]
[Thu Sep 17 15:17:50.807426 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/smtp/.env"] [unique_id "aqxY_ucL08BTTQixEnp4qQAAAEI"]
[Thu Sep 17 15:17:50.809026 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxY_ucL08BTTQixEnp4qgAAACs"]
[Thu Sep 17 15:17:50.896095 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/newsletter/.env"] [unique_id "aqxY_ucL08BTTQixEnp4rAAAABo"]
[Thu Sep 17 15:17:50.905990 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:38354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production"] [unique_id "aqxY_ucL08BTTQixEnp4rQAAABQ"]
[Thu Sep 17 15:17:50.906112 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:38354] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production"] [unique_id "aqxY_ucL08BTTQixEnp4rQAAABQ"]
[Thu Sep 17 15:17:50.921853 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.218.131:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxY_ucL08BTTQixEnp4rgAAAHU"]
[Thu Sep 17 15:17:50.970801 2026] [security2:error] [pid 971102:tid 971311] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailing/.env"] [unique_id "aqxY_ucL08BTTQixEnp4rwAAAE0"]
[Thu Sep 17 15:17:51.042364 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxY_-cL08BTTQixEnp4sgAAAEs"]
[Thu Sep 17 15:17:51.051868 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/ses/.env"] [unique_id "aqxY_-cL08BTTQixEnp4swAAACA"]
[Thu Sep 17 15:17:51.101571 2026] [security2:error] [pid 971102:tid 971259] [client 34.154.67.31:51890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxY_-cL08BTTQixEnp4tAAAABk"]
[Thu Sep 17 15:17:51.139387 2026] [security2:error] [pid 971102:tid 971315] [client 116.111.164.228:38506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY_-cL08BTTQixEnp4sAAAUWU"]
[Thu Sep 17 15:17:51.172077 2026] [security2:error] [pid 971102:tid 971322] [client 185.213.175.37:38386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxY_-cL08BTTQixEnp4tQAAAFg"]
[Thu Sep 17 15:17:51.216994 2026] [security2:error] [pid 971102:tid 971285] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sendgrid/.env"] [unique_id "aqxY_-cL08BTTQixEnp4uAAAADM"]
[Thu Sep 17 15:17:51.240826 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.173.223:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php.save"] [unique_id "aqxY_-cL08BTTQixEnp4ugAAABg"]
[Thu Sep 17 15:17:51.277677 2026] [security2:error] [pid 971102:tid 971313] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxY_-cL08BTTQixEnp4uwAAAE8"]
[Thu Sep 17 15:17:51.377438 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sparkpost/.env"] [unique_id "aqxY_-cL08BTTQixEnp4vgAAAFs"]
[Thu Sep 17 15:17:51.440496 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/notifications/.env"] [unique_id "aqxY_-cL08BTTQixEnp4wAAAAD4"]
[Thu Sep 17 15:17:51.445927 2026] [security2:error] [pid 971102:tid 971243] [client 185.213.175.37:38386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxY_-cL08BTTQixEnp4wQAAAAk"]
[Thu Sep 17 15:17:51.507557 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxY_-cL08BTTQixEnp4wwAAAGY"]
[Thu Sep 17 15:17:51.533259 2026] [security2:error] [pid 971102:tid 971241] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/postmark/.env"] [unique_id "aqxY_-cL08BTTQixEnp4xQAAAAc"]
[Thu Sep 17 15:17:51.569108 2026] [security2:error] [pid 971102:tid 971358] [client 34.154.67.31:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxY_-cL08BTTQixEnp4xwAAAHw"]
[Thu Sep 17 15:17:51.588944 2026] [security2:error] [pid 971102:tid 971252] [client 185.213.175.37:38376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY_-cL08BTTQixEnp4yQAAABI"]
[Thu Sep 17 15:17:51.589064 2026] [security2:error] [pid 971102:tid 971252] [client 185.213.175.37:38376] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY_-cL08BTTQixEnp4yQAAABI"]
[Thu Sep 17 15:17:51.591097 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/notify/.env"] [unique_id "aqxY_-cL08BTTQixEnp4ywAAAA0"]
[Thu Sep 17 15:17:51.612533 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.218.131:55744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxY_-cL08BTTQixEnp4zQAAAEk"]
[Thu Sep 17 15:17:51.691051 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailgun/.env"] [unique_id "aqxY_-cL08BTTQixEnp40AAAAD0"]
[Thu Sep 17 15:17:51.725350 2026] [security2:error] [pid 971102:tid 971281] [client 185.213.175.37:38386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxY_-cL08BTTQixEnp40QAAAC8"]
[Thu Sep 17 15:17:51.727396 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.173.223:37318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxY_-cL08BTTQixEnp40gAAAE4"]
[Thu Sep 17 15:17:51.736609 2026] [security2:error] [pid 971102:tid 971289] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxY_-cL08BTTQixEnp41QAAADc"]
[Thu Sep 17 15:17:51.749982 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sender/.env"] [unique_id "aqxY_-cL08BTTQixEnp41gAAABY"]
[Thu Sep 17 15:17:51.852122 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mandrill/.env"] [unique_id "aqxY_-cL08BTTQixEnp41wAAAHI"]
[Thu Sep 17 15:17:51.916118 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/campaign/.env"] [unique_id "aqxY_-cL08BTTQixEnp42AAAADE"]
[Thu Sep 17 15:17:51.977349 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxY_-cL08BTTQixEnp42QAAAFk"]
[Thu Sep 17 15:17:52.017634 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailjet/.env"] [unique_id "aqxZAOcL08BTTQixEnp42gAAAHk"]
[Thu Sep 17 15:17:52.034710 2026] [security2:error] [pid 971102:tid 971234] [client 185.213.175.37:38396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.save"] [unique_id "aqxZAOcL08BTTQixEnp42wAAAAA"]
[Thu Sep 17 15:17:52.034815 2026] [security2:error] [pid 971102:tid 971234] [client 185.213.175.37:38396] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.save"] [unique_id "aqxZAOcL08BTTQixEnp42wAAAAA"]
[Thu Sep 17 15:17:52.045296 2026] [security2:error] [pid 971102:tid 971343] [client 34.154.67.31:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp43AAAAG0"]
[Thu Sep 17 15:17:52.069819 2026] [security2:error] [pid 971102:tid 971338] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/newsletter/.env"] [unique_id "aqxZAOcL08BTTQixEnp43QAAAGg"]
[Thu Sep 17 15:17:52.180493 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/brevo/.env"] [unique_id "aqxZAOcL08BTTQixEnp44wAAADA"]
[Thu Sep 17 15:17:52.182933 2026] [security2:error] [pid 971102:tid 971257] [client 185.213.175.37:38408] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.staging"] [unique_id "aqxZAOcL08BTTQixEnp45QAAABc"]
[Thu Sep 17 15:17:52.210255 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxZAOcL08BTTQixEnp46QAAAHA"]
[Thu Sep 17 15:17:52.220072 2026] [security2:error] [pid 971102:tid 971329] [client 34.95.173.223:37326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp47AAAAF8"]
[Thu Sep 17 15:17:52.223628 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/ses/.env"] [unique_id "aqxZAOcL08BTTQixEnp47QAAAFI"]
[Thu Sep 17 15:17:52.307017 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.218.131:55746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp48gAAAHM"]
[Thu Sep 17 15:17:52.321745 2026] [security2:error] [pid 971102:tid 971236] [client 185.213.175.37:38410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.test"] [unique_id "aqxZAOcL08BTTQixEnp48wAAAAI"]
[Thu Sep 17 15:17:52.321888 2026] [security2:error] [pid 971102:tid 971236] [client 185.213.175.37:38410] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.test"] [unique_id "aqxZAOcL08BTTQixEnp48wAAAAI"]
[Thu Sep 17 15:17:52.343468 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/transactional/.env"] [unique_id "aqxZAOcL08BTTQixEnp49AAAAF4"]
[Thu Sep 17 15:17:52.387192 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sendgrid/.env"] [unique_id "aqxZAOcL08BTTQixEnp49wAAAHE"]
[Thu Sep 17 15:17:52.443825 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxZAOcL08BTTQixEnp4-QAAACs"]
[Thu Sep 17 15:17:52.501589 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/bulk/.env"] [unique_id "aqxZAOcL08BTTQixEnp4-gAAABo"]
[Thu Sep 17 15:17:52.533749 2026] [security2:error] [pid 971102:tid 971267] [client 185.213.175.37:38422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.txt"] [unique_id "aqxZAOcL08BTTQixEnp4_wAAACE"]
[Thu Sep 17 15:17:52.543185 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sparkpost/.env"] [unique_id "aqxZAOcL08BTTQixEnp5AAAAACk"]
[Thu Sep 17 15:17:52.547114 2026] [security2:error] [pid 971102:tid 971306] [client 34.154.67.31:51914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp5AQAAAEg"]
[Thu Sep 17 15:17:52.662975 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/aws/.env"] [unique_id "aqxZAOcL08BTTQixEnp5AgAAACo"]
[Thu Sep 17 15:17:52.666895 2026] [security2:error] [pid 971102:tid 971266] [client 185.213.175.37:38408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app.env"] [unique_id "aqxZAOcL08BTTQixEnp5BAAAACA"]
[Thu Sep 17 15:17:52.674189 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxZAOcL08BTTQixEnp5BgAAAHo"]
[Thu Sep 17 15:17:52.708274 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/postmark/.env"] [unique_id "aqxZAOcL08BTTQixEnp5BwAAAFE"]
[Thu Sep 17 15:17:52.714950 2026] [security2:error] [pid 971102:tid 971354] [client 34.95.173.223:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp5CAAAAHg"]
[Thu Sep 17 15:17:52.818251 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/azure/.env"] [unique_id "aqxZAOcL08BTTQixEnp5DQAAACw"]
[Thu Sep 17 15:17:52.860814 2026] [security2:error] [pid 971102:tid 971258] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailgun/.env"] [unique_id "aqxZAOcL08BTTQixEnp5DgAAABg"]
[Thu Sep 17 15:17:52.901782 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxZAOcL08BTTQixEnp5EAAAABw"]
[Thu Sep 17 15:17:52.977446 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/gcp/.env"] [unique_id "aqxZAOcL08BTTQixEnp5EQAAAB4"]
[Thu Sep 17 15:17:52.992454 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.218.131:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp5FAAAAC0"]
[Thu Sep 17 15:17:53.019504 2026] [security2:error] [pid 971102:tid 971318] [client 34.154.67.31:51926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5FgAAAFQ"]
[Thu Sep 17 15:17:53.020265 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mandrill/.env"] [unique_id "aqxZAecL08BTTQixEnp5FQAAAFs"]
[Thu Sep 17 15:17:53.129249 2026] [security2:error] [pid 971102:tid 971243] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxZAecL08BTTQixEnp5GgAAAAk"]
[Thu Sep 17 15:17:53.129248 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cloud/.env"] [unique_id "aqxZAecL08BTTQixEnp5GQAAAD4"]
[Thu Sep 17 15:17:53.130084 2026] [security2:error] [pid 971102:tid 971271] [client 185.213.175.37:38436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/secrets.env"] [unique_id "aqxZAecL08BTTQixEnp5GwAAACU"]
[Thu Sep 17 15:17:53.130146 2026] [security2:error] [pid 971102:tid 971271] [client 185.213.175.37:38436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/secrets.env"] [unique_id "aqxZAecL08BTTQixEnp5GwAAACU"]
[Thu Sep 17 15:17:53.177435 2026] [security2:error] [pid 971102:tid 971241] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailjet/.env"] [unique_id "aqxZAecL08BTTQixEnp5HAAAAAc"]
[Thu Sep 17 15:17:53.202164 2026] [security2:error] [pid 971102:tid 971245] [client 34.95.173.223:37344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5HgAAAAs"]
[Thu Sep 17 15:17:53.213335 2026] [security2:error] [pid 971102:tid 971290] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.uat"] [unique_id "aqxZAecL08BTTQixEnp5HwAAADg"]
[Thu Sep 17 15:17:53.267574 2026] [security2:error] [pid 971102:tid 971293] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.orig"] [unique_id "aqxZAecL08BTTQixEnp5IwAAADs"]
[Thu Sep 17 15:17:53.280174 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/infrastructure/.env"] [unique_id "aqxZAecL08BTTQixEnp5JAAAAD0"]
[Thu Sep 17 15:17:53.330681 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/brevo/.env"] [unique_id "aqxZAecL08BTTQixEnp5JQAAAC8"]
[Thu Sep 17 15:17:53.362806 2026] [security2:error] [pid 971102:tid 971289] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxZAecL08BTTQixEnp5JgAAADc"]
[Thu Sep 17 15:17:53.403423 2026] [security2:error] [pid 971102:tid 971344] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.copy"] [unique_id "aqxZAecL08BTTQixEnp5JwAAAG4"]
[Thu Sep 17 15:17:53.446793 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/docker/.env"] [unique_id "aqxZAecL08BTTQixEnp5KAAAAH4"]
[Thu Sep 17 15:17:53.484672 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/transactional/.env"] [unique_id "aqxZAecL08BTTQixEnp5KQAAAGI"]
[Thu Sep 17 15:17:53.506950 2026] [security2:error] [pid 971102:tid 971312] [client 34.154.67.31:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5KgAAAE4"]
[Thu Sep 17 15:17:53.599491 2026] [security2:error] [pid 971102:tid 971321] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxZAecL08BTTQixEnp5LAAAAFc"]
[Thu Sep 17 15:17:53.622538 2026] [security2:error] [pid 971102:tid 971299] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/k8s/.env"] [unique_id "aqxZAecL08BTTQixEnp5LQAAAEE"]
[Thu Sep 17 15:17:53.646440 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/bulk/.env"] [unique_id "aqxZAecL08BTTQixEnp5LwAAAEo"]
[Thu Sep 17 15:17:53.679304 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.218.131:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5MwAAABA"]
[Thu Sep 17 15:17:53.691080 2026] [security2:error] [pid 971102:tid 971305] [client 34.95.173.223:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5NAAAAEc"]
[Thu Sep 17 15:17:53.779340 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/kubernetes/.env"] [unique_id "aqxZAecL08BTTQixEnp5NgAAAHk"]
[Thu Sep 17 15:17:53.800951 2026] [security2:error] [pid 971102:tid 971353] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/aws/.env"] [unique_id "aqxZAecL08BTTQixEnp5OQAAAHc"]
[Thu Sep 17 15:17:53.828495 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxZAecL08BTTQixEnp5OgAAAEY"]
[Thu Sep 17 15:17:53.841774 2026] [security2:error] [pid 971102:tid 971346] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.local.bak"] [unique_id "aqxZAecL08BTTQixEnp5PQAAAHA"]
[Thu Sep 17 15:17:53.936085 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/terraform/.env"] [unique_id "aqxZAecL08BTTQixEnp5QAAAAAU"]
[Thu Sep 17 15:17:53.954840 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/azure/.env"] [unique_id "aqxZAecL08BTTQixEnp5QgAAAF4"]
[Thu Sep 17 15:17:53.989003 2026] [security2:error] [pid 971102:tid 971303] [client 34.154.67.31:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5RAAAAEU"]
[Thu Sep 17 15:17:54.065621 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxZAucL08BTTQixEnp5RQAAAAo"]
[Thu Sep 17 15:17:54.100827 2026] [security2:error] [pid 971102:tid 971319] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/ansible/.env"] [unique_id "aqxZAucL08BTTQixEnp5RwAAAFU"]
[Thu Sep 17 15:17:54.111678 2026] [security2:error] [pid 971102:tid 971347] [client 185.213.175.37:38438] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.staging.local"] [unique_id "aqxZAucL08BTTQixEnp5SAAAAHE"]
[Thu Sep 17 15:17:54.111734 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/gcp/.env"] [unique_id "aqxZAucL08BTTQixEnp5SQAAACs"]
[Thu Sep 17 15:17:54.198128 2026] [security2:error] [pid 971102:tid 971263] [client 34.95.173.223:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5TQAAAB0"]
[Thu Sep 17 15:17:54.265396 2026] [security2:error] [pid 971102:tid 971260] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.prod.bak"] [unique_id "aqxZAucL08BTTQixEnp5TgAAABo"]
[Thu Sep 17 15:17:54.267355 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.git/.env"] [unique_id "aqxZAucL08BTTQixEnp5TwAAAHU"]
[Thu Sep 17 15:17:54.271303 2026] [security2:error] [pid 971102:tid 971267] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cloud/.env"] [unique_id "aqxZAucL08BTTQixEnp5UAAAACE"]
[Thu Sep 17 15:17:54.301306 2026] [security2:error] [pid 971102:tid 971275] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxZAucL08BTTQixEnp5UgAAACk"]
[Thu Sep 17 15:17:54.381181 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.218.131:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5VAAAAEI"]
[Thu Sep 17 15:17:54.432322 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/infrastructure/.env"] [unique_id "aqxZAucL08BTTQixEnp5VwAAAFA"]
[Thu Sep 17 15:17:54.443054 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/ci/.env"] [unique_id "aqxZAucL08BTTQixEnp5WAAAAFE"]
[Thu Sep 17 15:17:54.467641 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5WgAAACQ"]
[Thu Sep 17 15:17:54.489554 2026] [security2:error] [pid 971102:tid 971249] [client 66.249.66.199:40488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nlfephrata.org"] [uri "/index.php"] [unique_id "aqxZAucL08BTTQixEnp5UQAAAA8"]
[Thu Sep 17 15:17:54.533040 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxZAucL08BTTQixEnp5XAAAAFw"]
[Thu Sep 17 15:17:54.542960 2026] [security2:error] [pid 971102:tid 971361] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.development.old"] [unique_id "aqxZAucL08BTTQixEnp5XQAAAH8"]
[Thu Sep 17 15:17:54.595579 2026] [security2:error] [pid 971102:tid 971333] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/docker/.env"] [unique_id "aqxZAucL08BTTQixEnp5YAAAAGM"]
[Thu Sep 17 15:17:54.606790 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cd/.env"] [unique_id "aqxZAucL08BTTQixEnp5YQAAABU"]
[Thu Sep 17 15:17:54.670526 2026] [security2:error] [pid 971102:tid 971318] [client 185.213.175.37:38438] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker.env"] [unique_id "aqxZAucL08BTTQixEnp5YgAAAFQ"]
[Thu Sep 17 15:17:54.684557 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.173.223:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5YwAAADw"]
[Thu Sep 17 15:17:54.761807 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/k8s/.env"] [unique_id "aqxZAucL08BTTQixEnp5agAAAAs"]
[Thu Sep 17 15:17:54.768610 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/jenkins/.env"] [unique_id "aqxZAucL08BTTQixEnp5awAAABI"]
[Thu Sep 17 15:17:54.768620 2026] [security2:error] [pid 971102:tid 971290] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxZAucL08BTTQixEnp5bAAAADg"]
[Thu Sep 17 15:17:54.924910 2026] [security2:error] [pid 971102:tid 971331] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxZAucL08BTTQixEnp5bgAAAGE"]
[Thu Sep 17 15:17:54.924933 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/kubernetes/.env"] [unique_id "aqxZAucL08BTTQixEnp5bwAAADo"]
[Thu Sep 17 15:17:54.929615 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxZAucL08BTTQixEnp5cAAAACc"], referer: binance.com
[Thu Sep 17 15:17:54.942502 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/gitlab/.env"] [unique_id "aqxZAucL08BTTQixEnp5cQAAAG4"]
[Thu Sep 17 15:17:54.954770 2026] [security2:error] [pid 971102:tid 971358] [client 34.154.67.31:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5cgAAAHw"]
[Thu Sep 17 15:17:55.002205 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxZA-cL08BTTQixEnp5cwAAAA0"]
[Thu Sep 17 15:17:55.063716 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxZA-cL08BTTQixEnp5dQAAAHI"]
[Thu Sep 17 15:17:55.070454 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.218.131:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5dgAAAGQ"]
[Thu Sep 17 15:17:55.097488 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/terraform/.env"] [unique_id "aqxZA-cL08BTTQixEnp5dwAAAGI"]
[Thu Sep 17 15:17:55.100549 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/github/.env"] [unique_id "aqxZA-cL08BTTQixEnp5eAAAAE4"]
[Thu Sep 17 15:17:55.132623 2026] [security2:error] [pid 971102:tid 971265] [client 45.169.98.18:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5eQAAAB8"]
[Thu Sep 17 15:17:55.132757 2026] [security2:error] [pid 971102:tid 971265] [client 45.169.98.18:60915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5eQAAAB8"]
[Thu Sep 17 15:17:55.189266 2026] [security2:error] [pid 971102:tid 971360] [client 34.95.173.223:37714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5fgAAAH4"]
[Thu Sep 17 15:17:55.207386 2026] [security2:error] [pid 971102:tid 971323] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxZA-cL08BTTQixEnp5gQAAAFk"]
[Thu Sep 17 15:17:55.207486 2026] [security2:error] [pid 971102:tid 971323] [client 185.213.175.37:38438] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxZA-cL08BTTQixEnp5gQAAAFk"]
[Thu Sep 17 15:17:55.229847 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxZA-cL08BTTQixEnp5gwAAAGk"]
[Thu Sep 17 15:17:55.257885 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/ansible/.env"] [unique_id "aqxZA-cL08BTTQixEnp5hAAAAEM"]
[Thu Sep 17 15:17:55.262561 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/actions/.env"] [unique_id "aqxZA-cL08BTTQixEnp5hQAAAEc"]
[Thu Sep 17 15:17:55.344726 2026] [security2:error] [pid 971102:tid 971353] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxZA-cL08BTTQixEnp5hwAAAHc"]
[Thu Sep 17 15:17:55.415859 2026] [security2:error] [pid 971102:tid 971287] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.git/.env"] [unique_id "aqxZA-cL08BTTQixEnp5iQAAADU"]
[Thu Sep 17 15:17:55.419354 2026] [security2:error] [pid 971102:tid 971280] [client 34.154.67.31:51984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5igAAAC4"]
[Thu Sep 17 15:17:55.420091 2026] [authz_core:error] [pid 971102:tid 971299] [client 172.239.147.162:51966] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:55.424510 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/circleci/.env"] [unique_id "aqxZA-cL08BTTQixEnp5iwAAAAU"]
[Thu Sep 17 15:17:55.465686 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jAAAAEU"]
[Thu Sep 17 15:17:55.482923 2026] [security2:error] [pid 971102:tid 971329] [client 185.213.175.37:38444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/admin/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jQAAAF8"]
[Thu Sep 17 15:17:55.589868 2026] [security2:error] [pid 971102:tid 971244] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/ci/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jgAAAAo"]
[Thu Sep 17 15:17:55.611305 2026] [security2:error] [pid 971102:tid 971319] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/travis/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jwAAAFU"]
[Thu Sep 17 15:17:55.635582 2026] [security2:error] [pid 971102:tid 971272] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config"] [unique_id "aqxZA-cL08BTTQixEnp5kQAAACY"]
[Thu Sep 17 15:17:55.676211 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.173.223:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5lQAAAAE"]
[Thu Sep 17 15:17:55.696554 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxZA-cL08BTTQixEnp5lgAAAHU"]
[Thu Sep 17 15:17:55.752706 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cd/.env"] [unique_id "aqxZA-cL08BTTQixEnp5lwAAACk"]
[Thu Sep 17 15:17:55.763258 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.218.131:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5mAAAADI"]
[Thu Sep 17 15:17:55.780716 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/buildkite/.env"] [unique_id "aqxZA-cL08BTTQixEnp5mwAAAEI"]
[Thu Sep 17 15:17:55.818238 2026] [security2:error] [pid 971102:tid 971286] [client 185.55.149.49:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5nAAAADQ"]
[Thu Sep 17 15:17:55.818342 2026] [security2:error] [pid 971102:tid 971286] [client 185.55.149.49:53496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5nAAAADQ"]
[Thu Sep 17 15:17:55.903335 2026] [security2:error] [pid 971102:tid 971267] [client 34.154.67.31:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5nwAAACE"]
[Thu Sep 17 15:17:55.929652 2026] [security2:error] [pid 971102:tid 971297] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/jenkins/.env"] [unique_id "aqxZA-cL08BTTQixEnp5oQAAAD8"]
[Thu Sep 17 15:17:55.930844 2026] [security2:error] [pid 971102:tid 971270] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxZA-cL08BTTQixEnp5ogAAACQ"]
[Thu Sep 17 15:17:55.931458 2026] [security2:error] [pid 971102:tid 971259] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.js"] [unique_id "aqxZA-cL08BTTQixEnp5owAAABk"]
[Thu Sep 17 15:17:55.949109 2026] [security2:error] [pid 971102:tid 971311] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mysql/.env"] [unique_id "aqxZA-cL08BTTQixEnp5pAAAAE0"]
[Thu Sep 17 15:17:56.060046 2026] [security2:error] [pid 971102:tid 971253] [client 185.213.175.37:38444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.js"] [unique_id "aqxZBOcL08BTTQixEnp5pQAAABM"]
[Thu Sep 17 15:17:56.089355 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/gitlab/.env"] [unique_id "aqxZBOcL08BTTQixEnp5pwAAACo"]
[Thu Sep 17 15:17:56.112056 2026] [security2:error] [pid 971102:tid 971337] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/postgres/.env"] [unique_id "aqxZBOcL08BTTQixEnp5qAAAAGc"]
[Thu Sep 17 15:17:56.161890 2026] [security2:error] [pid 971102:tid 971350] [client 34.95.173.223:37730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZBOcL08BTTQixEnp5qwAAAHQ"]
[Thu Sep 17 15:17:56.163298 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxZBOcL08BTTQixEnp5rAAAABw"]
[Thu Sep 17 15:17:56.201284 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.py"] [unique_id "aqxZBOcL08BTTQixEnp5rQAAABQ"]
[Thu Sep 17 15:17:56.225856 2026] [security2:error] [pid 971102:tid 971217] [remote 110.249.201.128:65354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/better-watch-out-better-not-cry-ken-ham-is-coming-to-town-part-1/"] [unique_id "aqxZBOcL08BTTQixEnp5rwAAG3A"]
[Thu Sep 17 15:17:56.259132 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/github/.env"] [unique_id "aqxZBOcL08BTTQixEnp5sAAAAD4"]
[Thu Sep 17 15:17:56.275043 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mongodb/.env"] [unique_id "aqxZBOcL08BTTQixEnp5sQAAAFY"]
[Thu Sep 17 15:17:56.396892 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxZBOcL08BTTQixEnp5twAAAC8"]
[Thu Sep 17 15:17:56.425618 2026] [security2:error] [pid 971102:tid 971293] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/actions/.env"] [unique_id "aqxZBOcL08BTTQixEnp5uAAAADs"]
[Thu Sep 17 15:17:56.441941 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/redis/.env"] [unique_id "aqxZBOcL08BTTQixEnp5uQAAABY"]
[Thu Sep 17 15:17:56.452407 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZBOcL08BTTQixEnp5ugAAADw"]
[Thu Sep 17 15:17:56.549304 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp5vAAAAE8"]
[Thu Sep 17 15:17:56.549453 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp5vAAAAE8"]
[Thu Sep 17 15:17:56.588200 2026] [security2:error] [pid 971102:tid 971269] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/circleci/.env"] [unique_id "aqxZBOcL08BTTQixEnp5vQAAACM"]
[Thu Sep 17 15:17:56.598819 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZBOcL08BTTQixEnp5vwAAAGE"]
[Thu Sep 17 15:17:56.627198 2026] [security2:error] [pid 971102:tid 971344] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxZBOcL08BTTQixEnp5wAAAAG4"]
[Thu Sep 17 15:17:56.652221 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.173.223:37732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZBOcL08BTTQixEnp5wgAAAAk"]
[Thu Sep 17 15:17:56.741119 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/travis/.env"] [unique_id "aqxZBOcL08BTTQixEnp5xgAAAE4"]
[Thu Sep 17 15:17:56.755376 2026] [security2:error] [pid 971102:tid 971265] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZBOcL08BTTQixEnp5yAAAAB8"]
[Thu Sep 17 15:17:56.857598 2026] [security2:error] [pid 971102:tid 971291] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxZBOcL08BTTQixEnp5zAAAADk"]
[Thu Sep 17 15:17:56.899042 2026] [security2:error] [pid 971102:tid 971343] [client 185.213.175.37:38444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config/production.json"] [unique_id "aqxZBOcL08BTTQixEnp5zgAAAG0"]
[Thu Sep 17 15:17:56.902844 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/buildkite/.env"] [unique_id "aqxZBOcL08BTTQixEnp50QAAAEY"]
[Thu Sep 17 15:17:56.904792 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:42140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp50wAAADY"]
[Thu Sep 17 15:17:56.911814 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:42140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp50wAAADY"]
[Thu Sep 17 15:17:56.923049 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/kafka/.env"] [unique_id "aqxZBOcL08BTTQixEnp51AAAAGw"]
[Thu Sep 17 15:17:56.990788 2026] [security2:error] [pid 971102:tid 971358] [client 210.222.43.21:63746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZBOcL08BTTQixEnp5ywAAAHw"], referer: http://talent-in-borders.com/main
[Thu Sep 17 15:17:57.039006 2026] [security2:error] [pid 971102:tid 971346] [client 194.46.238.145:59884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZBOcL08BTTQixEnp51QAAcFY"]
[Thu Sep 17 15:17:57.057482 2026] [security2:error] [pid 971102:tid 971299] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mysql/.env"] [unique_id "aqxZBecL08BTTQixEnp52QAAAEE"]
[Thu Sep 17 15:17:57.085029 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxZBecL08BTTQixEnp52wAAAEo"]
[Thu Sep 17 15:17:57.085037 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/queue/.env"] [unique_id "aqxZBecL08BTTQixEnp53AAAAF4"]
[Thu Sep 17 15:17:57.129565 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.218.131:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp53gAAADA"]
[Thu Sep 17 15:17:57.150443 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.173.223:37742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp54QAAADU"]
[Thu Sep 17 15:17:57.194439 2026] [authz_core:error] [pid 971102:tid 971280] [client 172.239.147.162:64024] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:57.209808 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/postgres/.env"] [unique_id "aqxZBecL08BTTQixEnp56AAAAB0"]
[Thu Sep 17 15:17:57.236174 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/worker/.env"] [unique_id "aqxZBecL08BTTQixEnp56QAAAAE"]
[Thu Sep 17 15:17:57.312299 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxZBecL08BTTQixEnp57QAAAHo"]
[Thu Sep 17 15:17:57.371026 2026] [security2:error] [pid 971102:tid 971297] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mongodb/.env"] [unique_id "aqxZBecL08BTTQixEnp58AAAAD8"]
[Thu Sep 17 15:17:57.400783 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/job/.env"] [unique_id "aqxZBecL08BTTQixEnp58QAAACQ"]
[Thu Sep 17 15:17:57.531714 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/redis/.env"] [unique_id "aqxZBecL08BTTQixEnp5-AAAACw"]
[Thu Sep 17 15:17:57.539664 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxZBecL08BTTQixEnp5-gAAAFw"]
[Thu Sep 17 15:17:57.560647 2026] [security2:error] [pid 971102:tid 971361] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/test/.env"] [unique_id "aqxZBecL08BTTQixEnp5-wAAAH8"]
[Thu Sep 17 15:17:57.633203 2026] [security2:error] [pid 971102:tid 971324] [client 34.95.173.223:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp5_gAAAFo"]
[Thu Sep 17 15:17:57.682124 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZBecL08BTTQixEnp6AgAAAFs"]
[Thu Sep 17 15:17:57.718115 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/qa/.env"] [unique_id "aqxZBecL08BTTQixEnp6BAAAAFY"]
[Thu Sep 17 15:17:57.768816 2026] [security2:error] [pid 971102:tid 971241] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxZBecL08BTTQixEnp6BQAAAAc"]
[Thu Sep 17 15:17:57.808674 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.218.131:55802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp6BgAAACo"]
[Thu Sep 17 15:17:57.837853 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZBecL08BTTQixEnp6BwAAAD0"]
[Thu Sep 17 15:17:57.850116 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBecL08BTTQixEnp6CAAAAGo"]
[Thu Sep 17 15:17:57.850201 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:56402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBecL08BTTQixEnp6CAAAAGo"]
[Thu Sep 17 15:17:57.878142 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/preview/.env"] [unique_id "aqxZBecL08BTTQixEnp6CgAAAC8"]
[Thu Sep 17 15:17:57.992842 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/kafka/.env"] [unique_id "aqxZBecL08BTTQixEnp6DgAAABY"]
[Thu Sep 17 15:17:58.004116 2026] [security2:error] [pid 971102:tid 971294] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxZBucL08BTTQixEnp6DwAAADw"]
[Thu Sep 17 15:17:58.073711 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/beta/.env"] [unique_id "aqxZBucL08BTTQixEnp6EgAAAGE"]
[Thu Sep 17 15:17:58.120018 2026] [security2:error] [pid 971102:tid 971293] [client 34.95.173.223:37752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZBucL08BTTQixEnp6FAAAADs"]
[Thu Sep 17 15:17:58.146195 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/serviceAccountKey.json"] [unique_id "aqxZBucL08BTTQixEnp6FQAAAHI"]
[Thu Sep 17 15:17:58.148040 2026] [security2:error] [pid 971102:tid 971345] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/queue/.env"] [unique_id "aqxZBucL08BTTQixEnp6FgAAAG8"]
[Thu Sep 17 15:17:58.235842 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/uat/.env"] [unique_id "aqxZBucL08BTTQixEnp6GQAAAE4"]
[Thu Sep 17 15:17:58.239079 2026] [security2:error] [pid 971102:tid 971265] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxZBucL08BTTQixEnp6GgAAAB8"]
[Thu Sep 17 15:17:58.313904 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/worker/.env"] [unique_id "aqxZBucL08BTTQixEnp6GwAAAHs"]
[Thu Sep 17 15:17:58.393580 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/stage/.env"] [unique_id "aqxZBucL08BTTQixEnp6IQAAAEc"]
[Thu Sep 17 15:17:58.469368 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/job/.env"] [unique_id "aqxZBucL08BTTQixEnp6JQAAADY"]
[Thu Sep 17 15:17:58.472445 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxZBucL08BTTQixEnp6JwAAAAY"]
[Thu Sep 17 15:17:58.506208 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.218.131:55814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZBucL08BTTQixEnp6KAAAAH4"]
[Thu Sep 17 15:17:58.550461 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/development/.env"] [unique_id "aqxZBucL08BTTQixEnp6KQAAAFI"]
[Thu Sep 17 15:17:58.627115 2026] [security2:error] [pid 971102:tid 971346] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/test/.env"] [unique_id "aqxZBucL08BTTQixEnp6LAAAAHA"]
[Thu Sep 17 15:17:58.700385 2026] [security2:error] [pid 971102:tid 971236] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxZBucL08BTTQixEnp6MAAAAAI"]
[Thu Sep 17 15:17:58.703844 2026] [security2:error] [pid 971102:tid 971280] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/production/.env"] [unique_id "aqxZBucL08BTTQixEnp6MgAAAC4"]
[Thu Sep 17 15:17:58.720892 2026] [security2:error] [pid 971102:tid 971341] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.git/HEAD"] [unique_id "aqxZBucL08BTTQixEnp6MwAAAGs"]
[Thu Sep 17 15:17:58.784851 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/qa/.env"] [unique_id "aqxZBucL08BTTQixEnp6NQAAAAE"]
[Thu Sep 17 15:17:58.857097 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/config/app/.env"] [unique_id "aqxZBucL08BTTQixEnp6OAAAAFA"]
[Thu Sep 17 15:17:58.928986 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxZBucL08BTTQixEnp6OwAAAEg"]
[Thu Sep 17 15:17:58.935672 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/preview/.env"] [unique_id "aqxZBucL08BTTQixEnp6PAAAACQ"]
[Thu Sep 17 15:17:59.018216 2026] [security2:error] [pid 971102:tid 971319] [client 34.151.157.242:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6RQAAAFU"]
[Thu Sep 17 15:17:59.027854 2026] [security2:error] [pid 971102:tid 971284] [client 185.213.175.37:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/wp-config.php"] [unique_id "aqxZBucL08BTTQixEnp6PwAAADI"]
[Thu Sep 17 15:17:59.086371 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/beta/.env"] [unique_id "aqxZB-cL08BTTQixEnp6SAAAABM"]
[Thu Sep 17 15:17:59.131274 2026] [security2:error] [pid 971102:tid 971309] [client 185.213.175.37:38444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/wp-config.php.bak"] [unique_id "aqxZB-cL08BTTQixEnp6SwAAAEs"]
[Thu Sep 17 15:17:59.193308 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.218.131:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6TwAAAE0"]
[Thu Sep 17 15:17:59.237781 2026] [security2:error] [pid 971102:tid 971359] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/uat/.env"] [unique_id "aqxZB-cL08BTTQixEnp6UgAAAH0"]
[Thu Sep 17 15:17:59.389047 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/stage/.env"] [unique_id "aqxZB-cL08BTTQixEnp6VQAAADo"]
[Thu Sep 17 15:17:59.405184 2026] [security2:error] [pid 971102:tid 971295] [client 200.104.130.167:38298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZB-cL08BTTQixEnp6UwAAPSo"]
[Thu Sep 17 15:17:59.440264 2026] [authz_core:error] [pid 971102:tid 971245] [client 172.239.147.162:49436] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:17:59.477157 2026] [security2:error] [pid 971102:tid 971294] [client 34.151.157.242:39118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/info.php"] [unique_id "aqxZB-cL08BTTQixEnp6WQAAADw"]
[Thu Sep 17 15:17:59.540708 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/development/.env"] [unique_id "aqxZB-cL08BTTQixEnp6XQAAAEk"]
[Thu Sep 17 15:17:59.602853 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config/database.yml"] [unique_id "aqxZB-cL08BTTQixEnp6XgAAAHI"]
[Thu Sep 17 15:17:59.611300 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxZB-cL08BTTQixEnp6XwAAACM"]
[Thu Sep 17 15:17:59.692118 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/production/.env"] [unique_id "aqxZB-cL08BTTQixEnp6ZAAAAEc"]
[Thu Sep 17 15:17:59.738186 2026] [security2:error] [pid 971102:tid 971355] [client 185.213.175.37:44048] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker-compose.yml"] [unique_id "aqxZB-cL08BTTQixEnp6ZgAAAHk"]
[Thu Sep 17 15:17:59.821740 2026] [security2:error] [pid 971102:tid 971291] [client 172.239.147.162:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxZB-cL08BTTQixEnp6aQAAADk"], referer: binance.com
[Thu Sep 17 15:17:59.838479 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxZB-cL08BTTQixEnp6agAAAEY"]
[Thu Sep 17 15:17:59.842927 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/config/app/.env"] [unique_id "aqxZB-cL08BTTQixEnp6awAAAGw"]
[Thu Sep 17 15:17:59.876718 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.218.131:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6bQAAAFM"]
[Thu Sep 17 15:17:59.907651 2026] [security2:error] [pid 971102:tid 971302] [client 185.213.175.37:44048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/config"] [unique_id "aqxZB-cL08BTTQixEnp6bgAAAEQ"]
[Thu Sep 17 15:17:59.907793 2026] [security2:error] [pid 971102:tid 971302] [client 185.213.175.37:44048] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/config"] [unique_id "aqxZB-cL08BTTQixEnp6bgAAAEQ"]
[Thu Sep 17 15:17:59.927557 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:39124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/php.php"] [unique_id "aqxZB-cL08BTTQixEnp6bwAAAAA"]
[Thu Sep 17 15:17:59.992677 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:50394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6dAAAAG0"]
[Thu Sep 17 15:18:00.065261 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxZCOcL08BTTQixEnp6dQAAAHA"]
[Thu Sep 17 15:18:00.076703 2026] [security2:error] [pid 971102:tid 971310] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/settings"] [unique_id "aqxZCOcL08BTTQixEnp6dgAAAEw"]
[Thu Sep 17 15:18:00.247947 2026] [security2:error] [pid 971102:tid 971263] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/v1/config"] [unique_id "aqxZCOcL08BTTQixEnp6ewAAAB0"]
[Thu Sep 17 15:18:00.293935 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxZCOcL08BTTQixEnp6fAAAAEI"]
[Thu Sep 17 15:18:00.390501 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:39134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/i.php"] [unique_id "aqxZCOcL08BTTQixEnp6fgAAAGs"]
[Thu Sep 17 15:18:00.425483 2026] [security2:error] [pid 971102:tid 971244] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/v1/settings"] [unique_id "aqxZCOcL08BTTQixEnp6fwAAAAo"]
[Thu Sep 17 15:18:00.452127 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:39140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/info.php"] [unique_id "aqxZCOcL08BTTQixEnp6gAAAAHU"]
[Thu Sep 17 15:18:00.476376 2026] [security2:error] [pid 971102:tid 971328] [client 186.105.232.15:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6gQAAAF4"]
[Thu Sep 17 15:18:00.476477 2026] [security2:error] [pid 971102:tid 971328] [client 186.105.232.15:56486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6gQAAAF4"]
[Thu Sep 17 15:18:00.528050 2026] [security2:error] [pid 971102:tid 971354] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxZCOcL08BTTQixEnp6hgAAAHg"]
[Thu Sep 17 15:18:00.570997 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZCOcL08BTTQixEnp6hwAAADU"]
[Thu Sep 17 15:18:00.606704 2026] [security2:error] [pid 971102:tid 971284] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/openapi.json"] [unique_id "aqxZCOcL08BTTQixEnp6iAAAADI"]
[Thu Sep 17 15:18:00.758936 2026] [security2:error] [pid 971102:tid 971327] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxZCOcL08BTTQixEnp6jQAAAF0"]
[Thu Sep 17 15:18:00.799023 2026] [security2:error] [pid 971102:tid 971296] [client 185.213.175.37:44058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/id_rsa"] [unique_id "aqxZCOcL08BTTQixEnp6jgAAAD4"]
[Thu Sep 17 15:18:00.849787 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:39154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/pi.php"] [unique_id "aqxZCOcL08BTTQixEnp6kAAAAEs"]
[Thu Sep 17 15:18:00.862750 2026] [security2:error] [pid 971102:tid 971238] [client 156.192.234.52:53201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6kgAAAAQ"]
[Thu Sep 17 15:18:00.863428 2026] [security2:error] [pid 971102:tid 971238] [client 156.192.234.52:53201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6kgAAAAQ"]
[Thu Sep 17 15:18:00.902852 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:39168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/php.php"] [unique_id "aqxZCOcL08BTTQixEnp6kwAAAFo"]
[Thu Sep 17 15:18:00.985239 2026] [security2:error] [pid 971102:tid 971322] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxZCOcL08BTTQixEnp6lQAAAFg"]
[Thu Sep 17 15:18:00.985769 2026] [security2:error] [pid 971102:tid 971340] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/id_ed25519"] [unique_id "aqxZCOcL08BTTQixEnp6lAAAAGo"]
[Thu Sep 17 15:18:00.995412 2026] [authz_core:error] [pid 971102:tid 971261] [client 172.239.147.162:51958] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:01.211168 2026] [security2:error] [pid 971102:tid 971344] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxZCecL08BTTQixEnp6oQAAAG4"]
[Thu Sep 17 15:18:01.251382 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.218.131:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZCecL08BTTQixEnp6ogAAACk"]
[Thu Sep 17 15:18:01.301598 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:39184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/pinfo.php"] [unique_id "aqxZCecL08BTTQixEnp6pQAAAFY"]
[Thu Sep 17 15:18:01.357078 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/i.php"] [unique_id "aqxZCecL08BTTQixEnp6qAAAAAk"]
[Thu Sep 17 15:18:01.393538 2026] [security2:error] [pid 971102:tid 971269] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/log"] [unique_id "aqxZCecL08BTTQixEnp6qQAAACM"]
[Thu Sep 17 15:18:01.441276 2026] [security2:error] [pid 971102:tid 971312] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxZCecL08BTTQixEnp6qgAAAE4"]
[Thu Sep 17 15:18:01.672530 2026] [security2:error] [pid 971102:tid 971332] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxZCecL08BTTQixEnp6sgAAAGI"]
[Thu Sep 17 15:18:01.787666 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:39198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/test.php"] [unique_id "aqxZCecL08BTTQixEnp6tgAAAGw"]
[Thu Sep 17 15:18:01.830727 2026] [security2:error] [pid 971102:tid 971339] [client 34.151.157.242:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/pi.php"] [unique_id "aqxZCecL08BTTQixEnp6uAAAAGk"]
[Thu Sep 17 15:18:01.843322 2026] [security2:error] [pid 971102:tid 971234] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app.log"] [unique_id "aqxZCecL08BTTQixEnp6uQAAAAA"]
[Thu Sep 17 15:18:01.900222 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxZCecL08BTTQixEnp6ugAAAG0"]
[Thu Sep 17 15:18:02.128085 2026] [security2:error] [pid 971102:tid 971255] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxZCucL08BTTQixEnp6wgAAABU"]
[Thu Sep 17 15:18:02.234563 2026] [security2:error] [pid 971102:tid 971308] [client 172.239.147.162:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxZCucL08BTTQixEnp6yQAAAEo"], referer: binance.com
[Thu Sep 17 15:18:02.281133 2026] [security2:error] [pid 971102:tid 971328] [client 62.113.113.162:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.113.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/thank_you.php"] [unique_id "aqxZCucL08BTTQixEnp6zAAAAF4"], referer: http://chicagolandexteriorsinc.com/thank_you.php
[Thu Sep 17 15:18:02.285842 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/pinfo.php"] [unique_id "aqxZCucL08BTTQixEnp6zgAAAEI"]
[Thu Sep 17 15:18:02.309302 2026] [security2:error] [pid 971102:tid 971306] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/_profiler/phpinfo"] [unique_id "aqxZCucL08BTTQixEnp6zwAAAEg"]
[Thu Sep 17 15:18:02.315604 2026] [security2:error] [pid 971102:tid 971314] [client 172.239.147.162:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxZCucL08BTTQixEnp60AAAAFA"], referer: binance.com
[Thu Sep 17 15:18:02.354920 2026] [security2:error] [pid 971102:tid 971270] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxZCucL08BTTQixEnp60QAAACQ"]
[Thu Sep 17 15:18:02.401593 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZCucL08BTTQixEnp6zQAAAAg"]
[Thu Sep 17 15:18:02.585167 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxZCucL08BTTQixEnp62AAAAFw"]
[Thu Sep 17 15:18:02.717447 2026] [security2:error] [pid 971102:tid 971350] [client 34.151.157.242:39220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/p.php"] [unique_id "aqxZCucL08BTTQixEnp63wAAAHQ"]
[Thu Sep 17 15:18:02.750569 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/test.php"] [unique_id "aqxZCucL08BTTQixEnp64gAAAF0"]
[Thu Sep 17 15:18:02.819081 2026] [security2:error] [pid 971102:tid 971318] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxZCucL08BTTQixEnp65QAAAFQ"]
[Thu Sep 17 15:18:02.830837 2026] [security2:error] [pid 971102:tid 971335] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/dump.sql"] [unique_id "aqxZCucL08BTTQixEnp65gAAAGU"]
[Thu Sep 17 15:18:03.050713 2026] [security2:error] [pid 971102:tid 971293] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxZC-cL08BTTQixEnp66gAAADs"]
[Thu Sep 17 15:18:03.063015 2026] [security2:error] [pid 971102:tid 971272] [client 62.113.113.162:64151] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "62.113.113.162" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "chicagolandexteriorsinc.com"] [uri "/contact.php"] [unique_id "aqxZC-cL08BTTQixEnp66wAAACY"], referer: http://chicagolandexteriorsinc.com/contact.php
[Thu Sep 17 15:18:03.172701 2026] [security2:error] [pid 971102:tid 971345] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backup.sql"] [unique_id "aqxZC-cL08BTTQixEnp68wAAAG8"]
[Thu Sep 17 15:18:03.177972 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:54498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/debug.php"] [unique_id "aqxZC-cL08BTTQixEnp69AAAACk"]
[Thu Sep 17 15:18:03.277822 2026] [security2:error] [pid 971102:tid 971257] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxZC-cL08BTTQixEnp6-gAAABc"]
[Thu Sep 17 15:18:03.356733 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZC-cL08BTTQixEnp6-QAAAE4"]
[Thu Sep 17 15:18:03.451478 2026] [security2:error] [pid 971102:tid 971321] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/db.sql"] [unique_id "aqxZC-cL08BTTQixEnp6_QAAAFc"]
[Thu Sep 17 15:18:03.509284 2026] [security2:error] [pid 971102:tid 971333] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxZC-cL08BTTQixEnp6_wAAAGM"]
[Thu Sep 17 15:18:03.643064 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZC-cL08BTTQixEnp7BQAAAGA"]
[Thu Sep 17 15:18:03.663815 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/p.php"] [unique_id "aqxZC-cL08BTTQixEnp7BgAAADE"]
[Thu Sep 17 15:18:03.761281 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxZC-cL08BTTQixEnp7DAAAAAo"]
[Thu Sep 17 15:18:03.764001 2026] [security2:error] [pid 971102:tid 971351] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/database.sql"] [unique_id "aqxZC-cL08BTTQixEnp7DQAAAHU"]
[Thu Sep 17 15:18:03.845345 2026] [security2:error] [pid 971102:tid 971282] [client 172.239.147.162:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxZC-cL08BTTQixEnp7EAAAADA"], referer: binance.com
[Thu Sep 17 15:18:03.897043 2026] [authz_core:error] [pid 971102:tid 971337] [client 5.189.145.112:61686] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:03.987734 2026] [security2:error] [pid 971102:tid 971286] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxZC-cL08BTTQixEnp7GQAAADQ"]
[Thu Sep 17 15:18:04.073229 2026] [security2:error] [pid 971102:tid 971287] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production.old"] [unique_id "aqxZDOcL08BTTQixEnp7JAAAADU"]
[Thu Sep 17 15:18:04.137718 2026] [security2:error] [pid 971102:tid 971259] [client 34.151.157.242:54528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZDOcL08BTTQixEnp7JgAAABk"]
[Thu Sep 17 15:18:04.142556 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:54544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/debug.php"] [unique_id "aqxZDOcL08BTTQixEnp7JwAAACQ"]
[Thu Sep 17 15:18:04.225433 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxZDOcL08BTTQixEnp7OQAAADM"]
[Thu Sep 17 15:18:04.260143 2026] [security2:error] [pid 971102:tid 971329] [client 172.239.147.162:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxZDOcL08BTTQixEnp7OwAAAF8"], referer: binance.com
[Thu Sep 17 15:18:04.457142 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxZDOcL08BTTQixEnp7TQAAABI"]
[Thu Sep 17 15:18:04.633225 2026] [security2:error] [pid 971102:tid 971322] [client 34.151.157.242:54556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZDOcL08BTTQixEnp7TgAAAFg"]
[Thu Sep 17 15:18:04.654763 2026] [security2:error] [pid 971102:tid 971340] [client 34.151.157.242:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZDOcL08BTTQixEnp7TwAAAGo"]
[Thu Sep 17 15:18:04.689409 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxZDOcL08BTTQixEnp7UQAAACs"]
[Thu Sep 17 15:18:04.918012 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxZDOcL08BTTQixEnp7YAAAAAE"]
[Thu Sep 17 15:18:05.012149 2026] [security2:error] [pid 971102:tid 971251] [client 104.28.198.244:22803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7agAAABE"]
[Thu Sep 17 15:18:05.080827 2026] [security2:error] [pid 971102:tid 971275] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/v1/keys"] [unique_id "aqxZDecL08BTTQixEnp7bAAAACk"]
[Thu Sep 17 15:18:05.150679 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxZDecL08BTTQixEnp7bQAAAFk"]
[Thu Sep 17 15:18:05.157203 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:54572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7bwAAAAk"]
[Thu Sep 17 15:18:05.157219 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7bgAAADo"]
[Thu Sep 17 15:18:05.209855 2026] [security2:error] [pid 971102:tid 971251] [client 104.28.198.244:22803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7agAAABE"]
[Thu Sep 17 15:18:05.406205 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxZDecL08BTTQixEnp7cwAAACM"]
[Thu Sep 17 15:18:05.612322 2026] [security2:error] [pid 971102:tid 971332] [client 45.169.98.18:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7gAAAAGI"]
[Thu Sep 17 15:18:05.612460 2026] [security2:error] [pid 971102:tid 971332] [client 45.169.98.18:61474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7gAAAAGI"]
[Thu Sep 17 15:18:05.633803 2026] [security2:error] [pid 971102:tid 971279] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxZDecL08BTTQixEnp7ggAAAC0"]
[Thu Sep 17 15:18:05.657651 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:54600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7gwAAAEQ"]
[Thu Sep 17 15:18:05.670459 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxZDecL08BTTQixEnp7hAAAACc"], referer: binance.com
[Thu Sep 17 15:18:05.675892 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7hQAAAGw"]
[Thu Sep 17 15:18:05.800772 2026] [security2:error] [pid 971102:tid 971339] [client 172.239.147.162:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxZDecL08BTTQixEnp7iAAAAGk"], referer: binance.com
[Thu Sep 17 15:18:05.861196 2026] [security2:error] [pid 971102:tid 971236] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxZDecL08BTTQixEnp7jwAAAAI"]
[Thu Sep 17 15:18:06.118335 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxZDucL08BTTQixEnp7mQAAAHo"]
[Thu Sep 17 15:18:06.203208 2026] [security2:error] [pid 971102:tid 971259] [client 34.151.157.242:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZDucL08BTTQixEnp7mwAAABk"]
[Thu Sep 17 15:18:06.242672 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZDucL08BTTQixEnp7nQAAACQ"]
[Thu Sep 17 15:18:06.348587 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxZDucL08BTTQixEnp7oQAAABI"]
[Thu Sep 17 15:18:06.560695 2026] [security2:error] [pid 971102:tid 971258] [client 185.55.149.49:54214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZDucL08BTTQixEnp7pgAAABg"]
[Thu Sep 17 15:18:06.560818 2026] [security2:error] [pid 971102:tid 971258] [client 185.55.149.49:54214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZDucL08BTTQixEnp7pgAAABg"]
[Thu Sep 17 15:18:06.579110 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxZDucL08BTTQixEnp7pwAAAFw"]
[Thu Sep 17 15:18:06.602102 2026] [security2:error] [pid 971102:tid 971278] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/cgi/printenv"] [unique_id "aqxZDucL08BTTQixEnp7qAAAACw"]
[Thu Sep 17 15:18:06.779849 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZDucL08BTTQixEnp7qwAAAB4"]
[Thu Sep 17 15:18:06.810835 2026] [security2:error] [pid 971102:tid 971295] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxZDucL08BTTQixEnp7rwAAAD0"]
[Thu Sep 17 15:18:06.854978 2026] [security2:error] [pid 971102:tid 971235] [client 201.252.128.60:35713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZDucL08BTTQixEnp7qgAAAXw"]
[Thu Sep 17 15:18:06.912131 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZDucL08BTTQixEnp7rgAAAGY"]
[Thu Sep 17 15:18:07.041324 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:44066] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/application_default_credentials.json"] [unique_id "aqxZD-cL08BTTQixEnp7tgAAABQ"]
[Thu Sep 17 15:18:07.047170 2026] [security2:error] [pid 971102:tid 971305] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxZD-cL08BTTQixEnp7twAAAEc"]
[Thu Sep 17 15:18:07.206384 2026] [security2:error] [pid 971102:tid 971312] [client 185.213.175.37:44066] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.aws/config"] [unique_id "aqxZD-cL08BTTQixEnp7wAAAAE4"]
[Thu Sep 17 15:18:07.278436 2026] [security2:error] [pid 971102:tid 971271] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxZD-cL08BTTQixEnp7wQAAACU"]
[Thu Sep 17 15:18:07.290109 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZD-cL08BTTQixEnp7wgAAAHk"]
[Thu Sep 17 15:18:07.303072 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/php-info.php"] [unique_id "aqxZD-cL08BTTQixEnp7wwAAACo"]
[Thu Sep 17 15:18:07.495303 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:41385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZD-cL08BTTQixEnp7yQAAADY"]
[Thu Sep 17 15:18:07.495786 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:41385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZD-cL08BTTQixEnp7yQAAADY"]
[Thu Sep 17 15:18:07.511103 2026] [security2:error] [pid 971102:tid 971302] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxZD-cL08BTTQixEnp7ygAAAEQ"]
[Thu Sep 17 15:18:07.661860 2026] [security2:error] [pid 971102:tid 971342] [client 172.239.147.162:51503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxZD-cL08BTTQixEnp7zAAAAGw"], referer: binance.com
[Thu Sep 17 15:18:07.702413 2026] [security2:error] [pid 971102:tid 971279] [client 172.239.147.162:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxZD-cL08BTTQixEnp7zQAAAC0"], referer: binance.com
[Thu Sep 17 15:18:07.742518 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxZD-cL08BTTQixEnp7zgAAAEI"]
[Thu Sep 17 15:18:07.786146 2026] [security2:error] [pid 971102:tid 971274] [client 185.213.175.37:44066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/n8n"] [unique_id "aqxZD-cL08BTTQixEnp70QAAACg"]
[Thu Sep 17 15:18:07.786253 2026] [security2:error] [pid 971102:tid 971274] [client 185.213.175.37:44066] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/n8n"] [unique_id "aqxZD-cL08BTTQixEnp70QAAACg"]
[Thu Sep 17 15:18:07.813362 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:54642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpversion.php"] [unique_id "aqxZD-cL08BTTQixEnp71AAAAAI"]
[Thu Sep 17 15:18:07.974219 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxZD-cL08BTTQixEnp72gAAAF4"]
[Thu Sep 17 15:18:08.093337 2026] [security2:error] [pid 971102:tid 971325] [client 185.213.175.37:44072] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker-compose.yaml"] [unique_id "aqxZEOcL08BTTQixEnp74gAAAFs"]
[Thu Sep 17 15:18:08.125962 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZEOcL08BTTQixEnp74AAAAA0"]
[Thu Sep 17 15:18:08.206237 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxZEOcL08BTTQixEnp75gAAABw"]
[Thu Sep 17 15:18:08.315950 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:54652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/_phpinfo.php"] [unique_id "aqxZEOcL08BTTQixEnp76gAAAAU"]
[Thu Sep 17 15:18:08.426025 2026] [security2:error] [pid 971102:tid 971245] [client 185.213.175.37:44072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker-compose.yaml.bak"] [unique_id "aqxZEOcL08BTTQixEnp78AAAAAs"]
[Thu Sep 17 15:18:08.436071 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxZEOcL08BTTQixEnp78QAAAFI"]
[Thu Sep 17 15:18:08.448835 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:54640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/php-info.php"] [unique_id "aqxZEOcL08BTTQixEnp78gAAAB0"]
[Thu Sep 17 15:18:08.503568 2026] [security2:error] [pid 971102:tid 971258] [client 114.198.138.124:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZEOcL08BTTQixEnp79QAAABg"]
[Thu Sep 17 15:18:08.503706 2026] [security2:error] [pid 971102:tid 971258] [client 114.198.138.124:57054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZEOcL08BTTQixEnp79QAAABg"]
[Thu Sep 17 15:18:08.642034 2026] [security2:error] [pid 971102:tid 971307] [client 176.166.138.255:51826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZEOcL08BTTQixEnp79gAAST4"]
[Thu Sep 17 15:18:08.668666 2026] [security2:error] [pid 971102:tid 971305] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxZEOcL08BTTQixEnp7_gAAAEc"]
[Thu Sep 17 15:18:08.748477 2026] [security2:error] [pid 971102:tid 971331] [client 185.213.175.37:44072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production.yaml"] [unique_id "aqxZEOcL08BTTQixEnp8AAAAAGE"]
[Thu Sep 17 15:18:08.814907 2026] [security2:error] [pid 971102:tid 971254] [client 34.151.157.242:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZEOcL08BTTQixEnp8BgAAABQ"]
[Thu Sep 17 15:18:08.911845 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxZEOcL08BTTQixEnp8CQAAAHA"]
[Thu Sep 17 15:18:08.938495 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:54682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpversion.php"] [unique_id "aqxZEOcL08BTTQixEnp8CwAAACU"]
[Thu Sep 17 15:18:09.143664 2026] [security2:error] [pid 971102:tid 971297] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxZEecL08BTTQixEnp8EgAAAD8"]
[Thu Sep 17 15:18:09.296095 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/server-info.php"] [unique_id "aqxZEecL08BTTQixEnp8FQAAAGI"]
[Thu Sep 17 15:18:09.378780 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxZEecL08BTTQixEnp8HAAAAEg"]
[Thu Sep 17 15:18:09.428568 2026] [security2:error] [pid 971102:tid 971314] [client 172.239.147.162:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxZEecL08BTTQixEnp8HgAAAFA"], referer: binance.com
[Thu Sep 17 15:18:09.441812 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:54700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/_phpinfo.php"] [unique_id "aqxZEecL08BTTQixEnp8HwAAABU"]
[Thu Sep 17 15:18:09.604626 2026] [security2:error] [pid 971102:tid 971259] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxZEecL08BTTQixEnp8IwAAABk"]
[Thu Sep 17 15:18:09.698297 2026] [security2:error] [pid 971102:tid 971347] [client 185.213.175.37:48390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/aws/credentials.json"] [unique_id "aqxZEecL08BTTQixEnp8JgAAAHE"]
[Thu Sep 17 15:18:09.797750 2026] [security2:error] [pid 971102:tid 971268] [client 34.151.157.242:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/server-status.php"] [unique_id "aqxZEecL08BTTQixEnp8KwAAACI"]
[Thu Sep 17 15:18:09.831160 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxZEecL08BTTQixEnp8LgAAAEo"]
[Thu Sep 17 15:18:09.935275 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:54718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZEecL08BTTQixEnp8NgAAAEM"]
[Thu Sep 17 15:18:10.057191 2026] [security2:error] [pid 971102:tid 971249] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxZEucL08BTTQixEnp8OAAAAA8"]
[Thu Sep 17 15:18:10.092762 2026] [security2:error] [pid 971102:tid 971316] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.aws/credentials.json"] [unique_id "aqxZEucL08BTTQixEnp8OQAAAFI"]
[Thu Sep 17 15:18:10.285449 2026] [security2:error] [pid 971102:tid 971294] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxZEucL08BTTQixEnp8RgAAADw"]
[Thu Sep 17 15:18:10.327770 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app-config.json"] [unique_id "aqxZEucL08BTTQixEnp8TQAAAHI"]
[Thu Sep 17 15:18:10.409651 2026] [security2:error] [pid 971102:tid 971326] [client 43.173.173.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8QgAAAFw"]
[Thu Sep 17 15:18:10.429409 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/server-info.php"] [unique_id "aqxZEucL08BTTQixEnp8UwAAAEc"]
[Thu Sep 17 15:18:10.476844 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8TwAAAFY"]
[Thu Sep 17 15:18:10.480288 2026] [security2:error] [pid 971102:tid 971276] [client 43.173.174.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8TgAAACo"]
[Thu Sep 17 15:18:10.511935 2026] [security2:error] [pid 971102:tid 971324] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxZEucL08BTTQixEnp8VgAAAFo"]
[Thu Sep 17 15:18:10.597407 2026] [security2:error] [pid 971102:tid 971332] [client 3.82.141.143:37532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/web.config"] [unique_id "aqxZEucL08BTTQixEnp8XQAAAGI"]
[Thu Sep 17 15:18:10.607252 2026] [security2:error] [pid 971102:tid 971274] [client 3.82.141.143:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php"] [unique_id "aqxZEucL08BTTQixEnp8ZQAAACg"]
[Thu Sep 17 15:18:10.607545 2026] [security2:error] [pid 971102:tid 971247] [client 3.82.141.143:37446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rcpphotorestoration.com"] [uri "/config.php"] [unique_id "aqxZEucL08BTTQixEnp8ZwAAAA0"]
[Thu Sep 17 15:18:10.608898 2026] [security2:error] [pid 971102:tid 971282] [client 3.82.141.143:37632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env.bak"] [unique_id "aqxZEucL08BTTQixEnp8YgAAADA"]
[Thu Sep 17 15:18:10.626912 2026] [security2:error] [pid 971102:tid 971240] [client 3.82.141.143:37466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php~"] [unique_id "aqxZEucL08BTTQixEnp8cgAAAAY"]
[Thu Sep 17 15:18:10.627066 2026] [security2:error] [pid 971102:tid 971283] [client 3.82.141.143:37564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php.old"] [unique_id "aqxZEucL08BTTQixEnp8dQAAADE"]
[Thu Sep 17 15:18:10.629136 2026] [security2:error] [pid 971102:tid 971297] [client 3.82.141.143:37584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env.backup"] [unique_id "aqxZEucL08BTTQixEnp8dAAAAD8"]
[Thu Sep 17 15:18:10.645014 2026] [security2:error] [pid 971102:tid 971259] [client 3.82.141.143:37604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php.bak"] [unique_id "aqxZEucL08BTTQixEnp8eQAAABk"]
[Thu Sep 17 15:18:10.646430 2026] [security2:error] [pid 971102:tid 971306] [client 3.82.141.143:37600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env"] [unique_id "aqxZEucL08BTTQixEnp8egAAAEg"]
[Thu Sep 17 15:18:10.659371 2026] [security2:error] [pid 971102:tid 971329] [client 3.82.141.143:37532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php.save"] [unique_id "aqxZEucL08BTTQixEnp8ewAAAF8"]
[Thu Sep 17 15:18:10.666190 2026] [security2:error] [pid 971102:tid 971280] [client 3.82.141.143:37356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env.old"] [unique_id "aqxZEucL08BTTQixEnp8ggAAAC4"]
[Thu Sep 17 15:18:10.740601 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxZEucL08BTTQixEnp8gwAAAEk"]
[Thu Sep 17 15:18:10.788099 2026] [security2:error] [pid 971102:tid 971253] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/server-config.json"] [unique_id "aqxZEucL08BTTQixEnp8hwAAABM"]
[Thu Sep 17 15:18:10.905238 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/server-status.php"] [unique_id "aqxZEucL08BTTQixEnp8kAAAAC8"]
[Thu Sep 17 15:18:10.985251 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8jgAAAHU"]
[Thu Sep 17 15:18:10.986877 2026] [security2:error] [pid 971102:tid 971279] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxZEucL08BTTQixEnp8kQAAAC0"]
[Thu Sep 17 15:18:10.997133 2026] [security2:error] [pid 971102:tid 971315] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/settings.json"] [unique_id "aqxZEucL08BTTQixEnp8kgAAAFE"]
[Thu Sep 17 15:18:11.161523 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZE-cL08BTTQixEnp8mQAAAGs"]
[Thu Sep 17 15:18:11.221134 2026] [security2:error] [pid 971102:tid 971298] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxZE-cL08BTTQixEnp8mwAAAEA"]
[Thu Sep 17 15:18:11.407806 2026] [security2:error] [pid 971102:tid 971350] [client 185.213.175.37:48392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/configuration.json"] [unique_id "aqxZE-cL08BTTQixEnp8pAAAAHQ"]
[Thu Sep 17 15:18:11.407930 2026] [security2:error] [pid 971102:tid 971350] [client 185.213.175.37:48392] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/configuration.json"] [unique_id "aqxZE-cL08BTTQixEnp8pAAAAHQ"]
[Thu Sep 17 15:18:11.453358 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxZE-cL08BTTQixEnp8pwAAAAQ"]
[Thu Sep 17 15:18:11.497568 2026] [security2:error] [pid 971102:tid 971241] [client 186.105.232.15:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8qwAAAAc"]
[Thu Sep 17 15:18:11.497671 2026] [security2:error] [pid 971102:tid 971241] [client 186.105.232.15:57043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8qwAAAAc"]
[Thu Sep 17 15:18:11.520555 2026] [security2:error] [pid 971102:tid 971337] [client 156.192.234.52:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8rgAAAGc"]
[Thu Sep 17 15:18:11.523567 2026] [security2:error] [pid 971102:tid 971337] [client 156.192.234.52:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8rgAAAGc"]
[Thu Sep 17 15:18:11.650333 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.90:52506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lemuspools.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxZE-cL08BTTQixEnp8sQAAAAE"]
[Thu Sep 17 15:18:11.663982 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZE-cL08BTTQixEnp8sgAAAE8"]
[Thu Sep 17 15:18:11.685337 2026] [security2:error] [pid 971102:tid 971345] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxZE-cL08BTTQixEnp8tAAAAG8"]
[Thu Sep 17 15:18:11.808424 2026] [security2:error] [pid 971102:tid 971267] [client 185.213.175.37:48396] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/conf.json"] [unique_id "aqxZE-cL08BTTQixEnp8tgAAACE"]
[Thu Sep 17 15:18:11.919400 2026] [security2:error] [pid 971102:tid 971234] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxZE-cL08BTTQixEnp8vQAAAAA"]
[Thu Sep 17 15:18:11.940390 2026] [security2:error] [pid 971102:tid 971264] [client 172.239.147.162:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxZE-cL08BTTQixEnp8vgAAAB4"], referer: binance.com
[Thu Sep 17 15:18:11.958576 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZE-cL08BTTQixEnp8uAAAAEk"]
[Thu Sep 17 15:18:11.976982 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:48396] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/conf/config.json"] [unique_id "aqxZE-cL08BTTQixEnp8wAAAABQ"]
[Thu Sep 17 15:18:12.036784 2026] [security2:error] [pid 971102:tid 971256] [client 185.213.175.37:48400] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/settings.json"] [unique_id "aqxZFOcL08BTTQixEnp8wQAAABY"]
[Thu Sep 17 15:18:12.151462 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxZFOcL08BTTQixEnp8yAAAAG0"]
[Thu Sep 17 15:18:12.188074 2026] [security2:error] [pid 971102:tid 971346] [client 34.151.157.242:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZFOcL08BTTQixEnp8yQAAAHA"]
[Thu Sep 17 15:18:12.265316 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.90:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxZFOcL08BTTQixEnp8ygAAAHI"]
[Thu Sep 17 15:18:12.383178 2026] [security2:error] [pid 971102:tid 971273] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxZFOcL08BTTQixEnp8zgAAACc"]
[Thu Sep 17 15:18:12.616636 2026] [security2:error] [pid 971102:tid 971329] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxZFOcL08BTTQixEnp88AAAAF8"]
[Thu Sep 17 15:18:12.675430 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZFOcL08BTTQixEnp89gAAAAI"]
[Thu Sep 17 15:18:12.742847 2026] [security2:error] [pid 971102:tid 971291] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZFOcL08BTTQixEnp88QAAADk"]
[Thu Sep 17 15:18:12.761363 2026] [autoindex:error] [pid 971102:tid 971304] [client 45.115.26.203:49230] AH01276: Cannot serve directory /home1/awesone8/public_html/risingstarspress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:18:12.846380 2026] [security2:error] [pid 971102:tid 971337] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxZFOcL08BTTQixEnp9EAAAAGc"]
[Thu Sep 17 15:18:12.953892 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZFOcL08BTTQixEnp9EwAAAE8"]
[Thu Sep 17 15:18:13.080471 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxZFecL08BTTQixEnp9FgAAAGY"]
[Thu Sep 17 15:18:13.176101 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:42474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9HgAAAD0"]
[Thu Sep 17 15:18:13.257370 2026] [security2:error] [pid 971102:tid 971307] [client 172.239.147.162:59251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxZFecL08BTTQixEnp9HwAAAEk"], referer: binance.com
[Thu Sep 17 15:18:13.289503 2026] [security2:error] [pid 971102:tid 971324] [client 185.213.175.37:48418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.json"] [unique_id "aqxZFecL08BTTQixEnp9IAAAAFo"]
[Thu Sep 17 15:18:13.289646 2026] [security2:error] [pid 971102:tid 971324] [client 185.213.175.37:48418] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.json"] [unique_id "aqxZFecL08BTTQixEnp9IAAAAFo"]
[Thu Sep 17 15:18:13.310426 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxZFecL08BTTQixEnp9IQAAACY"]
[Thu Sep 17 15:18:13.483415 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:42488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9LAAAAHE"]
[Thu Sep 17 15:18:13.540637 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxZFecL08BTTQixEnp9LgAAAC8"]
[Thu Sep 17 15:18:13.687985 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:42504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9NAAAAGw"]
[Thu Sep 17 15:18:13.720987 2026] [security2:error] [pid 971102:tid 971351] [client 185.213.175.37:48402] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/environment.json"] [unique_id "aqxZFecL08BTTQixEnp9NwAAAHU"]
[Thu Sep 17 15:18:13.773710 2026] [security2:error] [pid 971102:tid 971287] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxZFecL08BTTQixEnp9OQAAADU"]
[Thu Sep 17 15:18:13.831975 2026] [security2:error] [pid 971102:tid 971257] [client 46.101.77.15:53470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZE-cL08BTTQixEnp8vwAAFxA"], referer: http://newspace.us./blog/
[Thu Sep 17 15:18:13.999195 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:42506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9RAAAAHk"]
[Thu Sep 17 15:18:14.005868 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxZFucL08BTTQixEnp9RQAAAA0"]
[Thu Sep 17 15:18:14.174734 2026] [security2:error] [pid 971102:tid 971255] [client 46.101.77.15:53470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZFucL08BTTQixEnp9RwAAFSc"], referer: http://newspace.us./backup/
[Thu Sep 17 15:18:14.207048 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:42518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZFucL08BTTQixEnp9TwAAAEI"]
[Thu Sep 17 15:18:14.294241 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxZFucL08BTTQixEnp9UAAAAB0"]
[Thu Sep 17 15:18:14.497800 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:42520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZFucL08BTTQixEnp9WgAAAAA"]
[Thu Sep 17 15:18:15.202633 2026] [security2:error] [pid 971102:tid 971298] [client 118.179.125.113:4220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZF-cL08BTTQixEnp9WwAAQEI"]
[Thu Sep 17 15:18:15.225908 2026] [http2:info] [pid 1012520:tid 1012520] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:18:15.244251 2026] [security2:error] [pid 1012520:tid 1012657] [client 185.213.175.37:48454] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/secret.json"] [unique_id "aqxZFwpXMN3p_zkwXf2M8QAAAIs"]
[Thu Sep 17 15:18:15.404162 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.151.157.242:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZFwpXMN3p_zkwXf2M-gAAAIc"]
[Thu Sep 17 15:18:15.409512 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.151.157.242:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZFwpXMN3p_zkwXf2M-wAAAI0"]
[Thu Sep 17 15:18:15.454150 2026] [security2:error] [pid 1012520:tid 1012652] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZFwpXMN3p_zkwXf2M-QAAhgA"], referer: http://newspace.us./wordpress/
[Thu Sep 17 15:18:15.480788 2026] [security2:error] [pid 1012520:tid 1012662] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxZFwpXMN3p_zkwXf2M_QAAAJA"]
[Thu Sep 17 15:18:15.713336 2026] [security2:error] [pid 1012520:tid 1012684] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxZFwpXMN3p_zkwXf2NBwAAAKY"]
[Thu Sep 17 15:18:15.835191 2026] [security2:error] [pid 1012520:tid 1012689] [client 185.213.175.37:48472] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/keys.json"] [unique_id "aqxZFwpXMN3p_zkwXf2NCgAAAKs"]
[Thu Sep 17 15:18:15.899973 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.151.157.242:42568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZFwpXMN3p_zkwXf2NDgAAAKc"]
[Thu Sep 17 15:18:15.926223 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.151.157.242:42552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php~"] [unique_id "aqxZFwpXMN3p_zkwXf2NEgAAAKg"]
[Thu Sep 17 15:18:15.966085 2026] [security2:error] [pid 1012520:tid 1012696] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZFwpXMN3p_zkwXf2NDwAAsgM"], referer: http://newspace.us./new/
[Thu Sep 17 15:18:16.058286 2026] [fcgid:warn] [pid 1012520:tid 1012708] (70014)End of file found: [client 66.132.224.230:18838] mod_fcgid: can't get data from http client
[Thu Sep 17 15:18:16.076786 2026] [security2:error] [pid 1012520:tid 1012710] [client 85.204.70.90:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGQAAAMA"]
[Thu Sep 17 15:18:16.076923 2026] [security2:error] [pid 1012520:tid 1012710] [client 85.204.70.90:58700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGQAAAMA"]
[Thu Sep 17 15:18:16.099756 2026] [security2:error] [pid 1012520:tid 1012703] [client 45.169.98.18:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGgAAALk"]
[Thu Sep 17 15:18:16.099867 2026] [security2:error] [pid 1012520:tid 1012703] [client 45.169.98.18:62192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGgAAALk"]
[Thu Sep 17 15:18:16.389601 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.151.157.242:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZGApXMN3p_zkwXf2NJwAAAM4"]
[Thu Sep 17 15:18:16.401565 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.151.157.242:42580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/info.php.bak"] [unique_id "aqxZGApXMN3p_zkwXf2NKQAAANA"]
[Thu Sep 17 15:18:16.710796 2026] [security2:error] [pid 1012520:tid 1012752] [client 185.213.175.37:48472] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.netrc"] [unique_id "aqxZGApXMN3p_zkwXf2NLgAAAOo"]
[Thu Sep 17 15:18:16.719226 2026] [security2:error] [pid 1012520:tid 1012753] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxZGApXMN3p_zkwXf2NMAAAAOs"]
[Thu Sep 17 15:18:16.721270 2026] [security2:error] [pid 1012520:tid 1012532] [remote 195.3.220.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.220.3.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beartoothagilityclub.com"] [uri "/.well-known/acme-challenge/wp-firewall.php"] [unique_id "aqxZGApXMN3p_zkwXf2NLwAA6Ao"]
[Thu Sep 17 15:18:16.914428 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.151.157.242:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZGApXMN3p_zkwXf2NNgAAAO4"]
[Thu Sep 17 15:18:16.928860 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.151.157.242:42590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZGApXMN3p_zkwXf2NNwAAAO8"]
[Thu Sep 17 15:18:16.951372 2026] [security2:error] [pid 1012520:tid 1012764] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxZGApXMN3p_zkwXf2NOgAAAPY"]
[Thu Sep 17 15:18:17.016375 2026] [security2:error] [pid 1012520:tid 1012766] [client 185.213.175.37:48472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/google-services.json"] [unique_id "aqxZGQpXMN3p_zkwXf2NPQAAAPg"]
[Thu Sep 17 15:18:17.183770 2026] [security2:error] [pid 1012520:tid 1012773] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NPwAA_ww"], referer: http://newspace.us./old/
[Thu Sep 17 15:18:17.185048 2026] [security2:error] [pid 1012520:tid 1012657] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NQgAAAIs"]
[Thu Sep 17 15:18:17.231128 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.55.149.49:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NQwAAAPk"]
[Thu Sep 17 15:18:17.231235 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.55.149.49:54928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NQwAAAPk"]
[Thu Sep 17 15:18:17.354558 2026] [security2:error] [pid 1012520:tid 1012537] [remote 195.3.220.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.220.3.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beartoothagilityclub.com"] [uri "/.well-known/acme-challenge/222.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NSQAAmw8"]
[Thu Sep 17 15:18:17.391385 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.151.157.242:42604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NSwAAAI0"]
[Thu Sep 17 15:18:17.414488 2026] [security2:error] [pid 1012520:tid 1012676] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NTgAAAJ4"]
[Thu Sep 17 15:18:17.437085 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.151.157.242:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php~"] [unique_id "aqxZGQpXMN3p_zkwXf2NUQAAAJU"]
[Thu Sep 17 15:18:17.513178 2026] [security2:error] [pid 1012520:tid 1012687] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NUwAAqRA"], referer: http://newspace.us./wp/
[Thu Sep 17 15:18:17.641585 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NVAAAAKw"]
[Thu Sep 17 15:18:17.657160 2026] [security2:error] [pid 1012520:tid 1012685] [client 185.213.175.37:48466] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/application.properties"] [unique_id "aqxZGQpXMN3p_zkwXf2NVwAAAKc"]
[Thu Sep 17 15:18:17.874957 2026] [security2:error] [pid 1012520:tid 1012704] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NWQAAALo"]
[Thu Sep 17 15:18:17.890616 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.151.157.242:42622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NWgAAALA"]
[Thu Sep 17 15:18:17.907644 2026] [security2:error] [pid 1012520:tid 1012700] [client 185.213.175.37:48454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/application.yml.bak"] [unique_id "aqxZGQpXMN3p_zkwXf2NWwAAALY"]
[Thu Sep 17 15:18:17.922248 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.151.157.242:42624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/info.php.bak"] [unique_id "aqxZGQpXMN3p_zkwXf2NXAAAAKg"]
[Thu Sep 17 15:18:18.026037 2026] [security2:error] [pid 1012520:tid 1012689] [client 154.190.208.131:41997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NXgAAAKs"]
[Thu Sep 17 15:18:18.026169 2026] [security2:error] [pid 1012520:tid 1012689] [client 154.190.208.131:41997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NXgAAAKs"]
[Thu Sep 17 15:18:18.112646 2026] [security2:error] [pid 1012520:tid 1012710] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NXwAAAMA"]
[Thu Sep 17 15:18:18.320993 2026] [security2:error] [pid 1012520:tid 1012715] [client 128.201.185.153:57792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NZAAAxRM"]
[Thu Sep 17 15:18:18.345377 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NZgAAAJ0"]
[Thu Sep 17 15:18:18.388348 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.151.157.242:42628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NZwAAALc"]
[Thu Sep 17 15:18:18.390556 2026] [security2:error] [pid 1012520:tid 1012719] [client 185.213.175.37:48454] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.yml"] [unique_id "aqxZGgpXMN3p_zkwXf2NaAAAAMk"]
[Thu Sep 17 15:18:18.408905 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.151.157.242:42634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZGgpXMN3p_zkwXf2NagAAAMc"]
[Thu Sep 17 15:18:18.421679 2026] [authz_core:error] [pid 1012520:tid 1012678] [client 172.239.147.162:62409] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:18:18.574223 2026] [security2:error] [pid 1012520:tid 1012726] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NbQAAANA"]
[Thu Sep 17 15:18:18.613814 2026] [security2:error] [pid 1012520:tid 1012670] [client 185.213.175.37:48438] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.toml"] [unique_id "aqxZGgpXMN3p_zkwXf2NbwAAAJg"]
[Thu Sep 17 15:18:18.802891 2026] [security2:error] [pid 1012520:tid 1012742] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NdAAAAOA"]
[Thu Sep 17 15:18:18.859530 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.151.157.242:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NdgAAANc"]
[Thu Sep 17 15:18:18.895784 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.151.157.242:42646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NdwAAAN8"]
[Thu Sep 17 15:18:19.010950 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NeAAAAOE"]
[Thu Sep 17 15:18:19.011096 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:57688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NeAAAAOE"]
[Thu Sep 17 15:18:19.030336 2026] [security2:error] [pid 1012520:tid 1012747] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NeQAAAOU"]
[Thu Sep 17 15:18:19.126930 2026] [authz_core:error] [pid 1012520:tid 1012716] [client 5.189.145.112:63023] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:19.257841 2026] [security2:error] [pid 1012520:tid 1012766] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NgAAAAPg"]
[Thu Sep 17 15:18:19.336854 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.151.157.242:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NhAAAAO8"]
[Thu Sep 17 15:18:19.405129 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.151.157.242:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NhwAAAPc"]
[Thu Sep 17 15:18:19.485149 2026] [security2:error] [pid 1012520:tid 1012768] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NiwAAAPo"]
[Thu Sep 17 15:18:19.622896 2026] [authz_core:error] [pid 1012520:tid 1012651] [client 185.213.175.37:48438] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Thu Sep 17 15:18:19.702537 2026] [authz_core:error] [pid 1012520:tid 1012666] [client 172.239.147.162:60129] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:18:19.713706 2026] [security2:error] [pid 1012520:tid 1012677] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NlQAAAJ8"]
[Thu Sep 17 15:18:19.827866 2026] [security2:error] [pid 1012520:tid 1012679] [client 185.213.175.37:48438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/token.json"] [unique_id "aqxZGwpXMN3p_zkwXf2NlgAAAKE"]
[Thu Sep 17 15:18:19.828022 2026] [security2:error] [pid 1012520:tid 1012679] [client 185.213.175.37:48438] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/token.json"] [unique_id "aqxZGwpXMN3p_zkwXf2NlgAAAKE"]
[Thu Sep 17 15:18:19.830639 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.151.157.242:42676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NlwAAAJE"]
[Thu Sep 17 15:18:19.890900 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.151.157.242:42680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NmQAAAKQ"]
[Thu Sep 17 15:18:19.943446 2026] [security2:error] [pid 1012520:tid 1012688] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NnAAAAKo"]
[Thu Sep 17 15:18:20.168648 2026] [security2:error] [pid 1012520:tid 1012686] [client 127.0.0.1:17636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxZHApXMN3p_zkwXf2NoQAAAKg"]
[Thu Sep 17 15:18:20.168685 2026] [security2:error] [pid 1012520:tid 1012700] [client 127.0.0.1:17622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.starrjoyblog.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxZHApXMN3p_zkwXf2NoAAAALY"]
[Thu Sep 17 15:18:20.168965 2026] [security2:error] [pid 1012520:tid 1012694] [client 74.7.228.2:33370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.starrjoyblog.com"] [uri "/robots.txt"] [unique_id "aqxZHApXMN3p_zkwXf2NnwAAsB0"]
[Thu Sep 17 15:18:20.175856 2026] [security2:error] [pid 1012520:tid 1012689] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NpQAAAKs"]
[Thu Sep 17 15:18:20.335414 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.151.157.242:42692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NqAAAALw"]
[Thu Sep 17 15:18:20.372741 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.151.157.242:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NqQAAAJA"]
[Thu Sep 17 15:18:20.408734 2026] [security2:error] [pid 1012520:tid 1012715] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NqgAAAMU"]
[Thu Sep 17 15:18:20.501270 2026] [security2:error] [pid 1012520:tid 1012652] [client 185.213.175.37:46788] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/credentials.yml"] [unique_id "aqxZHApXMN3p_zkwXf2NrwAAAIY"]
[Thu Sep 17 15:18:20.638571 2026] [security2:error] [pid 1012520:tid 1012678] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NsQAAAKA"]
[Thu Sep 17 15:18:20.671544 2026] [security2:error] [pid 1012520:tid 1012725] [client 185.213.175.37:46794] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.git/HEAD"] [unique_id "aqxZHApXMN3p_zkwXf2NsgAAAM8"]
[Thu Sep 17 15:18:20.820195 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.151.157.242:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NtQAAALs"]
[Thu Sep 17 15:18:20.835843 2026] [security2:error] [pid 1012520:tid 1012722] [client 185.213.175.37:46794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/.git/HEAD"] [unique_id "aqxZHApXMN3p_zkwXf2NtwAAAMw"]
[Thu Sep 17 15:18:20.835965 2026] [security2:error] [pid 1012520:tid 1012722] [client 185.213.175.37:46794] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/.git/HEAD"] [unique_id "aqxZHApXMN3p_zkwXf2NtwAAAMw"]
[Thu Sep 17 15:18:20.869052 2026] [security2:error] [pid 1012520:tid 1012736] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NuQAAANo"]
[Thu Sep 17 15:18:20.872615 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.151.157.242:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NugAAAM0"]
[Thu Sep 17 15:18:21.096293 2026] [security2:error] [pid 1012520:tid 1012731] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2NvQAAANU"]
[Thu Sep 17 15:18:21.252840 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.168.200.72:19441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "freeofgravity.com"] [uri "/index.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NnQAAAKI"]
[Thu Sep 17 15:18:21.298730 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.151.157.242:42708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2NxQAAAOQ"]
[Thu Sep 17 15:18:21.323584 2026] [security2:error] [pid 1012520:tid 1012757] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2NxgAAAO8"]
[Thu Sep 17 15:18:21.350947 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.151.157.242:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2NxwAAAJc"]
[Thu Sep 17 15:18:21.429003 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.246.241.88:42496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHQpXMN3p_zkwXf2NyAAAAPw"]
[Thu Sep 17 15:18:21.448686 2026] [security2:error] [pid 1012520:tid 1012772] [client 185.213.175.37:46788] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backend/.git/HEAD"] [unique_id "aqxZHQpXMN3p_zkwXf2NygAAAP4"]
[Thu Sep 17 15:18:21.500197 2026] [authz_core:error] [pid 1012520:tid 1012765] [client 172.239.147.162:50694] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:21.553425 2026] [security2:error] [pid 1012520:tid 1012778] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2NzQAAAQQ"]
[Thu Sep 17 15:18:21.763899 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.151.157.242:42722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2N0QAAAIs"]
[Thu Sep 17 15:18:21.784558 2026] [security2:error] [pid 1012520:tid 1012776] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2N0gAAAQI"]
[Thu Sep 17 15:18:21.825627 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.151.157.242:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2N0wAAAIU"]
[Thu Sep 17 15:18:22.010888 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N2AAAAKw"]
[Thu Sep 17 15:18:22.055435 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.246.241.88:37342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHgpXMN3p_zkwXf2N2QAAAKk"]
[Thu Sep 17 15:18:22.081119 2026] [security2:error] [pid 1012520:tid 1012677] [client 156.192.234.52:54452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N2gAAAJ8"]
[Thu Sep 17 15:18:22.081733 2026] [security2:error] [pid 1012520:tid 1012677] [client 156.192.234.52:54452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N2gAAAJ8"]
[Thu Sep 17 15:18:22.223066 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.151.157.242:42744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N5gAAAKo"]
[Thu Sep 17 15:18:22.239552 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N5wAAALQ"]
[Thu Sep 17 15:18:22.300158 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.151.157.242:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N6QAAALo"]
[Thu Sep 17 15:18:22.469188 2026] [security2:error] [pid 1012520:tid 1012718] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N6wAAAMg"]
[Thu Sep 17 15:18:22.697858 2026] [security2:error] [pid 1012520:tid 1012722] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N8AAAAMw"]
[Thu Sep 17 15:18:22.723023 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.151.157.242:42768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N8wAAAM8"]
[Thu Sep 17 15:18:22.756710 2026] [security2:error] [pid 1012520:tid 1012562] [remote 122.14.226.13:29030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christiansoncampusnlc.com"] [uri "/robots.txt"] [unique_id "aqxZHgpXMN3p_zkwXf2N9AAAkSg"]
[Thu Sep 17 15:18:22.793725 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.151.157.242:42782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N9gAAALs"]
[Thu Sep 17 15:18:22.833703 2026] [security2:error] [pid 1012520:tid 1012661] [client 186.105.232.15:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N-QAAAI8"]
[Thu Sep 17 15:18:22.833891 2026] [security2:error] [pid 1012520:tid 1012661] [client 186.105.232.15:57617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N-QAAAI8"]
[Thu Sep 17 15:18:22.926289 2026] [security2:error] [pid 1012520:tid 1012733] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N_wAAANc"]
[Thu Sep 17 15:18:22.953032 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:37356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHgpXMN3p_zkwXf2OAgAAANo"]
[Thu Sep 17 15:18:22.956111 2026] [authz_core:error] [pid 1012520:tid 1012734] [client 172.239.147.162:51074] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:23.169132 2026] [security2:error] [pid 1012520:tid 1012757] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2OCAAAAO8"]
[Thu Sep 17 15:18:23.174189 2026] [security2:error] [pid 1012520:tid 1012724] [client 185.219.41.85:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.219.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OBgAAAM4"]
[Thu Sep 17 15:18:23.198952 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.151.157.242:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OCQAAAPg"]
[Thu Sep 17 15:18:23.285592 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.151.157.242:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OCwAAAOo"]
[Thu Sep 17 15:18:23.402407 2026] [security2:error] [pid 1012520:tid 1012770] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2ODAAAAPw"]
[Thu Sep 17 15:18:23.632246 2026] [security2:error] [pid 1012520:tid 1012676] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2OEwAAAJ4"]
[Thu Sep 17 15:18:23.690378 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.151.157.242:57824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OFwAAAQI"]
[Thu Sep 17 15:18:23.757701 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.151.157.242:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OGQAAAIU"]
[Thu Sep 17 15:18:23.813531 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.246.241.88:37364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHwpXMN3p_zkwXf2OJwAAAIc"]
[Thu Sep 17 15:18:23.864379 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2OKAAAAKw"]
[Thu Sep 17 15:18:24.097015 2026] [security2:error] [pid 1012520:tid 1012704] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxZIApXMN3p_zkwXf2ONAAAALo"]
[Thu Sep 17 15:18:24.328961 2026] [security2:error] [pid 1012520:tid 1012681] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxZIApXMN3p_zkwXf2OQAAAAKM"]
[Thu Sep 17 15:18:24.357096 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIApXMN3p_zkwXf2ONQAAALQ"]
[Thu Sep 17 15:18:24.364525 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.151.157.242:57860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZIApXMN3p_zkwXf2OQQAAAKs"]
[Thu Sep 17 15:18:24.503454 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env"] [unique_id "aqxZIApXMN3p_zkwXf2ORAAAALI"]
[Thu Sep 17 15:18:24.525946 2026] [security2:error] [pid 1012520:tid 1012702] [client 172.239.147.162:59307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxZIApXMN3p_zkwXf2ORQAAALg"], referer: binance.com
[Thu Sep 17 15:18:24.561417 2026] [security2:error] [pid 1012520:tid 1012707] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxZIApXMN3p_zkwXf2ORgAAAL0"]
[Thu Sep 17 15:18:24.794629 2026] [security2:error] [pid 1012520:tid 1012680] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxZIApXMN3p_zkwXf2OWwAAAKI"]
[Thu Sep 17 15:18:24.806243 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIApXMN3p_zkwXf2OTwAAAIw"]
[Thu Sep 17 15:18:24.841766 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.151.157.242:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZIApXMN3p_zkwXf2OXwAAANY"]
[Thu Sep 17 15:18:25.028427 2026] [security2:error] [pid 1012520:tid 1012766] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OaAAAAPg"]
[Thu Sep 17 15:18:25.113157 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIApXMN3p_zkwXf2OZwAAAPA"]
[Thu Sep 17 15:18:25.254147 2026] [fcgid:warn] [pid 1012520:tid 1012745] (70014)End of file found: [client 45.43.62.37:48526] mod_fcgid: can't get data from http client
[Thu Sep 17 15:18:25.261360 2026] [security2:error] [pid 1012520:tid 1012666] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2ObwAAAJQ"]
[Thu Sep 17 15:18:25.338136 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.151.157.242:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OcwAAAQE"]
[Thu Sep 17 15:18:25.377641 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OcAAAAQQ"]
[Thu Sep 17 15:18:25.490773 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OdQAAAKw"]
[Thu Sep 17 15:18:25.645852 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OdgAAAJI"]
[Thu Sep 17 15:18:25.726567 2026] [security2:error] [pid 1012520:tid 1012697] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OiAAAALM"]
[Thu Sep 17 15:18:25.806975 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.bak"] [unique_id "aqxZIQpXMN3p_zkwXf2OiwAAALY"]
[Thu Sep 17 15:18:25.833997 2026] [security2:error] [pid 1012520:tid 1012631] [remote 110.249.202.161:55560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/outlines"] [unique_id "aqxZIQpXMN3p_zkwXf2OjQAAqW0"]
[Thu Sep 17 15:18:25.915607 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OiQAAALw"]
[Thu Sep 17 15:18:25.934923 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OigAAAJ8"]
[Thu Sep 17 15:18:25.961970 2026] [security2:error] [pid 1012520:tid 1012671] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OkAAAAJk"]
[Thu Sep 17 15:18:25.961989 2026] [security2:error] [pid 1012520:tid 1012668] [client 172.239.147.162:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OkQAAAJY"], referer: binance.com
[Thu Sep 17 15:18:26.006683 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.backup"] [unique_id "aqxZIgpXMN3p_zkwXf2OkgAAALE"]
[Thu Sep 17 15:18:26.180684 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OkwAAALA"]
[Thu Sep 17 15:18:26.196353 2026] [security2:error] [pid 1012520:tid 1012702] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OlwAAALg"]
[Thu Sep 17 15:18:26.356367 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OmwAAAMw"]
[Thu Sep 17 15:18:26.436551 2026] [security2:error] [pid 1012520:tid 1012744] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OnQAAAOI"]
[Thu Sep 17 15:18:26.442494 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OnAAAAMQ"]
[Thu Sep 17 15:18:26.480444 2026] [security2:error] [pid 1012520:tid 1012652] [client 104.28.198.244:22649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OngAAAIY"]
[Thu Sep 17 15:18:26.480621 2026] [security2:error] [pid 1012520:tid 1012652] [client 104.28.198.244:22649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OngAAAIY"]
[Thu Sep 17 15:18:26.512090 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.old"] [unique_id "aqxZIgpXMN3p_zkwXf2OoAAAANU"]
[Thu Sep 17 15:18:26.584385 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.169.98.18:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OoQAAAME"]
[Thu Sep 17 15:18:26.584494 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.169.98.18:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OoQAAAME"]
[Thu Sep 17 15:18:26.602353 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OnwAAALs"]
[Thu Sep 17 15:18:26.664897 2026] [security2:error] [pid 1012520:tid 1012736] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OpwAAANo"]
[Thu Sep 17 15:18:26.699539 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OogAAANc"]
[Thu Sep 17 15:18:26.865769 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OqQAAAPY"]
[Thu Sep 17 15:18:26.898097 2026] [security2:error] [pid 1012520:tid 1012740] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OrgAAAN4"]
[Thu Sep 17 15:18:26.972238 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OrQAAAMc"]
[Thu Sep 17 15:18:27.130900 2026] [security2:error] [pid 1012520:tid 1012766] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OtwAAAPg"]
[Thu Sep 17 15:18:27.131122 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OtAAAAM4"]
[Thu Sep 17 15:18:27.163193 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.192.52.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OswAAAO8"]
[Thu Sep 17 15:18:27.261122 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OugAAAJc"]
[Thu Sep 17 15:18:27.356299 2026] [security2:error] [pid 1012520:tid 1012745] [client 172.239.147.162:50021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OwgAAAOM"], referer: binance.com
[Thu Sep 17 15:18:27.370921 2026] [security2:error] [pid 1012520:tid 1012777] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OwwAAAQM"]
[Thu Sep 17 15:18:27.404045 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OvwAAAJo"]
[Thu Sep 17 15:18:27.527192 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OxAAAAOA"]
[Thu Sep 17 15:18:27.607075 2026] [security2:error] [pid 1012520:tid 1012737] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OyAAAANs"]
[Thu Sep 17 15:18:27.691048 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OxwAAANQ"]
[Thu Sep 17 15:18:27.825003 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OygAAAJ4"]
[Thu Sep 17 15:18:27.841980 2026] [security2:error] [pid 1012520:tid 1012651] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OzgAAAIU"]
[Thu Sep 17 15:18:27.851898 2026] [security2:error] [pid 1012520:tid 1012683] [client 185.219.41.85:56794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OKQAAAKU"]
[Thu Sep 17 15:18:27.897847 2026] [security2:error] [pid 1012520:tid 1012727] [client 185.55.149.49:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZIwpXMN3p_zkwXf2O0gAAANE"]
[Thu Sep 17 15:18:27.897969 2026] [security2:error] [pid 1012520:tid 1012727] [client 185.55.149.49:63648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZIwpXMN3p_zkwXf2O0gAAANE"]
[Thu Sep 17 15:18:27.964051 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OzwAAAN8"]
[Thu Sep 17 15:18:28.074182 2026] [security2:error] [pid 1012520:tid 1012762] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O2QAAAPQ"]
[Thu Sep 17 15:18:28.101300 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2O1gAAANA"]
[Thu Sep 17 15:18:28.231063 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2O2gAAALM"]
[Thu Sep 17 15:18:28.307557 2026] [security2:error] [pid 1012520:tid 1012708] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O3AAAAL4"]
[Thu Sep 17 15:18:28.520904 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2O3gAAAIg"]
[Thu Sep 17 15:18:28.550422 2026] [security2:error] [pid 1012520:tid 1012702] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O6AAAALg"]
[Thu Sep 17 15:18:28.593235 2026] [security2:error] [pid 1012520:tid 1012700] [client 154.190.208.131:42601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJApXMN3p_zkwXf2O6QAAALY"]
[Thu Sep 17 15:18:28.593405 2026] [security2:error] [pid 1012520:tid 1012700] [client 154.190.208.131:42601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJApXMN3p_zkwXf2O6QAAALY"]
[Thu Sep 17 15:18:28.784175 2026] [security2:error] [pid 1012520:tid 1012652] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O8AAAAIY"]
[Thu Sep 17 15:18:28.795842 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2O7wAAANw"]
[Thu Sep 17 15:18:28.805943 2026] [security2:error] [pid 1012520:tid 1012751] [client 172.239.147.162:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxZJApXMN3p_zkwXf2O8wAAAOk"], referer: binance.com
[Thu Sep 17 15:18:29.022291 2026] [security2:error] [pid 1012520:tid 1012717] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PIgAAAMc"]
[Thu Sep 17 15:18:29.053728 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2PFgAAAPY"]
[Thu Sep 17 15:18:29.257235 2026] [security2:error] [pid 1012520:tid 1012666] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PKQAAAJQ"]
[Thu Sep 17 15:18:29.309542 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PJwAAAI4"]
[Thu Sep 17 15:18:29.488731 2026] [security2:error] [pid 1012520:tid 1012670] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PMwAAAJg"]
[Thu Sep 17 15:18:29.552367 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.swp"] [unique_id "aqxZJQpXMN3p_zkwXf2PNAAAAMs"]
[Thu Sep 17 15:18:29.560064 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PMgAAAMY"]
[Thu Sep 17 15:18:29.719578 2026] [security2:error] [pid 1012520:tid 1012762] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PPAAAAPQ"]
[Thu Sep 17 15:18:29.765801 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env~"] [unique_id "aqxZJQpXMN3p_zkwXf2PPQAAAKQ"]
[Thu Sep 17 15:18:29.866317 2026] [security2:error] [pid 1012520:tid 1012651] [client 114.198.138.124:58347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PPwAAAIU"]
[Thu Sep 17 15:18:29.866482 2026] [security2:error] [pid 1012520:tid 1012651] [client 114.198.138.124:58347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PPwAAAIU"]
[Thu Sep 17 15:18:29.952633 2026] [security2:error] [pid 1012520:tid 1012689] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PQwAAAKs"]
[Thu Sep 17 15:18:29.971867 2026] [security2:error] [pid 1012520:tid 1012677] [client 5.189.145.112:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PRQAAAJ8"], referer: binance.com
[Thu Sep 17 15:18:30.185574 2026] [security2:error] [pid 1012520:tid 1012735] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxZJgpXMN3p_zkwXf2PTAAAANk"]
[Thu Sep 17 15:18:30.419296 2026] [security2:error] [pid 1012520:tid 1012729] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxZJgpXMN3p_zkwXf2PWAAAANM"]
[Thu Sep 17 15:18:30.655594 2026] [security2:error] [pid 1012520:tid 1012740] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxZJgpXMN3p_zkwXf2PYgAAAN4"]
[Thu Sep 17 15:18:30.786895 2026] [security2:error] [pid 1012520:tid 1012760] [client 69.165.67.149:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.67.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "danielstepniak.com"] [uri "/index.php"] [unique_id "aqxZJgpXMN3p_zkwXf2PZwAAAPI"], referer: https://danielstepniak.com
[Thu Sep 17 15:18:30.923655 2026] [security2:error] [pid 1012520:tid 1012658] [client 8.228.208.101:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxZJgpXMN3p_zkwXf2PbAAAAIw"]
[Thu Sep 17 15:18:30.986168 2026] [security2:error] [pid 1012520:tid 1012666] [client 185.219.41.85:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.219.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZJgpXMN3p_zkwXf2PcgAAAJQ"]
[Thu Sep 17 15:18:31.197311 2026] [security2:error] [pid 1012520:tid 1012701] [client 37.139.53.7:53756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "authorsandrasmith.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PgwAAALc"], referer: https://authorsandrasmith.com/?page_id=5
[Thu Sep 17 15:18:31.197411 2026] [security2:error] [pid 1012520:tid 1012701] [client 37.139.53.7:53756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "authorsandrasmith.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PgwAAALc"], referer: https://authorsandrasmith.com/?page_id=5
[Thu Sep 17 15:18:31.405539 2026] [security2:error] [pid 1012520:tid 1012765] [client 31.215.13.14:60304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PiQAA91w"]
[Thu Sep 17 15:18:31.595008 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/app/.env"] [unique_id "aqxZJwpXMN3p_zkwXf2PjwAAAPQ"]
[Thu Sep 17 15:18:31.718155 2026] [security2:error] [pid 1012520:tid 1012741] [client 8.228.208.101:43840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/info.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PkAAAAN8"]
[Thu Sep 17 15:18:31.844453 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/apps/.env"] [unique_id "aqxZJwpXMN3p_zkwXf2PkQAAAPs"]
[Thu Sep 17 15:18:32.045062 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PmAAAAJ8"]
[Thu Sep 17 15:18:32.282222 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/web/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PoAAAAL8"]
[Thu Sep 17 15:18:32.349173 2026] [security2:error] [pid 1012520:tid 1012753] [client 185.219.41.85:56822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZKApXMN3p_zkwXf2PlwAAAOs"]
[Thu Sep 17 15:18:32.425473 2026] [security2:error] [pid 1012520:tid 1012715] [client 8.228.208.101:43856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/php.php"] [unique_id "aqxZKApXMN3p_zkwXf2PqQAAAMU"]
[Thu Sep 17 15:18:32.464697 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/site/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PqgAAAMw"]
[Thu Sep 17 15:18:32.624951 2026] [security2:error] [pid 1012520:tid 1012671] [client 156.192.234.52:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKApXMN3p_zkwXf2PsQAAAJk"]
[Thu Sep 17 15:18:32.625510 2026] [security2:error] [pid 1012520:tid 1012671] [client 156.192.234.52:55082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKApXMN3p_zkwXf2PsQAAAJk"]
[Thu Sep 17 15:18:32.640935 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/public/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PsgAAALw"]
[Thu Sep 17 15:18:33.000089 2026] [core:error] [pid 1012520:tid 1012699] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:33.000117 2026] [core:error] [pid 1012520:tid 1012699] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:33.122680 2026] [security2:error] [pid 1012520:tid 1012717] [client 8.228.208.101:43866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/i.php"] [unique_id "aqxZKQpXMN3p_zkwXf2PuwAAAMc"]
[Thu Sep 17 15:18:33.176153 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/backend/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2PvAAAAPA"]
[Thu Sep 17 15:18:33.219557 2026] [security2:error] [pid 1012520:tid 1012636] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.bak"] [unique_id "aqxZKQpXMN3p_zkwXf2PwgAA73I"]
[Thu Sep 17 15:18:33.219582 2026] [security2:error] [pid 1012520:tid 1012635] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.backup"] [unique_id "aqxZKQpXMN3p_zkwXf2PvwAA73E"]
[Thu Sep 17 15:18:33.220511 2026] [security2:error] [pid 1012520:tid 1012636] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.old"] [unique_id "aqxZKQpXMN3p_zkwXf2PwwAA73I"]
[Thu Sep 17 15:18:33.462645 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/server/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P5wAAAPc"]
[Thu Sep 17 15:18:33.537573 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4AAAAPE"]
[Thu Sep 17 15:18:33.537573 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3QAAAIs"]
[Thu Sep 17 15:18:33.537578 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3wAAAKo"]
[Thu Sep 17 15:18:33.537588 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3gAAAOA"]
[Thu Sep 17 15:18:33.537617 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4gAAAOM"]
[Thu Sep 17 15:18:33.537702 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P5AAAAJE"]
[Thu Sep 17 15:18:33.537987 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4QAAALc"]
[Thu Sep 17 15:18:33.538357 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P2gAAANg"]
[Thu Sep 17 15:18:33.538500 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4wAAAMs"]
[Thu Sep 17 15:18:33.540201 2026] [security2:error] [pid 1012520:tid 1012522] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/.env.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P6wAA7wA"]
[Thu Sep 17 15:18:33.540967 2026] [security2:error] [pid 1012520:tid 1012636] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P7AAA73I"]
[Thu Sep 17 15:18:33.557542 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P2wAAAJg"]
[Thu Sep 17 15:18:33.558144 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P2QAAAJs"]
[Thu Sep 17 15:18:33.573422 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3AAAAPo"]
[Thu Sep 17 15:18:33.628922 2026] [authz_core:error] [pid 1012520:tid 1012761] [client 172.239.147.162:49455] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:33.689491 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/frontend/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P9gAAAIg"]
[Thu Sep 17 15:18:33.785341 2026] [security2:error] [pid 1012520:tid 1012683] [client 186.105.232.15:58172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-AAAAKU"]
[Thu Sep 17 15:18:33.785431 2026] [security2:error] [pid 1012520:tid 1012683] [client 186.105.232.15:58172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-AAAAKU"]
[Thu Sep 17 15:18:33.806912 2026] [security2:error] [pid 1012520:tid 1012687] [client 8.228.208.101:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-gAAAKk"]
[Thu Sep 17 15:18:33.928524 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/src/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P_AAAANo"]
[Thu Sep 17 15:18:33.948918 2026] [security2:error] [pid 1012520:tid 1012524] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env~"] [unique_id "aqxZKQpXMN3p_zkwXf2P_gAA7wI"]
[Thu Sep 17 15:18:33.948927 2026] [security2:error] [pid 1012520:tid 1012528] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.swp"] [unique_id "aqxZKQpXMN3p_zkwXf2P_wAA7wY"]
[Thu Sep 17 15:18:34.002360 2026] [security2:error] [pid 1012520:tid 1012695] [client 37.0.160.87:44632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-wAAsQU"]
[Thu Sep 17 15:18:34.104765 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/core/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QFAAAANI"]
[Thu Sep 17 15:18:34.325449 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.61.219.136:32009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QFwAAAPk"]
[Thu Sep 17 15:18:34.325715 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.61.219.136:32009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QFwAAAPk"]
[Thu Sep 17 15:18:34.328635 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/core/app/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QGAAAAOY"]
[Thu Sep 17 15:18:34.393274 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QDQAAALA"]
[Thu Sep 17 15:18:34.393833 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QEQAAAKg"]
[Thu Sep 17 15:18:34.393919 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P9AAAAMI"]
[Thu Sep 17 15:18:34.394030 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QDwAAAJ0"]
[Thu Sep 17 15:18:34.394055 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QDgAAAMo"]
[Thu Sep 17 15:18:34.395379 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QEgAAAN4"]
[Thu Sep 17 15:18:34.397833 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QEAAAAKI"]
[Thu Sep 17 15:18:34.400710 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P9QAAAOI"]
[Thu Sep 17 15:18:34.493476 2026] [security2:error] [pid 1012520:tid 1012773] [client 8.228.208.101:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QGwAAAP8"]
[Thu Sep 17 15:18:34.497494 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/config/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QHAAAAKw"]
[Thu Sep 17 15:18:34.645309 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/private/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QHgAAAK4"]
[Thu Sep 17 15:18:34.744780 2026] [security2:error] [pid 1012520:tid 1012755] [client 114.119.151.83:39925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ccrmediator.com"] [uri "/continuum"] [unique_id "aqxZKgpXMN3p_zkwXf2QIAAAAO0"], referer: https://ccrmediator.com/blog/
[Thu Sep 17 15:18:34.813761 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/application/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QIQAAAJg"]
[Thu Sep 17 15:18:34.838059 2026] [security2:error] [pid 1012520:tid 1012541] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/backend/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QJgAAmxM"]
[Thu Sep 17 15:18:34.838072 2026] [security2:error] [pid 1012520:tid 1012538] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/app/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QIwAAmxA"]
[Thu Sep 17 15:18:34.838099 2026] [security2:error] [pid 1012520:tid 1012543] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/server/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKAAAmxU"]
[Thu Sep 17 15:18:34.838189 2026] [security2:error] [pid 1012520:tid 1012537] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/api/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QIgAAmw8"]
[Thu Sep 17 15:18:34.838217 2026] [security2:error] [pid 1012520:tid 1012542] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/config/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKQAAmxQ"]
[Thu Sep 17 15:18:34.838263 2026] [security2:error] [pid 1012520:tid 1012544] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/src/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKgAAmxY"]
[Thu Sep 17 15:18:34.838287 2026] [security2:error] [pid 1012520:tid 1012547] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/web/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKwAAmxk"]
[Thu Sep 17 15:18:34.851225 2026] [autoindex:error] [pid 1012520:tid 1012741] [client 51.4.104.8:55555] AH01276: Cannot serve directory /home1/kurtshul/public_html/website_122f4dbc/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:18:35.031144 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QMAAAAOg"]
[Thu Sep 17 15:18:35.033809 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QMQAAALY"]
[Thu Sep 17 15:18:35.041223 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/bootstrap/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QNgAAAPM"]
[Thu Sep 17 15:18:35.068378 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QMgAAAL8"]
[Thu Sep 17 15:18:35.142297 2026] [security2:error] [pid 1012520:tid 1012561] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/prod/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRwAAxCc"]
[Thu Sep 17 15:18:35.142359 2026] [security2:error] [pid 1012520:tid 1012556] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/dev/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRgAAxCI"]
[Thu Sep 17 15:18:35.142358 2026] [security2:error] [pid 1012520:tid 1012558] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/back/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQwAAxCQ"]
[Thu Sep 17 15:18:35.142422 2026] [security2:error] [pid 1012520:tid 1012551] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/laravel/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQAAAxB0"]
[Thu Sep 17 15:18:35.142422 2026] [security2:error] [pid 1012520:tid 1012562] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/apps/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQgAAxCg"]
[Thu Sep 17 15:18:35.142451 2026] [security2:error] [pid 1012520:tid 1012553] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/frontend/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPAAAxB8"]
[Thu Sep 17 15:18:35.142502 2026] [security2:error] [pid 1012520:tid 1012545] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/backup/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRAAAxBc"]
[Thu Sep 17 15:18:35.142502 2026] [security2:error] [pid 1012520:tid 1012549] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/var/www/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QOwAAxBs"]
[Thu Sep 17 15:18:35.142508 2026] [security2:error] [pid 1012520:tid 1012550] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/public/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPgAAxBw"]
[Thu Sep 17 15:18:35.142534 2026] [security2:error] [pid 1012520:tid 1012554] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/application/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQQAAxCA"]
[Thu Sep 17 15:18:35.142538 2026] [security2:error] [pid 1012520:tid 1012555] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/var/www/html/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPQAAxCE"]
[Thu Sep 17 15:18:35.142570 2026] [security2:error] [pid 1012520:tid 1012546] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/client/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPwAAxBg"]
[Thu Sep 17 15:18:35.142595 2026] [security2:error] [pid 1012520:tid 1012557] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/cms/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRQAAxCM"]
[Thu Sep 17 15:18:35.187978 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.228.208.101:43882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/test.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QSAAAALQ"]
[Thu Sep 17 15:18:35.221606 2026] [security2:error] [pid 1012520:tid 1012777] [client 185.61.219.136:35457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QSQAAAQM"], referer: https://www.google.com
[Thu Sep 17 15:18:35.256647 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/database/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QSwAAANQ"]
[Thu Sep 17 15:18:35.425097 2026] [security2:error] [pid 1012520:tid 1012706] [client 190.114.37.77:13648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QTAAAvCU"]
[Thu Sep 17 15:18:35.446962 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/storage/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QTwAAALE"]
[Thu Sep 17 15:18:35.455567 2026] [core:error] [pid 1012520:tid 1012656] [client 51.4.104.8:56594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:35.455588 2026] [core:error] [pid 1012520:tid 1012656] [client 51.4.104.8:56594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:35.676797 2026] [security2:error] [pid 1012520:tid 1012574] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/aws/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYwAAsjQ"]
[Thu Sep 17 15:18:35.676793 2026] [security2:error] [pid 1012520:tid 1012570] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.docker/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYQAAsjA"]
[Thu Sep 17 15:18:35.676796 2026] [security2:error] [pid 1012520:tid 1012639] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/old/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVAAAsnU"]
[Thu Sep 17 15:18:35.676841 2026] [security2:error] [pid 1012520:tid 1012573] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/server/backend/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYAAAsjM"]
[Thu Sep 17 15:18:35.676851 2026] [security2:error] [pid 1012520:tid 1012568] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/api-backend/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWgAAsi4"]
[Thu Sep 17 15:18:35.676897 2026] [security2:error] [pid 1012520:tid 1012579] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/server/api/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXwAAsjk"]
[Thu Sep 17 15:18:35.676897 2026] [security2:error] [pid 1012520:tid 1012576] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYgAAsjY"]
[Thu Sep 17 15:18:35.676936 2026] [security2:error] [pid 1012520:tid 1012564] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/production/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVgAAsio"]
[Thu Sep 17 15:18:35.676936 2026] [security2:error] [pid 1012520:tid 1012572] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/test/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVwAAsjI"]
[Thu Sep 17 15:18:35.676945 2026] [security2:error] [pid 1012520:tid 1012571] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/admin-app/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWwAAsjE"]
[Thu Sep 17 15:18:35.676982 2026] [security2:error] [pid 1012520:tid 1012540] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/new/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWAAAshI"]
[Thu Sep 17 15:18:35.677012 2026] [security2:error] [pid 1012520:tid 1012575] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/current/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXgAAsjU"]
[Thu Sep 17 15:18:35.677063 2026] [security2:error] [pid 1012520:tid 1012552] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/staging/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVQAAsh4"]
[Thu Sep 17 15:18:35.677089 2026] [security2:error] [pid 1012520:tid 1012580] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/public_html/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXQAAsjo"]
[Thu Sep 17 15:18:35.677106 2026] [security2:error] [pid 1012520:tid 1012567] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/node-api/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWQAAsi0"]
[Thu Sep 17 15:18:35.689241 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/var/www/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QZAAAAOU"]
[Thu Sep 17 15:18:35.704676 2026] [security2:error] [pid 1012520:tid 1012569] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/administrator/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXAAAsi8"]
[Thu Sep 17 15:18:35.873801 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/var/www/html/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QaQAAAJ0"]
[Thu Sep 17 15:18:35.895292 2026] [authz_core:error] [pid 1012520:tid 1012659] [client 172.239.147.162:56518] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:35.940196 2026] [security2:error] [pid 1012520:tid 1012697] [client 104.28.198.244:22537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QcAAAALM"]
[Thu Sep 17 15:18:35.940327 2026] [security2:error] [pid 1012520:tid 1012697] [client 104.28.198.244:22537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QcAAAALM"]
[Thu Sep 17 15:18:36.097368 2026] [security2:error] [pid 1012520:tid 1012694] [client 185.61.219.136:21717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZLApXMN3p_zkwXf2QcwAAALA"], referer: https://www.google.com
[Thu Sep 17 15:18:36.104340 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/current/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QdAAAAMY"]
[Thu Sep 17 15:18:36.109139 2026] [security2:error] [pid 1012520:tid 1012712] [client 51.4.104.8:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.104.4.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.kurtshuler.com"] [uri "/wp-login.php"] [unique_id "aqxZLApXMN3p_zkwXf2QcgAAAMI"]
[Thu Sep 17 15:18:36.196307 2026] [security2:error] [pid 1012520:tid 1012581] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/v1/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QegAA8Ts"]
[Thu Sep 17 15:18:36.196387 2026] [security2:error] [pid 1012520:tid 1012582] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/v3/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QewAA8Tw"]
[Thu Sep 17 15:18:36.196447 2026] [security2:error] [pid 1012520:tid 1012577] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.aws/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QdQAA8Tc"]
[Thu Sep 17 15:18:36.196473 2026] [security2:error] [pid 1012520:tid 1012566] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/stripe/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QeAAA8Sw"]
[Thu Sep 17 15:18:36.196593 2026] [security2:error] [pid 1012520:tid 1012586] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/media/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QfAAA8UA"]
[Thu Sep 17 15:18:36.196623 2026] [security2:error] [pid 1012520:tid 1012584] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/v2/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QdwAA8T4"]
[Thu Sep 17 15:18:36.302810 2026] [security2:error] [pid 1012520:tid 1012692] [client 8.228.208.101:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/p.php"] [unique_id "aqxZLApXMN3p_zkwXf2QmQAAAK4"]
[Thu Sep 17 15:18:36.328950 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/release/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QmwAAAM4"]
[Thu Sep 17 15:18:36.410111 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkAAAAKQ"]
[Thu Sep 17 15:18:36.413469 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QjwAAANE"]
[Thu Sep 17 15:18:36.414969 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkQAAAPQ"]
[Thu Sep 17 15:18:36.420744 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkgAAANs"]
[Thu Sep 17 15:18:36.420914 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlAAAAP4"]
[Thu Sep 17 15:18:36.421521 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlQAAAO8"]
[Thu Sep 17 15:18:36.426458 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkwAAAIk"]
[Thu Sep 17 15:18:36.428075 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlgAAAM0"]
[Thu Sep 17 15:18:36.455577 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlwAAAKw"]
[Thu Sep 17 15:18:36.455861 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QmAAAAQQ"]
[Thu Sep 17 15:18:36.508390 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/releases/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QogAAAIU"]
[Thu Sep 17 15:18:36.529407 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QngAAAJ8"]
[Thu Sep 17 15:18:36.691187 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/shared/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QpgAAAPU"]
[Thu Sep 17 15:18:36.716124 2026] [core:error] [pid 1012520:tid 1012707] [client 51.4.104.8:59011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:36.716140 2026] [core:error] [pid 1012520:tid 1012707] [client 51.4.104.8:59011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:36.899756 2026] [security2:error] [pid 1012520:tid 1012605] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.git/config.bak"] [unique_id "aqxZLApXMN3p_zkwXf2QsgAA1FM"]
[Thu Sep 17 15:18:36.951244 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/deploy/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QvAAAANM"]
[Thu Sep 17 15:18:36.966282 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QqwAAAL4"]
[Thu Sep 17 15:18:36.992313 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.228.208.101:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxZLApXMN3p_zkwXf2QvwAAALQ"]
[Thu Sep 17 15:18:37.055615 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QuQAAAOU"]
[Thu Sep 17 15:18:37.057615 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QuwAAAJU"]
[Thu Sep 17 15:18:37.062707 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QugAAAPg"]
[Thu Sep 17 15:18:37.064715 2026] [security2:error] [pid 1012520:tid 1012699] [client 45.169.98.18:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QwwAAALU"]
[Thu Sep 17 15:18:37.066585 2026] [security2:error] [pid 1012520:tid 1012699] [client 45.169.98.18:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QwwAAALU"]
[Thu Sep 17 15:18:37.067312 2026] [security2:error] [pid 1012520:tid 1012658] [client 74.7.230.10:43932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "blu.uua.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxZLQpXMN3p_zkwXf2QwgAAjFU"]
[Thu Sep 17 15:18:37.149111 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/build/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2QxgAAAPc"]
[Thu Sep 17 15:18:37.295454 2026] [authz_core:error] [pid 1012520:tid 1012774] [client 172.239.147.162:60344] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:18:37.297475 2026] [security2:error] [pid 1012520:tid 1012720] [client 51.4.104.8:59895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.104.4.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.kurtshuler.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q0AAAAMo"]
[Thu Sep 17 15:18:37.308111 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/dist/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q0QAAAPQ"]
[Thu Sep 17 15:18:37.337425 2026] [security2:error] [pid 1012520:tid 1012760] [client 186.33.67.131:54512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QyQAA8lk"]
[Thu Sep 17 15:18:37.378279 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QywAAAK8"]
[Thu Sep 17 15:18:37.407569 2026] [security2:error] [pid 1012520:tid 1012732] [client 5.189.145.112:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q1gAAANY"], referer: binance.com
[Thu Sep 17 15:18:37.502946 2026] [security2:error] [pid 1012520:tid 1012654] [client 185.61.219.136:11275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QvgAAAIg"], referer: https://www.google.com
[Thu Sep 17 15:18:37.542891 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/public_html/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q2wAAAQE"]
[Thu Sep 17 15:18:37.547554 2026] [security2:error] [pid 1012520:tid 1012688] [client 74.7.230.1:36776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.qwr.qfv.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxZLQpXMN3p_zkwXf2Q3AAAAKo"]
[Thu Sep 17 15:18:37.591798 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q2AAAAJg"]
[Thu Sep 17 15:18:37.698598 2026] [security2:error] [pid 1012520:tid 1012741] [client 8.228.208.101:43920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q4wAAAN8"]
[Thu Sep 17 15:18:37.710327 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/htdocs/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q5AAAAJs"]
[Thu Sep 17 15:18:37.752390 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q4gAAAJQ"]
[Thu Sep 17 15:18:37.753227 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q4QAAAMs"]
[Thu Sep 17 15:18:37.907874 2026] [core:error] [pid 1012520:tid 1012725] [client 51.4.104.8:60667] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:37.907893 2026] [core:error] [pid 1012520:tid 1012725] [client 51.4.104.8:60667] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:37.940914 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/www/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q6AAAANw"]
[Thu Sep 17 15:18:38.186939 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/html/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2Q-QAAAJ4"]
[Thu Sep 17 15:18:38.238608 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q9gAAANI"]
[Thu Sep 17 15:18:38.240693 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q9QAAAMA"]
[Thu Sep 17 15:18:38.259485 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q9wAAANM"]
[Thu Sep 17 15:18:38.386029 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.228.208.101:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q-gAAAJ0"]
[Thu Sep 17 15:18:38.397463 2026] [security2:error] [pid 1012520:tid 1012620] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxZLgpXMN3p_zkwXf2Q_AAAoGI"]
[Thu Sep 17 15:18:38.397504 2026] [security2:error] [pid 1012520:tid 1012631] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/id_rsa"] [unique_id "aqxZLgpXMN3p_zkwXf2RAAAAoG0"]
[Thu Sep 17 15:18:38.397521 2026] [security2:error] [pid 1012520:tid 1012617] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxZLgpXMN3p_zkwXf2Q_gAAoF8"]
[Thu Sep 17 15:18:38.399593 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/live/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RBQAAALw"]
[Thu Sep 17 15:18:38.551524 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RDwAAAMk"]
[Thu Sep 17 15:18:38.552248 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RDgAAALg"]
[Thu Sep 17 15:18:38.552249 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2REAAAAN4"]
[Thu Sep 17 15:18:38.574376 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RDQAAAKk"]
[Thu Sep 17 15:18:38.587082 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RFgAAAMY"]
[Thu Sep 17 15:18:38.604472 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/prod/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RGwAAAKU"]
[Thu Sep 17 15:18:38.662597 2026] [security2:error] [pid 1012520:tid 1012694] [client 185.55.149.49:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLAAAALA"]
[Thu Sep 17 15:18:38.662736 2026] [security2:error] [pid 1012520:tid 1012694] [client 185.55.149.49:64319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLAAAALA"]
[Thu Sep 17 15:18:38.778432 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/dev/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RPgAAAME"]
[Thu Sep 17 15:18:38.793955 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RJwAAAI8"]
[Thu Sep 17 15:18:38.807156 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLQAAAIg"]
[Thu Sep 17 15:18:38.812190 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLgAAALY"]
[Thu Sep 17 15:18:38.812235 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RKAAAANg"]
[Thu Sep 17 15:18:38.866021 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RNQAAAJg"]
[Thu Sep 17 15:18:38.890965 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2ROQAAAJo"]
[Thu Sep 17 15:18:38.948985 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/staging/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RUAAAAOw"]
[Thu Sep 17 15:18:38.957699 2026] [security2:error] [pid 1012520:tid 1012531] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RUQAA8gk"]
[Thu Sep 17 15:18:39.017070 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRAAAAMw"]
[Thu Sep 17 15:18:39.081320 2026] [security2:error] [pid 1012520:tid 1012735] [client 8.228.208.101:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZgAAANk"]
[Thu Sep 17 15:18:39.115131 2026] [security2:error] [pid 1012520:tid 1012657] [client 154.190.208.131:41863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZwAAAIs"]
[Thu Sep 17 15:18:39.115249 2026] [security2:error] [pid 1012520:tid 1012657] [client 154.190.208.131:41863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZwAAAIs"]
[Thu Sep 17 15:18:39.148374 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/opt/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RaQAAAJU"]
[Thu Sep 17 15:18:39.262955 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRgAAAMs"]
[Thu Sep 17 15:18:39.278629 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRQAAAIU"]
[Thu Sep 17 15:18:39.300090 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RTgAAAOE"]
[Thu Sep 17 15:18:39.301077 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RSAAAANQ"]
[Thu Sep 17 15:18:39.307397 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRwAAAMg"]
[Thu Sep 17 15:18:39.313414 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/laravel/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RcwAAAM4"]
[Thu Sep 17 15:18:39.423042 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RVwAAAO4"]
[Thu Sep 17 15:18:39.423275 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RXwAAAPU"]
[Thu Sep 17 15:18:39.426204 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RcAAAAIo"]
[Thu Sep 17 15:18:39.427129 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZQAAAQM"]
[Thu Sep 17 15:18:39.427377 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RcQAAAMI"]
[Thu Sep 17 15:18:39.435967 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RYgAAAMQ"]
[Thu Sep 17 15:18:39.457363 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RcgAAANU"]
[Thu Sep 17 15:18:39.512954 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/symfony/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2ReAAAAJw"]
[Thu Sep 17 15:18:39.549957 2026] [security2:error] [pid 1012520:tid 1012558] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/aws.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RfgAAiSQ"]
[Thu Sep 17 15:18:39.576609 2026] [security2:error] [pid 1012520:tid 1012545] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/mail.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RgwAAiRc"]
[Thu Sep 17 15:18:39.576614 2026] [security2:error] [pid 1012520:tid 1012549] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/config.inc.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RhQAAiRs"]
[Thu Sep 17 15:18:39.576633 2026] [security2:error] [pid 1012520:tid 1012562] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/stripe.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RggAAiSg"]
[Thu Sep 17 15:18:39.602431 2026] [security2:error] [pid 1012520:tid 1012554] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/nexmo.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RiAAAiSA"]
[Thu Sep 17 15:18:39.681088 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/wordpress/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RjwAAAOA"]
[Thu Sep 17 15:18:39.698785 2026] [security2:error] [pid 1012520:tid 1012557] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/wp-config.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RkgAAiSM"]
[Thu Sep 17 15:18:39.712878 2026] [security2:error] [pid 1012520:tid 1012559] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.bak"] [unique_id "aqxZLwpXMN3p_zkwXf2RlgAAiSU"]
[Thu Sep 17 15:18:39.712882 2026] [security2:error] [pid 1012520:tid 1012570] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.new"] [unique_id "aqxZLwpXMN3p_zkwXf2RmAAAiTA"]
[Thu Sep 17 15:18:39.712884 2026] [security2:error] [pid 1012520:tid 1012639] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.old"] [unique_id "aqxZLwpXMN3p_zkwXf2RlwAAiXU"]
[Thu Sep 17 15:18:39.713242 2026] [security2:error] [pid 1012520:tid 1012574] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxZLwpXMN3p_zkwXf2RmQAAiTQ"]
[Thu Sep 17 15:18:39.766295 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.228.208.101:43948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RmwAAAJE"]
[Thu Sep 17 15:18:39.766786 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RigAAAJs"]
[Thu Sep 17 15:18:39.846471 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RlQAAAPM"]
[Thu Sep 17 15:18:39.849197 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RkQAAAMU"]
[Thu Sep 17 15:18:39.851611 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RkwAAAOw"]
[Thu Sep 17 15:18:39.857435 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RlAAAANw"]
[Thu Sep 17 15:18:39.871031 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RmgAAAMc"]
[Thu Sep 17 15:18:39.899929 2026] [security2:error] [pid 1012520:tid 1012579] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxZLwpXMN3p_zkwXf2RoAAAiTk"]
[Thu Sep 17 15:18:39.923198 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/wp/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RpQAAAIs"]
[Thu Sep 17 15:18:39.957987 2026] [authz_core:error] [pid 1012520:tid 1012710] [client 172.239.147.162:51268] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:18:40.081346 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cms/.env"] [unique_id "aqxZMApXMN3p_zkwXf2RsQAAAOY"]
[Thu Sep 17 15:18:40.235532 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/drupal/.env"] [unique_id "aqxZMApXMN3p_zkwXf2RuAAAAN4"]
[Thu Sep 17 15:18:40.247463 2026] [security2:error] [pid 1012520:tid 1012552] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxZMApXMN3p_zkwXf2RuQAAiR4"]
[Thu Sep 17 15:18:40.300343 2026] [security2:error] [pid 1012520:tid 1012568] [remote 34.156.22.151:55556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RogAAiS4"]
[Thu Sep 17 15:18:40.304653 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RpgAAAPs"]
[Thu Sep 17 15:18:40.383477 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RtQAAAMk"]
[Thu Sep 17 15:18:40.452315 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZMApXMN3p_zkwXf2R0AAAAKw"]
[Thu Sep 17 15:18:40.467569 2026] [security2:error] [pid 1012520:tid 1012756] [client 85.208.96.203:36112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thehivetribe.com"] [uri "/robots.txt"] [unique_id "aqxZMApXMN3p_zkwXf2R0QAAAO4"]
[Thu Sep 17 15:18:40.467706 2026] [security2:error] [pid 1012520:tid 1012756] [client 85.208.96.203:36112] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thehivetribe.com"] [uri "/robots.txt"] [unique_id "aqxZMApXMN3p_zkwXf2R0QAAAO4"]
[Thu Sep 17 15:18:40.505279 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:54786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMApXMN3p_zkwXf2R1AAAAOE"]
[Thu Sep 17 15:18:40.505384 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:54786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMApXMN3p_zkwXf2R1AAAAOE"]
[Thu Sep 17 15:18:40.506946 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RvgAAAM4"]
[Thu Sep 17 15:18:40.527004 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RxwAAAOI"]
[Thu Sep 17 15:18:40.536247 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RzAAAANE"]
[Thu Sep 17 15:18:40.549732 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RzQAAAMY"]
[Thu Sep 17 15:18:40.558405 2026] [security2:error] [pid 1012520:tid 1012704] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/joomla/.env"] [unique_id "aqxZMApXMN3p_zkwXf2R1gAAALo"]
[Thu Sep 17 15:18:40.663713 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R1QAAAMI"]
[Thu Sep 17 15:18:40.732035 2026] [security2:error] [pid 1012520:tid 1012711] [client 85.208.96.196:62232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thehivetribe.com"] [uri "/"] [unique_id "aqxZMApXMN3p_zkwXf2R3AAAAME"]
[Thu Sep 17 15:18:40.732174 2026] [security2:error] [pid 1012520:tid 1012711] [client 85.208.96.196:62232] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thehivetribe.com"] [uri "/"] [unique_id "aqxZMApXMN3p_zkwXf2R3AAAAME"]
[Thu Sep 17 15:18:40.791460 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R2wAAAO0"]
[Thu Sep 17 15:18:40.803507 2026] [security2:error] [pid 1012520:tid 1012733] [client 57.141.14.33:43684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RGgAA13I"]
[Thu Sep 17 15:18:40.804394 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/magento/.env"] [unique_id "aqxZMApXMN3p_zkwXf2R5AAAALA"]
[Thu Sep 17 15:18:40.918561 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R4wAAALY"]
[Thu Sep 17 15:18:40.953503 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R5QAAAOA"]
[Thu Sep 17 15:18:40.963736 2026] [security2:error] [pid 1012520:tid 1012736] [client 134.185.85.61:55237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "groverpdx.net"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxZMApXMN3p_zkwXf2R6QAAANo"]
[Thu Sep 17 15:18:41.135801 2026] [security2:error] [pid 1012520:tid 1012673] [client 8.228.208.101:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R_gAAAJs"]
[Thu Sep 17 15:18:41.145021 2026] [authz_core:error] [pid 1012520:tid 1012764] [client 43.130.102.7:60732] AH01630: client denied by server configuration: /home4/glassbl4/public_html/fireflyhotglass/glass/wp-content/plugins/events-manager/multilingual/error_log
[Thu Sep 17 15:18:41.244547 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R_QAAAOU"]
[Thu Sep 17 15:18:41.244552 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R-gAAAM8"]
[Thu Sep 17 15:18:41.244555 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R_AAAAIs"]
[Thu Sep 17 15:18:41.249195 2026] [security2:error] [pid 1012520:tid 1012761] [client 185.61.219.136:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SBQAAAPM"]
[Thu Sep 17 15:18:41.249289 2026] [security2:error] [pid 1012520:tid 1012761] [client 185.61.219.136:62981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SBQAAAPM"]
[Thu Sep 17 15:18:41.249503 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R-AAAAJQ"]
[Thu Sep 17 15:18:41.262310 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R-wAAAKI"]
[Thu Sep 17 15:18:41.347360 2026] [security2:error] [pid 1012520:tid 1012730] [client 134.185.85.61:50054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "groverpdx.net"] [uri "/media/system/js/core.js"] [unique_id "aqxZMQpXMN3p_zkwXf2SDgAAANQ"]
[Thu Sep 17 15:18:41.460675 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SDQAAANI"]
[Thu Sep 17 15:18:41.542634 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/shopify/.env"] [unique_id "aqxZMQpXMN3p_zkwXf2SLwAAAMs"]
[Thu Sep 17 15:18:41.624760 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SGwAAAKw"]
[Thu Sep 17 15:18:41.704908 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SLgAAAOM"]
[Thu Sep 17 15:18:41.720505 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMAAAAOc"]
[Thu Sep 17 15:18:41.726521 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNAAAALk"]
[Thu Sep 17 15:18:41.728054 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMwAAAQI"]
[Thu Sep 17 15:18:41.732824 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMgAAANA"]
[Thu Sep 17 15:18:41.732926 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNQAAANY"]
[Thu Sep 17 15:18:41.746494 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNwAAAPE"]
[Thu Sep 17 15:18:41.747211 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMQAAAMo"]
[Thu Sep 17 15:18:41.759213 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNgAAAPc"]
[Thu Sep 17 15:18:41.769263 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/prestashop/.env"] [unique_id "aqxZMQpXMN3p_zkwXf2SQAAAAOw"]
[Thu Sep 17 15:18:41.774200 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SOwAAAJk"]
[Thu Sep 17 15:18:41.915153 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/codeigniter/.env"] [unique_id "aqxZMQpXMN3p_zkwXf2STgAAAM8"]
[Thu Sep 17 15:18:41.957361 2026] [security2:error] [pid 1012520:tid 1012624] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/info.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SWAAA3GY"]
[Thu Sep 17 15:18:41.957369 2026] [security2:error] [pid 1012520:tid 1012623] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/phpinfo.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SVgAA3GU"]
[Thu Sep 17 15:18:41.965408 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SRAAAAPY"]
[Thu Sep 17 15:18:42.051063 2026] [security2:error] [pid 1012520:tid 1012626] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/infos.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYQAA3Gg"]
[Thu Sep 17 15:18:42.072004 2026] [security2:error] [pid 1012520:tid 1012642] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/php.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYwAA3Hg"]
[Thu Sep 17 15:18:42.071999 2026] [security2:error] [pid 1012520:tid 1012643] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/php_info.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYgAA3Hk"]
[Thu Sep 17 15:18:42.098759 2026] [security2:error] [pid 1012520:tid 1012652] [client 172.239.147.162:49923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZgAAAIY"], referer: binance.com
[Thu Sep 17 15:18:42.106654 2026] [security2:error] [pid 1012520:tid 1012632] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/php-info.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZwAA3G4"]
[Thu Sep 17 15:18:42.106692 2026] [security2:error] [pid 1012520:tid 1012634] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/infophp.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SaAAA3HA"]
[Thu Sep 17 15:18:42.115451 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cakephp/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SaQAAANI"]
[Thu Sep 17 15:18:42.127150 2026] [security2:error] [pid 1012520:tid 1012686] [client 185.61.219.136:39779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SawAAAKg"], referer: https://www.google.com
[Thu Sep 17 15:18:42.194233 2026] [security2:error] [pid 1012520:tid 1012525] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2ScAAA3AM"]
[Thu Sep 17 15:18:42.222953 2026] [security2:error] [pid 1012520:tid 1012637] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2ScwAA3HM"]
[Thu Sep 17 15:18:42.223017 2026] [security2:error] [pid 1012520:tid 1012633] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdAAA3G8"]
[Thu Sep 17 15:18:42.242160 2026] [security2:error] [pid 1012520:tid 1012644] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/api/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdQAA3Ho"]
[Thu Sep 17 15:18:42.242192 2026] [security2:error] [pid 1012520:tid 1012616] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdgAA3F4"]
[Thu Sep 17 15:18:42.270852 2026] [security2:error] [pid 1012520:tid 1012718] [client 8.228.208.101:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdwAAAMg"]
[Thu Sep 17 15:18:42.284757 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SWwAAAOY"]
[Thu Sep 17 15:18:42.287630 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SXAAAAL8"]
[Thu Sep 17 15:18:42.315520 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/zend/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SegAAAMk"]
[Thu Sep 17 15:18:42.339656 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SXgAAAN8"]
[Thu Sep 17 15:18:42.339684 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYAAAAPs"]
[Thu Sep 17 15:18:42.386524 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZQAAAJU"]
[Thu Sep 17 15:18:42.387287 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SagAAANQ"]
[Thu Sep 17 15:18:42.396072 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZAAAAKo"]
[Thu Sep 17 15:18:42.464802 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SeAAAAKU"]
[Thu Sep 17 15:18:42.514005 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SggAAAOc"]
[Thu Sep 17 15:18:42.520285 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SjAAAANc"]
[Thu Sep 17 15:18:42.536610 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/yii/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SkgAAANo"]
[Thu Sep 17 15:18:42.549017 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SjwAAALY"]
[Thu Sep 17 15:18:42.551681 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SkAAAAJ8"]
[Thu Sep 17 15:18:42.668512 2026] [security2:error] [pid 1012520:tid 1012544] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/database.sql"] [unique_id "aqxZMgpXMN3p_zkwXf2SlQAA2RY"]
[Thu Sep 17 15:18:42.833151 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SogAAAJc"]
[Thu Sep 17 15:18:42.833847 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SoQAAAPY"]
[Thu Sep 17 15:18:42.862504 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SpAAAALg"]
[Thu Sep 17 15:18:42.864227 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SowAAALw"]
[Thu Sep 17 15:18:42.864553 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/laravel5/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SuAAAANI"]
[Thu Sep 17 15:18:42.872104 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SpwAAAOs"]
[Thu Sep 17 15:18:42.878248 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SpgAAAOQ"]
[Thu Sep 17 15:18:42.907710 2026] [security2:error] [pid 1012520:tid 1012533] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/env.backup"] [unique_id "aqxZMgpXMN3p_zkwXf2SvQAA2Qs"]
[Thu Sep 17 15:18:42.952231 2026] [security2:error] [pid 1012520:tid 1012771] [client 8.228.208.101:41266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SwwAAAP0"]
[Thu Sep 17 15:18:42.999772 2026] [security2:error] [pid 1012520:tid 1012725] [client 185.61.219.136:53763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SxgAAAM8"], referer: https://www.google.com
[Thu Sep 17 15:18:43.001822 2026] [security2:error] [pid 1012520:tid 1012562] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/configuration.php.old"] [unique_id "aqxZMwpXMN3p_zkwXf2SyAAA2Sg"]
[Thu Sep 17 15:18:43.011584 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/v1/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2SzgAAAQQ"]
[Thu Sep 17 15:18:43.128894 2026] [security2:error] [pid 1012520:tid 1012693] [client 156.192.234.52:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S1gAAAK8"]
[Thu Sep 17 15:18:43.130047 2026] [security2:error] [pid 1012520:tid 1012693] [client 156.192.234.52:55708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S1gAAAK8"]
[Thu Sep 17 15:18:43.186921 2026] [security2:error] [pid 1012520:tid 1012548] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/kyc/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S2QAA2Ro"]
[Thu Sep 17 15:18:43.187102 2026] [security2:error] [pid 1012520:tid 1012574] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/site.bak"] [unique_id "aqxZMwpXMN3p_zkwXf2S2AAA2TQ"]
[Thu Sep 17 15:18:43.210091 2026] [security2:error] [pid 1012520:tid 1012553] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.save"] [unique_id "aqxZMwpXMN3p_zkwXf2S3wAA2R8"]
[Thu Sep 17 15:18:43.213974 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/v2/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S4QAAAKU"]
[Thu Sep 17 15:18:43.372205 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2StgAAAIY"]
[Thu Sep 17 15:18:43.405568 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SvAAAAPs"]
[Thu Sep 17 15:18:43.408826 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5AAAAQE"]
[Thu Sep 17 15:18:43.410773 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SvgAAAN0"]
[Thu Sep 17 15:18:43.411743 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S0QAAAOM"]
[Thu Sep 17 15:18:43.411909 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5gAAAOc"]
[Thu Sep 17 15:18:43.411970 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SxQAAAPI"]
[Thu Sep 17 15:18:43.412052 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5wAAANc"]
[Thu Sep 17 15:18:43.416066 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/v3/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S8QAAAJI"]
[Thu Sep 17 15:18:43.416298 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SuQAAAP4"]
[Thu Sep 17 15:18:43.417554 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SugAAAKg"]
[Thu Sep 17 15:18:43.425506 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5QAAAJ4"]
[Thu Sep 17 15:18:43.598500 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/v1/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S8wAAAN4"]
[Thu Sep 17 15:18:43.636967 2026] [security2:error] [pid 1012520:tid 1012658] [client 8.228.208.101:41280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S9AAAAIw"]
[Thu Sep 17 15:18:43.639865 2026] [security2:error] [pid 1012520:tid 1012576] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/mysql.sql"] [unique_id "aqxZMwpXMN3p_zkwXf2S9gAAlzY"]
[Thu Sep 17 15:18:43.681135 2026] [security2:error] [pid 1012520:tid 1012572] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/node/api/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S-gAAlzI"]
[Thu Sep 17 15:18:43.750679 2026] [security2:error] [pid 1012520:tid 1012552] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/gcp/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S_wAAlx4"]
[Thu Sep 17 15:18:43.852676 2026] [security2:error] [pid 1012520:tid 1012713] [client 169.58.197.253:61737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ppfc.net"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S6AAAAMM"], referer: binance.com
[Thu Sep 17 15:18:43.882193 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S-wAAANE"]
[Thu Sep 17 15:18:43.938208 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2TAgAAAOo"]
[Thu Sep 17 15:18:43.939372 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/v2/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2TCgAAAL8"]
[Thu Sep 17 15:18:43.949526 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2TAwAAAKA"]
[Thu Sep 17 15:18:44.240886 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/rest/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TDgAAAQQ"]
[Thu Sep 17 15:18:44.324334 2026] [security2:error] [pid 1012520:tid 1012719] [client 8.228.208.101:41288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxZNApXMN3p_zkwXf2TEQAAAMk"]
[Thu Sep 17 15:18:44.406701 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/graphql/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TEgAAAKc"]
[Thu Sep 17 15:18:44.590873 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/gateway/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TGAAAAOU"]
[Thu Sep 17 15:18:44.662986 2026] [security2:error] [pid 1012520:tid 1012682] [client 185.61.219.136:47769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxZNApXMN3p_zkwXf2TDwAAAKQ"], referer: https://www.google.com
[Thu Sep 17 15:18:44.761208 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/microservice/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TGgAAAJY"]
[Thu Sep 17 15:18:44.988832 2026] [security2:error] [pid 1012520:tid 1012745] [client 5.189.145.112:49766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxZNApXMN3p_zkwXf2THwAAAOM"], referer: binance.com
[Thu Sep 17 15:18:45.018139 2026] [security2:error] [pid 1012520:tid 1012765] [client 8.228.208.101:41302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TIAAAAPc"]
[Thu Sep 17 15:18:45.038858 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/service/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TIwAAANc"]
[Thu Sep 17 15:18:45.121774 2026] [security2:error] [pid 1012520:tid 1012758] [client 186.105.232.15:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TKAAAAPA"]
[Thu Sep 17 15:18:45.121922 2026] [security2:error] [pid 1012520:tid 1012758] [client 186.105.232.15:58745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TKAAAAPA"]
[Thu Sep 17 15:18:45.151485 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TJAAAAJk"]
[Thu Sep 17 15:18:45.255988 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/v3/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TKwAAALk"]
[Thu Sep 17 15:18:45.512014 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/dev/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TMQAAAMI"]
[Thu Sep 17 15:18:45.693395 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/staging/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TNgAAAIk"]
[Thu Sep 17 15:18:45.704142 2026] [security2:error] [pid 1012520:tid 1012772] [client 8.228.208.101:41310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TNwAAAP4"]
[Thu Sep 17 15:18:45.922734 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/vendor/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TPQAAAOE"]
[Thu Sep 17 15:18:46.088700 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TQAAAAKE"]
[Thu Sep 17 15:18:46.160334 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/lib/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TQgAAALE"]
[Thu Sep 17 15:18:46.391418 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/resources/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TSgAAAJM"]
[Thu Sep 17 15:18:46.511168 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNgpXMN3p_zkwXf2TRwAAAL8"]
[Thu Sep 17 15:18:46.625120 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/assets/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TUwAAAM8"]
[Thu Sep 17 15:18:46.790337 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/uploads/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TVgAAAPU"]
[Thu Sep 17 15:18:46.941386 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/internal/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TXAAAAIc"]
[Thu Sep 17 15:18:47.045708 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNgpXMN3p_zkwXf2TXQAAAKc"]
[Thu Sep 17 15:18:47.160871 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/tools/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TZQAAANY"]
[Thu Sep 17 15:18:47.296422 2026] [security2:error] [pid 1012520:tid 1012739] [client 8.228.208.101:41318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZNwpXMN3p_zkwXf2TawAAAN0"]
[Thu Sep 17 15:18:47.316789 2026] [security2:error] [pid 1012520:tid 1012668] [client 69.165.72.150:50151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.72.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xom.dyz.mybluehost.me"] [uri "/index.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TbAAAAJY"], referer: https://mail.xom.dyz.mybluehost.me
[Thu Sep 17 15:18:47.380048 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TagAAAJ8"]
[Thu Sep 17 15:18:47.401436 2026] [core:error] [pid 1012520:tid 1012749] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:47.401456 2026] [core:error] [pid 1012520:tid 1012749] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:47.425242 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/scripts/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TcgAAAL0"]
[Thu Sep 17 15:18:47.567718 2026] [security2:error] [pid 1012520:tid 1012723] [client 45.169.98.18:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TeAAAAM0"]
[Thu Sep 17 15:18:47.569643 2026] [security2:error] [pid 1012520:tid 1012723] [client 45.169.98.18:64064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TeAAAAM0"]
[Thu Sep 17 15:18:47.595374 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/bin/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TeQAAAKg"]
[Thu Sep 17 15:18:47.765201 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TewAAAJ4"]
[Thu Sep 17 15:18:47.876823 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sbin/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TfgAAAI0"]
[Thu Sep 17 15:18:47.998838 2026] [security2:error] [pid 1012520:tid 1012721] [client 8.228.208.101:41334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TggAAAMs"]
[Thu Sep 17 15:18:48.067576 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/local/.env"] [unique_id "aqxZOApXMN3p_zkwXf2ThAAAALg"]
[Thu Sep 17 15:18:48.218115 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/portal/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TiAAAAMM"]
[Thu Sep 17 15:18:48.297248 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOApXMN3p_zkwXf2ThwAAAP8"]
[Thu Sep 17 15:18:48.464011 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/dashboard/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TjgAAAM4"]
[Thu Sep 17 15:18:48.580269 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOApXMN3p_zkwXf2TjwAAAOo"]
[Thu Sep 17 15:18:48.634626 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/panel/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TkwAAAK0"]
[Thu Sep 17 15:18:48.679685 2026] [security2:error] [pid 1012520:tid 1012695] [client 8.228.208.101:41340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZOApXMN3p_zkwXf2TlAAAALE"]
[Thu Sep 17 15:18:48.786735 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.bak"] [unique_id "aqxZOApXMN3p_zkwXf2TlgAAAOs"]
[Thu Sep 17 15:18:48.833833 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/crm/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TmQAAANI"]
[Thu Sep 17 15:18:49.007887 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.backup"] [unique_id "aqxZOQpXMN3p_zkwXf2TnAAAAIg"]
[Thu Sep 17 15:18:49.120340 2026] [security2:error] [pid 1012520:tid 1012684] [client 134.185.85.61:60496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "vagabondhiker.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxZOQpXMN3p_zkwXf2ToQAAAKY"]
[Thu Sep 17 15:18:49.150460 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/erp/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TogAAANQ"]
[Thu Sep 17 15:18:49.371796 2026] [security2:error] [pid 1012520:tid 1012685] [client 8.228.208.101:41350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TpgAAAKc"]
[Thu Sep 17 15:18:49.393545 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/shop/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TpwAAAI8"]
[Thu Sep 17 15:18:49.429978 2026] [security2:error] [pid 1012520:tid 1012719] [client 185.55.149.49:55773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TqQAAAMk"]
[Thu Sep 17 15:18:49.430072 2026] [security2:error] [pid 1012520:tid 1012719] [client 185.55.149.49:55773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TqQAAAMk"]
[Thu Sep 17 15:18:49.504156 2026] [security2:error] [pid 1012520:tid 1012756] [client 134.185.85.61:62907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "vagabondhiker.com"] [uri "/media/system/js/core.js"] [unique_id "aqxZOQpXMN3p_zkwXf2TqwAAAO4"]
[Thu Sep 17 15:18:49.615708 2026] [security2:error] [pid 1012520:tid 1012699] [client 154.190.208.131:42453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TrgAAALU"]
[Thu Sep 17 15:18:49.625171 2026] [security2:error] [pid 1012520:tid 1012699] [client 154.190.208.131:42453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TrgAAALU"]
[Thu Sep 17 15:18:49.630867 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/store/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TrwAAAPI"]
[Thu Sep 17 15:18:49.825597 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/saas/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TsgAAALM"]
[Thu Sep 17 15:18:50.005447 2026] [security2:error] [pid 1012520:tid 1012589] [remote 110.249.202.193:43382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/130-Zoom-meeting.jpg"] [unique_id "aqxZOgpXMN3p_zkwXf2TtwAAuUM"]
[Thu Sep 17 15:18:50.037351 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/client/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TuQAAAPs"]
[Thu Sep 17 15:18:50.075817 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.228.208.101:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TugAAAJ0"]
[Thu Sep 17 15:18:50.207844 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/project/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TvgAAAOI"]
[Thu Sep 17 15:18:50.414925 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/admin-panel/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TwAAAANw"]
[Thu Sep 17 15:18:50.561279 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/control-panel/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TwwAAANk"]
[Thu Sep 17 15:18:50.706744 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TxgAAALg"]
[Thu Sep 17 15:18:50.792063 2026] [security2:error] [pid 1012520:tid 1012700] [client 8.228.208.101:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TzAAAALY"]
[Thu Sep 17 15:18:50.895272 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/user-panel/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TzwAAAJM"]
[Thu Sep 17 15:18:51.064934 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.old"] [unique_id "aqxZOwpXMN3p_zkwXf2T1QAAALE"]
[Thu Sep 17 15:18:51.073429 2026] [security2:error] [pid 1012520:tid 1012727] [client 114.198.138.124:55431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T1wAAANE"]
[Thu Sep 17 15:18:51.073505 2026] [security2:error] [pid 1012520:tid 1012727] [client 114.198.138.124:55431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T1wAAANE"]
[Thu Sep 17 15:18:51.163961 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/node/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T2gAAAPM"]
[Thu Sep 17 15:18:51.232961 2026] [security2:error] [pid 1012520:tid 1012778] [client 5.189.145.112:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T2wAAAQQ"], referer: binance.com
[Thu Sep 17 15:18:51.330983 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/express/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T4gAAAPc"]
[Thu Sep 17 15:18:51.456203 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T5AAAAKM"]
[Thu Sep 17 15:18:51.481479 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxZOwpXMN3p_zkwXf2T6wAAAKw"]
[Thu Sep 17 15:18:51.501545 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/next/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T7AAAAJw"]
[Thu Sep 17 15:18:51.742696 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/nuxt/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T8gAAAKs"]
[Thu Sep 17 15:18:51.841806 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T8QAAAIY"]
[Thu Sep 17 15:18:52.001504 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/nest/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T9gAAAPk"]
[Thu Sep 17 15:18:52.169802 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPApXMN3p_zkwXf2T-wAAAPA"]
[Thu Sep 17 15:18:52.172872 2026] [security2:error] [pid 1012520:tid 1012775] [client 8.228.208.101:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxZPApXMN3p_zkwXf2UAgAAAQE"]
[Thu Sep 17 15:18:52.293174 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/react/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UBgAAAJ0"]
[Thu Sep 17 15:18:52.449014 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/vue/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UDQAAAIo"]
[Thu Sep 17 15:18:52.523018 2026] [security2:error] [pid 1012520:tid 1012743] [client 41.109.147.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TywAAAOE"]
[Thu Sep 17 15:18:52.526425 2026] [security2:error] [pid 1012520:tid 1012754] [client 148.230.161.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T4wAAAOw"]
[Thu Sep 17 15:18:52.568626 2026] [security2:error] [pid 1012520:tid 1012768] [client 172.239.147.162:59457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxZPApXMN3p_zkwXf2UEwAAAPo"], referer: binance.com
[Thu Sep 17 15:18:52.576136 2026] [security2:error] [pid 1012520:tid 1012565] [remote 87.81.226.99:7067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.npae.net"] [uri "/index.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TuwAA8Ss"]
[Thu Sep 17 15:18:52.630874 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPApXMN3p_zkwXf2UEAAAANw"]
[Thu Sep 17 15:18:52.652480 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/angular/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UFAAAAJQ"]
[Thu Sep 17 15:18:52.835960 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/svelte/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UFQAAAK0"]
[Thu Sep 17 15:18:52.871146 2026] [security2:error] [pid 1012520:tid 1012720] [client 8.228.208.101:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxZPApXMN3p_zkwXf2UGgAAAMo"]
[Thu Sep 17 15:18:52.999697 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPApXMN3p_zkwXf2UGwAAAQQ"]
[Thu Sep 17 15:18:53.028318 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/vite/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UIAAAAN4"]
[Thu Sep 17 15:18:53.185527 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/backup/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UJQAAAO8"]
[Thu Sep 17 15:18:53.439525 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UKgAAAIg"]
[Thu Sep 17 15:18:53.462171 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/backups/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2ULgAAAO4"]
[Thu Sep 17 15:18:53.556456 2026] [security2:error] [pid 1012520:tid 1012689] [client 8.228.208.101:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxZPQpXMN3p_zkwXf2ULwAAAKs"]
[Thu Sep 17 15:18:53.683764 2026] [security2:error] [pid 1012520:tid 1012747] [client 156.192.234.52:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UNwAAAOU"]
[Thu Sep 17 15:18:53.683935 2026] [security2:error] [pid 1012520:tid 1012747] [client 156.192.234.52:56340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UNwAAAOU"]
[Thu Sep 17 15:18:53.693382 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/old/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UOAAAAMI"]
[Thu Sep 17 15:18:53.771524 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UNgAAAOM"]
[Thu Sep 17 15:18:53.809065 2026] [security2:error] [pid 1012520:tid 1012668] [client 92.208.182.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UMgAAAJY"]
[Thu Sep 17 15:18:53.861431 2026] [security2:error] [pid 1012520:tid 1012696] [client 182.10.99.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UOwAAALI"]
[Thu Sep 17 15:18:53.958787 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/tmp/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UQwAAAIo"]
[Thu Sep 17 15:18:54.125047 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2URQAAANk"]
[Thu Sep 17 15:18:54.135726 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/temp/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2URgAAAOk"]
[Thu Sep 17 15:18:54.262140 2026] [security2:error] [pid 1012520:tid 1012743] [client 8.228.208.101:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxZPgpXMN3p_zkwXf2USQAAAOE"]
[Thu Sep 17 15:18:54.331082 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/lab/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2USwAAAJs"]
[Thu Sep 17 15:18:54.339531 2026] [security2:error] [pid 1012520:tid 1012721] [client 210.222.43.21:63813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2URwAAAMs"], referer: http://talent-in-borders.com/old-site
[Thu Sep 17 15:18:54.466291 2026] [authz_core:error] [pid 1012520:tid 1012706] [client 172.239.147.162:56649] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:54.526763 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cronlab/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2UVgAAAMw"]
[Thu Sep 17 15:18:54.550005 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2UUwAAALY"]
[Thu Sep 17 15:18:54.715739 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cron/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2UWgAAAK0"]
[Thu Sep 17 15:18:54.864055 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2UXQAAAMo"]
[Thu Sep 17 15:18:54.941427 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/en/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2UYAAAAPc"]
[Thu Sep 17 15:18:54.953794 2026] [security2:error] [pid 1012520:tid 1012651] [client 8.228.208.101:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxZPgpXMN3p_zkwXf2UZAAAAIU"]
[Thu Sep 17 15:18:55.172493 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/administrator/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UaAAAAKY"]
[Thu Sep 17 15:18:55.245788 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UagAAAOo"]
[Thu Sep 17 15:18:55.346103 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/psnlink/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UbAAAAQA"]
[Thu Sep 17 15:18:55.480396 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.swp"] [unique_id "aqxZPwpXMN3p_zkwXf2UcgAAANQ"]
[Thu Sep 17 15:18:55.481591 2026] [security2:error] [pid 1012520:tid 1012766] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UcwAA-G4"], referer: http://mezcalt.xavierlopezmiranda.com/new/
[Thu Sep 17 15:18:55.521816 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/exapi/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UdwAAAJE"]
[Thu Sep 17 15:18:55.614503 2026] [security2:error] [pid 1012520:tid 1012677] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UewAAnwM"], referer: http://mezcalt.xavierlopezmiranda.com/wordpress/
[Thu Sep 17 15:18:55.650466 2026] [security2:error] [pid 1012520:tid 1012746] [client 8.228.208.101:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UfAAAAOQ"]
[Thu Sep 17 15:18:55.667831 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env~"] [unique_id "aqxZPwpXMN3p_zkwXf2UfgAAAMc"]
[Thu Sep 17 15:18:55.683534 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sitemaps/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UgAAAAKI"]
[Thu Sep 17 15:18:55.746574 2026] [security2:error] [pid 1012520:tid 1012662] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UgQAAkHM"], referer: http://mezcalt.xavierlopezmiranda.com/wp/
[Thu Sep 17 15:18:55.879285 2026] [security2:error] [pid 1012520:tid 1012769] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UhAAA-3o"], referer: http://mezcalt.xavierlopezmiranda.com/old/
[Thu Sep 17 15:18:55.914956 2026] [security2:error] [pid 1012520:tid 1012682] [client 186.105.232.15:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UiQAAAKQ"]
[Thu Sep 17 15:18:55.915111 2026] [security2:error] [pid 1012520:tid 1012682] [client 186.105.232.15:59348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UiQAAAKQ"]
[Thu Sep 17 15:18:56.013700 2026] [security2:error] [pid 1012520:tid 1012772] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UjgAA_mw"], referer: http://mezcalt.xavierlopezmiranda.com/blog/
[Thu Sep 17 15:18:56.020125 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UiAAAAIo"]
[Thu Sep 17 15:18:56.038877 2026] [security2:error] [pid 1012520:tid 1012697] [client 40.77.167.73:15478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nlfephrata.org"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UgwAAs28"]
[Thu Sep 17 15:18:56.145774 2026] [security2:error] [pid 1012520:tid 1012653] [client 66.249.88.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UdAAAAIc"]
[Thu Sep 17 15:18:56.164901 2026] [security2:error] [pid 1012520:tid 1012768] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UlAAA-nE"], referer: http://mezcalt.xavierlopezmiranda.com/backup/
[Thu Sep 17 15:18:56.261203 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/logs/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UlQAAAKk"]
[Thu Sep 17 15:18:56.350060 2026] [security2:error] [pid 1012520:tid 1012692] [client 8.228.208.101:43950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxZQApXMN3p_zkwXf2UmAAAAK4"]
[Thu Sep 17 15:18:56.432876 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cache/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UmgAAANs"]
[Thu Sep 17 15:18:56.461204 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UmQAAALY"]
[Thu Sep 17 15:18:56.524451 2026] [authz_core:error] [pid 1012520:tid 1012722] [client 172.239.147.162:63512] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:56.597473 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailer/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UowAAANw"]
[Thu Sep 17 15:18:56.623894 2026] [security2:error] [pid 1012520:tid 1012742] [client 148.71.151.160:62626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UoQAA4GE"]
[Thu Sep 17 15:18:56.769584 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UqQAAANI"]
[Thu Sep 17 15:18:56.840595 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mail/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UqgAAAO8"]
[Thu Sep 17 15:18:57.041944 2026] [security2:error] [pid 1012520:tid 1012651] [client 8.228.208.101:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UsgAAAIU"]
[Thu Sep 17 15:18:57.271480 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/email/.env"] [unique_id "aqxZQQpXMN3p_zkwXf2UtwAAAK8"]
[Thu Sep 17 15:18:57.450993 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UugAAAOU"]
[Thu Sep 17 15:18:57.478974 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/smtp/.env"] [unique_id "aqxZQQpXMN3p_zkwXf2UvgAAANA"]
[Thu Sep 17 15:18:57.656063 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailing/.env"] [unique_id "aqxZQQpXMN3p_zkwXf2UwAAAAJk"]
[Thu Sep 17 15:18:57.756466 2026] [security2:error] [pid 1012520:tid 1012652] [client 8.228.208.101:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UwwAAAIY"]
[Thu Sep 17 15:18:57.873786 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UxAAAAOk"]
[Thu Sep 17 15:18:58.086220 2026] [security2:error] [pid 1012520:tid 1012731] [client 45.169.98.18:64623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2UyQAAANU"]
[Thu Sep 17 15:18:58.086339 2026] [security2:error] [pid 1012520:tid 1012731] [client 45.169.98.18:64623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2UyQAAANU"]
[Thu Sep 17 15:18:58.098684 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/app/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2UygAAAJs"]
[Thu Sep 17 15:18:58.325395 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/apps/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2UzgAAAPo"]
[Thu Sep 17 15:18:58.389037 2026] [security2:error] [pid 1012520:tid 1012719] [client 104.28.198.244:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U0gAAAMk"]
[Thu Sep 17 15:18:58.389161 2026] [security2:error] [pid 1012520:tid 1012719] [client 104.28.198.244:23015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U0gAAAMk"]
[Thu Sep 17 15:18:58.452152 2026] [security2:error] [pid 1012520:tid 1012685] [client 8.228.208.101:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U1QAAAKc"]
[Thu Sep 17 15:18:58.467355 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/notifications/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U1wAAAMU"]
[Thu Sep 17 15:18:58.488269 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U2AAAANs"]
[Thu Sep 17 15:18:58.495392 2026] [security2:error] [pid 1012520:tid 1012698] [client 213.149.61.85:9886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U0QAAtBA"]
[Thu Sep 17 15:18:58.641405 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/notify/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U2wAAAM4"]
[Thu Sep 17 15:18:58.650919 2026] [authz_core:error] [pid 1012520:tid 1012666] [client 172.239.147.162:58281] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:18:58.684799 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/web/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U3AAAAP8"]
[Thu Sep 17 15:18:58.717679 2026] [security2:error] [pid 1012520:tid 1012760] [client 172.239.147.162:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U3QAAAPI"], referer: binance.com
[Thu Sep 17 15:18:58.880926 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sender/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U3wAAAK0"]
[Thu Sep 17 15:18:58.885304 2026] [security2:error] [pid 1012520:tid 1012706] [client 103.61.184.148:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U3gAAALw"]
[Thu Sep 17 15:18:58.885436 2026] [security2:error] [pid 1012520:tid 1012706] [client 103.61.184.148:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U3gAAALw"]
[Thu Sep 17 15:18:58.944818 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/site/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U4gAAANM"]
[Thu Sep 17 15:18:59.036903 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/campaign/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U5QAAAOg"]
[Thu Sep 17 15:18:59.130994 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U5wAAAOI"]
[Thu Sep 17 15:18:59.140711 2026] [security2:error] [pid 1012520:tid 1012736] [client 8.228.208.101:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZQwpXMN3p_zkwXf2U6AAAANo"]
[Thu Sep 17 15:18:59.275941 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/newsletter/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U6gAAAKA"]
[Thu Sep 17 15:18:59.461120 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/ses/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U7QAAAPQ"]
[Thu Sep 17 15:18:59.619313 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sendgrid/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U8wAAAMY"]
[Thu Sep 17 15:18:59.656726 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQwpXMN3p_zkwXf2U8QAAALE"]
[Thu Sep 17 15:18:59.817259 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sparkpost/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U9AAAANQ"]
[Thu Sep 17 15:18:59.819466 2026] [security2:error] [pid 1012520:tid 1012674] [client 8.228.208.101:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZQwpXMN3p_zkwXf2U9QAAAJw"]
[Thu Sep 17 15:18:59.838874 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/backend/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U9gAAAPw"]
[Thu Sep 17 15:18:59.998874 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/postmark/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U-wAAAOM"]
[Thu Sep 17 15:18:59.998874 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/server/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U_AAAAMc"]
[Thu Sep 17 15:19:00.094342 2026] [security2:error] [pid 1012520:tid 1012739] [client 185.55.149.49:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBAAAAN0"]
[Thu Sep 17 15:19:00.094461 2026] [security2:error] [pid 1012520:tid 1012739] [client 185.55.149.49:58256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBAAAAN0"]
[Thu Sep 17 15:19:00.178843 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailgun/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VBQAAAPs"]
[Thu Sep 17 15:19:00.179594 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/frontend/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VBgAAAIY"]
[Thu Sep 17 15:19:00.198948 2026] [security2:error] [pid 1012520:tid 1012714] [client 154.190.208.131:41706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBwAAAMQ"]
[Thu Sep 17 15:19:00.200252 2026] [security2:error] [pid 1012520:tid 1012714] [client 154.190.208.131:41706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBwAAAMQ"]
[Thu Sep 17 15:19:00.389780 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/src/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VCgAAALM"]
[Thu Sep 17 15:19:00.468855 2026] [authz_core:error] [pid 1012520:tid 1012766] [client 172.239.147.162:56792] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:19:00.505246 2026] [security2:error] [pid 1012520:tid 1012656] [client 3.82.141.143:8244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php"] [unique_id "aqxZRApXMN3p_zkwXf2VHwAAAIo"]
[Thu Sep 17 15:19:00.506099 2026] [core:error] [pid 1012520:tid 1012773] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.506114 2026] [core:error] [pid 1012520:tid 1012773] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.509157 2026] [security2:error] [pid 1012520:tid 1012687] [client 3.82.141.143:8278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php~"] [unique_id "aqxZRApXMN3p_zkwXf2VIwAAAKk"]
[Thu Sep 17 15:19:00.509293 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.228.208.101:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZRApXMN3p_zkwXf2VIgAAAJE"]
[Thu Sep 17 15:19:00.510256 2026] [core:error] [pid 1012520:tid 1012655] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.510269 2026] [core:error] [pid 1012520:tid 1012655] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.512199 2026] [core:error] [pid 1012520:tid 1012760] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.512212 2026] [core:error] [pid 1012520:tid 1012760] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.513876 2026] [security2:error] [pid 1012520:tid 1012719] [client 3.82.141.143:8260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php.bak"] [unique_id "aqxZRApXMN3p_zkwXf2VKAAAAMk"]
[Thu Sep 17 15:19:00.517618 2026] [core:error] [pid 1012520:tid 1012750] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.517633 2026] [core:error] [pid 1012520:tid 1012750] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519261 2026] [core:error] [pid 1012520:tid 1012740] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519282 2026] [core:error] [pid 1012520:tid 1012740] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519712 2026] [core:error] [pid 1012520:tid 1012686] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519723 2026] [core:error] [pid 1012520:tid 1012686] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.520182 2026] [core:error] [pid 1012520:tid 1012664] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.520194 2026] [core:error] [pid 1012520:tid 1012664] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.522956 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mandrill/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VOAAAAM8"]
[Thu Sep 17 15:19:00.525587 2026] [security2:error] [pid 1012520:tid 1012709] [client 3.82.141.143:8024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxZRApXMN3p_zkwXf2VOgAAAL8"]
[Thu Sep 17 15:19:00.531925 2026] [core:error] [pid 1012520:tid 1012711] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.531944 2026] [core:error] [pid 1012520:tid 1012711] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.534996 2026] [security2:error] [pid 1012520:tid 1012700] [client 3.82.141.143:8258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php.old"] [unique_id "aqxZRApXMN3p_zkwXf2VQAAAALY"]
[Thu Sep 17 15:19:00.535404 2026] [security2:error] [pid 1012520:tid 1012753] [client 3.82.141.143:8130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/config.php"] [unique_id "aqxZRApXMN3p_zkwXf2VQQAAAOs"]
[Thu Sep 17 15:19:00.537410 2026] [core:error] [pid 1012520:tid 1012752] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.537426 2026] [core:error] [pid 1012520:tid 1012752] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.538802 2026] [core:error] [pid 1012520:tid 1012683] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.538813 2026] [core:error] [pid 1012520:tid 1012683] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.539374 2026] [core:error] [pid 1012520:tid 1012689] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.539383 2026] [core:error] [pid 1012520:tid 1012689] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.540038 2026] [security2:error] [pid 1012520:tid 1012679] [client 3.82.141.143:8144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/web.config"] [unique_id "aqxZRApXMN3p_zkwXf2VSQAAAKE"]
[Thu Sep 17 15:19:00.540090 2026] [security2:error] [pid 1012520:tid 1012713] [client 3.82.141.143:8004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxZRApXMN3p_zkwXf2VSAAAAMM"]
[Thu Sep 17 15:19:00.546949 2026] [security2:error] [pid 1012520:tid 1012776] [client 162.241.226.11:35656] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxZRApXMN3p_zkwXf2VMQAAAQI"]
[Thu Sep 17 15:19:00.569875 2026] [security2:error] [pid 1012520:tid 1012701] [client 3.82.141.143:8342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php.save"] [unique_id "aqxZRApXMN3p_zkwXf2VWQAAALc"]
[Thu Sep 17 15:19:00.571144 2026] [core:error] [pid 1012520:tid 1012733] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571157 2026] [core:error] [pid 1012520:tid 1012696] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571162 2026] [core:error] [pid 1012520:tid 1012733] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571168 2026] [core:error] [pid 1012520:tid 1012696] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571185 2026] [core:error] [pid 1012520:tid 1012672] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571192 2026] [core:error] [pid 1012520:tid 1012672] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571218 2026] [core:error] [pid 1012520:tid 1012697] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571229 2026] [core:error] [pid 1012520:tid 1012697] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571345 2026] [core:error] [pid 1012520:tid 1012777] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571352 2026] [core:error] [pid 1012520:tid 1012777] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.572737 2026] [core:error] [pid 1012520:tid 1012714] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.572748 2026] [core:error] [pid 1012520:tid 1012714] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.575857 2026] [security2:error] [pid 1012520:tid 1012706] [client 3.82.141.143:8354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VWwAAALw"]
[Thu Sep 17 15:19:00.585346 2026] [core:error] [pid 1012520:tid 1012657] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.585361 2026] [core:error] [pid 1012520:tid 1012657] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.598272 2026] [security2:error] [pid 1012520:tid 1012712] [client 3.82.141.143:8004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxZRApXMN3p_zkwXf2VZAAAAMI"]
[Thu Sep 17 15:19:00.606953 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/core/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VZQAAAPA"]
[Thu Sep 17 15:19:00.620076 2026] [core:error] [pid 1012520:tid 1012755] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.620094 2026] [core:error] [pid 1012520:tid 1012755] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654445 2026] [core:error] [pid 1012520:tid 1012698] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654468 2026] [core:error] [pid 1012520:tid 1012698] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654917 2026] [core:error] [pid 1012520:tid 1012753] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654933 2026] [core:error] [pid 1012520:tid 1012753] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.763137 2026] [core:error] [pid 1012520:tid 1012766] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.763157 2026] [core:error] [pid 1012520:tid 1012766] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.807954 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/core/app/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VbwAAAQM"]
[Thu Sep 17 15:19:00.874344 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailjet/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VcQAAAK0"]
[Thu Sep 17 15:19:00.986114 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/config/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VdQAAAJk"]
[Thu Sep 17 15:19:01.007655 2026] [security2:error] [pid 1012520:tid 1012665] [client 192.178.6.5:43607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxZRQpXMN3p_zkwXf2VdgAAAJM"]
[Thu Sep 17 15:19:01.071165 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/brevo/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VdwAAALU"]
[Thu Sep 17 15:19:01.173501 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/private/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VeAAAAJQ"]
[Thu Sep 17 15:19:01.217676 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.228.208.101:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZRQpXMN3p_zkwXf2VeQAAAJE"]
[Thu Sep 17 15:19:01.264723 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/transactional/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VegAAANo"]
[Thu Sep 17 15:19:01.338762 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/application/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VfgAAAKc"]
[Thu Sep 17 15:19:01.459757 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/bulk/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VgQAAAJY"]
[Thu Sep 17 15:19:01.543407 2026] [security2:error] [pid 1012520:tid 1012669] [client 85.153.205.90:10122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxZRApXMN3p_zkwXf2VCQAAlwE"], referer: https://www.adventuresofapril.com
[Thu Sep 17 15:19:01.554042 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/bootstrap/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VhQAAANU"]
[Thu Sep 17 15:19:01.636796 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/aws/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VhwAAAMI"]
[Thu Sep 17 15:19:01.691249 2026] [security2:error] [pid 1012520:tid 1012763] [client 114.198.138.124:56085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRQpXMN3p_zkwXf2ViAAAAPU"]
[Thu Sep 17 15:19:01.691343 2026] [security2:error] [pid 1012520:tid 1012763] [client 114.198.138.124:56085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRQpXMN3p_zkwXf2ViAAAAPU"]
[Thu Sep 17 15:19:01.728323 2026] [security2:error] [pid 1012520:tid 1012667] [client 172.239.147.162:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxZRQpXMN3p_zkwXf2ViQAAAJU"], referer: binance.com
[Thu Sep 17 15:19:01.784748 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/database/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VigAAAO0"]
[Thu Sep 17 15:19:01.834772 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/azure/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2ViwAAAM4"]
[Thu Sep 17 15:19:01.928302 2026] [security2:error] [pid 1012520:tid 1012758] [client 8.228.208.101:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZRQpXMN3p_zkwXf2VjgAAAPA"]
[Thu Sep 17 15:19:01.985374 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/storage/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VkQAAAOE"]
[Thu Sep 17 15:19:02.010052 2026] [security2:error] [pid 1012520:tid 1012705] [client 172.239.147.162:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxZRgpXMN3p_zkwXf2VlAAAALs"], referer: binance.com
[Thu Sep 17 15:19:02.079370 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/gcp/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VlwAAAPM"]
[Thu Sep 17 15:19:02.143625 2026] [security2:error] [pid 1012520:tid 1012530] [remote 216.73.217.142:31090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxZRgpXMN3p_zkwXf2VmAAAkgg"]
[Thu Sep 17 15:19:02.167483 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/var/www/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VmQAAAKs"]
[Thu Sep 17 15:19:02.297220 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cloud/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VmgAAAN8"]
[Thu Sep 17 15:19:02.331913 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/var/www/html/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VmwAAAMM"]
[Thu Sep 17 15:19:02.503474 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/infrastructure/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VpQAAANg"]
[Thu Sep 17 15:19:02.578909 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/current/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VpgAAAIU"]
[Thu Sep 17 15:19:02.621449 2026] [security2:error] [pid 1012520:tid 1012662] [client 8.228.208.101:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZRgpXMN3p_zkwXf2VpwAAAJA"]
[Thu Sep 17 15:19:02.705680 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/docker/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VqAAAAPw"]
[Thu Sep 17 15:19:02.794773 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/release/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VqgAAAK8"]
[Thu Sep 17 15:19:02.861987 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/k8s/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VrAAAAPg"]
[Thu Sep 17 15:19:02.946365 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/releases/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VrQAAAM8"]
[Thu Sep 17 15:19:03.079566 2026] [security2:error] [pid 1012520:tid 1012733] [client 172.239.147.162:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VswAAANc"], referer: binance.com
[Thu Sep 17 15:19:03.190710 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/shared/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VtQAAANA"]
[Thu Sep 17 15:19:03.204791 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/kubernetes/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VtgAAAOw"]
[Thu Sep 17 15:19:03.268421 2026] [security2:error] [pid 1012520:tid 1012656] [client 200.181.217.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VtAAAAIo"]
[Thu Sep 17 15:19:03.311434 2026] [security2:error] [pid 1012520:tid 1012750] [client 8.228.208.101:51890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VuAAAAOg"]
[Thu Sep 17 15:19:03.380121 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/terraform/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VuQAAAJg"]
[Thu Sep 17 15:19:03.439289 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/deploy/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VugAAAQE"]
[Thu Sep 17 15:19:03.562680 2026] [security2:error] [pid 1012520:tid 1012549] [remote 17.166.23.86:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.23.166.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/protegidas/consultar_usuario.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VvQAA1Bs"], referer: https://www.mtbclubdecampo.com/bici2/ruta.php?id=257
[Thu Sep 17 15:19:03.585610 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/ansible/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VvwAAAPk"]
[Thu Sep 17 15:19:03.639367 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/build/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VwAAAAJQ"]
[Thu Sep 17 15:19:03.877307 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dist/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VwgAAANo"]
[Thu Sep 17 15:19:03.981164 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.git/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VxQAAANM"]
[Thu Sep 17 15:19:04.004296 2026] [security2:error] [pid 1012520:tid 1012687] [client 8.228.208.101:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZSApXMN3p_zkwXf2VxgAAAKk"]
[Thu Sep 17 15:19:04.058835 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public_html/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VxwAAAJY"]
[Thu Sep 17 15:19:04.172206 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/ci/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VyQAAANU"]
[Thu Sep 17 15:19:04.241069 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/htdocs/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VywAAAKw"]
[Thu Sep 17 15:19:04.281335 2026] [security2:error] [pid 1012520:tid 1012692] [client 156.192.234.52:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZSApXMN3p_zkwXf2VzQAAAK4"]
[Thu Sep 17 15:19:04.281446 2026] [security2:error] [pid 1012520:tid 1012692] [client 156.192.234.52:56975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZSApXMN3p_zkwXf2VzQAAAK4"]
[Thu Sep 17 15:19:04.334281 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cd/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VzgAAAPU"]
[Thu Sep 17 15:19:04.392848 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/www/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VzwAAAJ4"]
[Thu Sep 17 15:19:04.528945 2026] [security2:error] [pid 1012520:tid 1012723] [client 119.13.212.112:47887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZSApXMN3p_zkwXf2V0AAAzSM"]
[Thu Sep 17 15:19:04.573408 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/html/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V0QAAAJU"]
[Thu Sep 17 15:19:04.587698 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/jenkins/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V0gAAAO0"]
[Thu Sep 17 15:19:04.723500 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/live/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V1wAAAOE"]
[Thu Sep 17 15:19:04.817009 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/gitlab/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V2AAAAME"]
[Thu Sep 17 15:19:04.931122 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/prod/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V2QAAALE"]
[Thu Sep 17 15:19:05.035960 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/github/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V3AAAAKs"]
[Thu Sep 17 15:19:05.153972 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dev/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V3wAAAKE"]
[Thu Sep 17 15:19:05.219217 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/actions/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V4gAAAQI"]
[Thu Sep 17 15:19:05.244739 2026] [security2:error] [pid 1012520:tid 1012674] [client 172.239.147.162:61950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V5AAAAJw"], referer: binance.com
[Thu Sep 17 15:19:05.345361 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/staging/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V5QAAANg"]
[Thu Sep 17 15:19:05.392878 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/circleci/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V5gAAAIU"]
[Thu Sep 17 15:19:05.501349 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/opt/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V6wAAAKA"]
[Thu Sep 17 15:19:05.542087 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/travis/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V7AAAAI8"]
[Thu Sep 17 15:19:05.709324 2026] [security2:error] [pid 1012520:tid 1012749] [client 119.13.212.112:34201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V7gAA5xo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621101158&hidebots=0&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:05.727708 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/buildkite/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V9QAAAIo"]
[Thu Sep 17 15:19:05.729867 2026] [security2:error] [pid 1012520:tid 1012704] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/laravel/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V9gAAALo"]
[Thu Sep 17 15:19:05.889201 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/symfony/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V_wAAANQ"]
[Thu Sep 17 15:19:05.894895 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mysql/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2WAAAAAJQ"]
[Thu Sep 17 15:19:05.951410 2026] [security2:error] [pid 1012520:tid 1012756] [client 43.172.196.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V-gAAAO4"]
[Thu Sep 17 15:19:05.951532 2026] [security2:error] [pid 1012520:tid 1012655] [client 43.173.174.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V-QAAAIk"]
[Thu Sep 17 15:19:06.179588 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/postgres/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WDAAAAJ8"]
[Thu Sep 17 15:19:06.424016 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mongodb/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WFgAAAME"]
[Thu Sep 17 15:19:06.493247 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/wordpress/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WFwAAAN4"]
[Thu Sep 17 15:19:06.581095 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/redis/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WHAAAAKU"]
[Thu Sep 17 15:19:06.706569 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/wp/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WIQAAANg"]
[Thu Sep 17 15:19:06.732285 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/elasticsearch/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WIgAAAP0"]
[Thu Sep 17 15:19:06.907516 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cms/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WKwAAAOk"]
[Thu Sep 17 15:19:06.989694 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/rabbitmq/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WLQAAALc"]
[Thu Sep 17 15:19:07.122015 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/drupal/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WMQAAAOo"]
[Thu Sep 17 15:19:07.162498 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/kafka/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WNAAAAP4"]
[Thu Sep 17 15:19:07.212191 2026] [security2:error] [pid 1012520:tid 1012672] [client 79.108.166.138:56242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sableandox.co.uk"] [uri "/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WNwAAAJo"]
[Thu Sep 17 15:19:07.270496 2026] [security2:error] [pid 1012520:tid 1012671] [client 75.153.80.107:35335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZSwpXMN3p_zkwXf2WNQAAmQ8"]
[Thu Sep 17 15:19:07.322653 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/joomla/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WOgAAAPk"]
[Thu Sep 17 15:19:07.376929 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/queue/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WPQAAAIk"]
[Thu Sep 17 15:19:07.486955 2026] [security2:error] [pid 1012520:tid 1012764] [client 172.239.147.162:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxZSwpXMN3p_zkwXf2WQQAAAPY"], referer: binance.com
[Thu Sep 17 15:19:07.527837 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/worker/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WQgAAAK0"]
[Thu Sep 17 15:19:07.579893 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/magento/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WQwAAAKo"]
[Thu Sep 17 15:19:07.752682 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/job/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WSQAAAKw"]
[Thu Sep 17 15:19:07.764311 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/shopify/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WSwAAAI4"]
[Thu Sep 17 15:19:07.914024 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/test/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WUAAAAKg"]
[Thu Sep 17 15:19:08.059645 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/prestashop/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WUQAAAJc"]
[Thu Sep 17 15:19:08.062456 2026] [security2:error] [pid 1012520:tid 1012668] [client 186.105.232.15:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WUgAAAJY"]
[Thu Sep 17 15:19:08.062545 2026] [security2:error] [pid 1012520:tid 1012668] [client 186.105.232.15:59947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WUgAAAJY"]
[Thu Sep 17 15:19:08.170901 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/qa/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WVQAAAJE"]
[Thu Sep 17 15:19:08.253357 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/codeigniter/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WVwAAAN8"]
[Thu Sep 17 15:19:08.340816 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/preview/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WWQAAAKM"]
[Thu Sep 17 15:19:08.468377 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cakephp/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WYAAAAM0"]
[Thu Sep 17 15:19:08.480999 2026] [security2:error] [pid 1012520:tid 1012746] [client 75.153.80.107:46051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZTApXMN3p_zkwXf2WWgAA5B4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621101158&hidebots=0&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:08.505229 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/beta/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WaQAAAPc"]
[Thu Sep 17 15:19:08.538284 2026] [security2:error] [pid 1012520:tid 1012769] [client 45.169.98.18:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WawAAAPs"]
[Thu Sep 17 15:19:08.538378 2026] [security2:error] [pid 1012520:tid 1012769] [client 45.169.98.18:65190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WawAAAPs"]
[Thu Sep 17 15:19:08.621293 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/zend/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WdwAAALk"]
[Thu Sep 17 15:19:08.661473 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/uat/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WewAAALY"]
[Thu Sep 17 15:19:08.775360 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/yii/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WfgAAAPI"]
[Thu Sep 17 15:19:08.959595 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/stage/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WgQAAAIk"]
[Thu Sep 17 15:19:08.967724 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/laravel5/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WggAAAKc"]
[Thu Sep 17 15:19:09.130127 2026] [security2:error] [pid 1012520:tid 1012754] [client 103.61.184.148:49671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WhAAAAOw"]
[Thu Sep 17 15:19:09.130267 2026] [security2:error] [pid 1012520:tid 1012754] [client 103.61.184.148:49671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WhAAAAOw"]
[Thu Sep 17 15:19:09.153478 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/v1/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WhQAAAOM"]
[Thu Sep 17 15:19:09.196312 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/development/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WiQAAAJ4"]
[Thu Sep 17 15:19:09.353370 2026] [security2:error] [pid 1012520:tid 1012763] [client 172.239.147.162:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WkAAAAPU"], referer: binance.com
[Thu Sep 17 15:19:09.367109 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/v2/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WkQAAAJU"]
[Thu Sep 17 15:19:09.373619 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/production/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WkgAAAJc"]
[Thu Sep 17 15:19:09.522306 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/config/app/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WlgAAAMM"]
[Thu Sep 17 15:19:09.557545 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/v3/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WlwAAAKM"]
[Thu Sep 17 15:19:09.718089 2026] [security2:error] [pid 1012520:tid 1012654] [client 51.8.102.37:56677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seedboxpress.com"] [uri "/index.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WlQAAiDg"]
[Thu Sep 17 15:19:09.783842 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.246.241.88:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WnwAAAI8"]
[Thu Sep 17 15:19:09.838452 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/v1/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WowAAAJM"]
[Thu Sep 17 15:19:10.063980 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/v2/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WpQAAALc"]
[Thu Sep 17 15:19:10.220423 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/rest/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WqgAAAOY"]
[Thu Sep 17 15:19:10.439122 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WqwAAANY"]
[Thu Sep 17 15:19:10.463487 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.246.241.88:47314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/info.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WsAAAAP8"]
[Thu Sep 17 15:19:10.468499 2026] [autoindex:error] [pid 1012520:tid 1012746] [client 49.36.220.170:63259] AH01276: Cannot serve directory /home1/afbacoco/public_html/rcgi/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://rcgi.us
[Thu Sep 17 15:19:10.501744 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/graphql/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WsQAAAPI"]
[Thu Sep 17 15:19:10.646282 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/gateway/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WtQAAAJk"]
[Thu Sep 17 15:19:10.801125 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/microservice/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WuAAAANQ"]
[Thu Sep 17 15:19:10.952262 2026] [security2:error] [pid 1012520:tid 1012697] [client 185.55.149.49:58894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WuwAAALM"]
[Thu Sep 17 15:19:10.952776 2026] [security2:error] [pid 1012520:tid 1012697] [client 185.55.149.49:58894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WuwAAALM"]
[Thu Sep 17 15:19:10.971757 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/service/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WvAAAANo"]
[Thu Sep 17 15:19:11.073981 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WvwAAANs"]
[Thu Sep 17 15:19:11.075595 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/php.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WwAAAAIk"]
[Thu Sep 17 15:19:11.129536 2026] [security2:error] [pid 1012520:tid 1012749] [client 154.190.208.131:42314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WwwAAAOc"]
[Thu Sep 17 15:19:11.153421 2026] [security2:error] [pid 1012520:tid 1012749] [client 154.190.208.131:42314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WwwAAAOc"]
[Thu Sep 17 15:19:11.155678 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/v3/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WxAAAAQQ"]
[Thu Sep 17 15:19:11.310496 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/dev/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WyAAAAO8"]
[Thu Sep 17 15:19:11.504436 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/staging/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WywAAAIc"]
[Thu Sep 17 15:19:11.577521 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WyQAAAI4"]
[Thu Sep 17 15:19:11.773759 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.246.241.88:47338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/i.php"] [unique_id "aqxZTwpXMN3p_zkwXf2W1gAAAJc"]
[Thu Sep 17 15:19:11.808606 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/vendor/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2W2AAAAOA"]
[Thu Sep 17 15:19:12.029595 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZTwpXMN3p_zkwXf2W2gAAAJs"]
[Thu Sep 17 15:19:12.038994 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/lib/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W2wAAAKU"]
[Thu Sep 17 15:19:12.263599 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/resources/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W5QAAAMQ"]
[Thu Sep 17 15:19:12.432261 2026] [security2:error] [pid 1012520:tid 1012662] [client 157.100.69.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "threadalittlelight.com"] [uri "/index.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WvQAAAJA"], referer: https://threadalittlelight.com
[Thu Sep 17 15:19:12.451416 2026] [security2:error] [pid 1012520:tid 1012771] [client 114.198.138.124:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUApXMN3p_zkwXf2W6QAAAP0"]
[Thu Sep 17 15:19:12.451551 2026] [security2:error] [pid 1012520:tid 1012771] [client 114.198.138.124:56736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUApXMN3p_zkwXf2W6QAAAP0"]
[Thu Sep 17 15:19:12.459524 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.246.241.88:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/pi.php"] [unique_id "aqxZUApXMN3p_zkwXf2W6gAAALA"]
[Thu Sep 17 15:19:12.497704 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/assets/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W6wAAAOQ"]
[Thu Sep 17 15:19:12.546502 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUApXMN3p_zkwXf2W5wAAAIU"]
[Thu Sep 17 15:19:12.783193 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/uploads/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W9AAAANI"]
[Thu Sep 17 15:19:12.798913 2026] [security2:error] [pid 1012520:tid 1012733] [client 76.33.142.4:22220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZUApXMN3p_zkwXf2W8AAA10w"]
[Thu Sep 17 15:19:12.974199 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/internal/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W-gAAAIk"]
[Thu Sep 17 15:19:13.022591 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUApXMN3p_zkwXf2W9QAAAJo"]
[Thu Sep 17 15:19:13.043812 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/pinfo.php"] [unique_id "aqxZUQpXMN3p_zkwXf2W_AAAANo"]
[Thu Sep 17 15:19:13.176444 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/tools/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XAAAAAKg"]
[Thu Sep 17 15:19:13.390311 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/scripts/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XBQAAAJU"]
[Thu Sep 17 15:19:13.496195 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XAwAAAMw"]
[Thu Sep 17 15:19:13.612043 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/bin/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XBwAAAK4"]
[Thu Sep 17 15:19:13.628917 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.246.241.88:37944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/test.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XCgAAAKw"]
[Thu Sep 17 15:19:13.781756 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XDAAAAOE"]
[Thu Sep 17 15:19:13.785473 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sbin/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XEAAAAKM"]
[Thu Sep 17 15:19:13.951388 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XDwAAAMM"]
[Thu Sep 17 15:19:13.990875 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/local/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XEgAAAMs"]
[Thu Sep 17 15:19:14.191779 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.bak"] [unique_id "aqxZUgpXMN3p_zkwXf2XFgAAAPE"]
[Thu Sep 17 15:19:14.231070 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/portal/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XFwAAAKU"]
[Thu Sep 17 15:19:14.267330 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XGAAAAN8"]
[Thu Sep 17 15:19:14.389487 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.backup"] [unique_id "aqxZUgpXMN3p_zkwXf2XGwAAAPc"]
[Thu Sep 17 15:19:14.437568 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dashboard/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XHQAAAOo"]
[Thu Sep 17 15:19:14.497319 2026] [security2:error] [pid 1012520:tid 1012597] [remote 111.225.149.176:14842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/152-Austin-Conference-300x225.jpg"] [unique_id "aqxZUgpXMN3p_zkwXf2XHgAAu0s"]
[Thu Sep 17 15:19:14.527351 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XHAAAANg"]
[Thu Sep 17 15:19:14.545498 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.246.241.88:37956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/p.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XHwAAAMA"]
[Thu Sep 17 15:19:14.666263 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/panel/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XJQAAAPs"]
[Thu Sep 17 15:19:14.693138 2026] [security2:error] [pid 1012520:tid 1012663] [client 172.239.147.162:56687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XJwAAAJE"], referer: binance.com
[Thu Sep 17 15:19:14.810602 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XJgAAAM4"]
[Thu Sep 17 15:19:14.818748 2026] [security2:error] [pid 1012520:tid 1012714] [client 156.192.234.52:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XKgAAAMQ"]
[Thu Sep 17 15:19:14.819245 2026] [security2:error] [pid 1012520:tid 1012714] [client 156.192.234.52:57601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XKgAAAMQ"]
[Thu Sep 17 15:19:14.825273 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/crm/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XKwAAALA"]
[Thu Sep 17 15:19:14.923076 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XKAAAAP0"]
[Thu Sep 17 15:19:14.989407 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/erp/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XLQAAAKE"]
[Thu Sep 17 15:19:15.072581 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XLAAAALY"]
[Thu Sep 17 15:19:15.143625 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/shop/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XMgAAAQM"]
[Thu Sep 17 15:19:15.196214 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.old"] [unique_id "aqxZUwpXMN3p_zkwXf2XNQAAAIo"]
[Thu Sep 17 15:19:15.332113 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XNgAAAMo"]
[Thu Sep 17 15:19:15.348125 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:37962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/debug.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XOQAAAPk"]
[Thu Sep 17 15:19:15.396645 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/store/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XPAAAALM"]
[Thu Sep 17 15:19:15.592334 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/saas/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XQgAAAOY"]
[Thu Sep 17 15:19:15.594106 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XPwAAAOw"]
[Thu Sep 17 15:19:15.785740 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XPgAAAKI"]
[Thu Sep 17 15:19:15.786296 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/client/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XSAAAAOU"]
[Thu Sep 17 15:19:15.856334 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XRgAAAJ8"]
[Thu Sep 17 15:19:15.966424 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/project/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XSgAAAO8"]
[Thu Sep 17 15:19:16.012019 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.bak"] [unique_id "aqxZVApXMN3p_zkwXf2XUAAAAJY"]
[Thu Sep 17 15:19:16.120367 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/admin-panel/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XUgAAAI4"]
[Thu Sep 17 15:19:16.147459 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.246.241.88:37966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxZVApXMN3p_zkwXf2XUwAAAOM"]
[Thu Sep 17 15:19:16.165194 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.backup"] [unique_id "aqxZVApXMN3p_zkwXf2XVAAAAKM"]
[Thu Sep 17 15:19:16.238480 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XUQAAAN4"]
[Thu Sep 17 15:19:16.319230 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/control-panel/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XWQAAAJM"]
[Thu Sep 17 15:19:16.423418 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XWAAAAIw"]
[Thu Sep 17 15:19:16.470958 2026] [security2:error] [pid 1012520:tid 1012657] [client 170.246.12.9:3172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XWgAAiz0"]
[Thu Sep 17 15:19:16.487501 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/user-panel/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XYAAAAOs"]
[Thu Sep 17 15:19:16.576130 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.old"] [unique_id "aqxZVApXMN3p_zkwXf2XYgAAAJs"]
[Thu Sep 17 15:19:16.683160 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/node/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XaAAAAPc"]
[Thu Sep 17 15:19:16.770794 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XYQAAAJ0"]
[Thu Sep 17 15:19:16.856839 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/express/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XawAAAJA"]
[Thu Sep 17 15:19:16.857192 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.246.241.88:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/test/phpinfo.php"] [unique_id "aqxZVApXMN3p_zkwXf2XbAAAAOo"]
[Thu Sep 17 15:19:16.864258 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XagAAANg"]
[Thu Sep 17 15:19:17.005216 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/next/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XdAAAAN0"]
[Thu Sep 17 15:19:17.131288 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XdwAAAP4"]
[Thu Sep 17 15:19:17.192823 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/nuxt/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XhAAAANc"]
[Thu Sep 17 15:19:17.285237 2026] [security2:error] [pid 1012520:tid 1012768] [client 76.33.142.4:23730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XhQAA-i8"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621101158&hidebots=0&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:17.322316 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XdQAAAP0"]
[Thu Sep 17 15:19:17.400207 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XhwAAAJg"]
[Thu Sep 17 15:19:17.452776 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/nest/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XiQAAANs"]
[Thu Sep 17 15:19:17.490934 2026] [security2:error] [pid 1012520:tid 1012703] [client 172.239.147.162:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XigAAALk"], referer: binance.com
[Thu Sep 17 15:19:17.610331 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/react/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XkQAAALM"]
[Thu Sep 17 15:19:17.666857 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XjQAAAJw"]
[Thu Sep 17 15:19:17.669910 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.246.241.88:37978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XlQAAAIg"]
[Thu Sep 17 15:19:17.802136 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XkAAAAI0"]
[Thu Sep 17 15:19:17.805332 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/vue/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XmgAAAOY"]
[Thu Sep 17 15:19:17.906846 2026] [security2:error] [pid 1012520:tid 1012720] [client 186.105.232.15:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XngAAAMo"]
[Thu Sep 17 15:19:17.906943 2026] [security2:error] [pid 1012520:tid 1012720] [client 186.105.232.15:60546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XngAAAMo"]
[Thu Sep 17 15:19:17.946370 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XnAAAANQ"]
[Thu Sep 17 15:19:18.025394 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/angular/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XoQAAAK4"]
[Thu Sep 17 15:19:18.201247 2026] [core:error] [pid 1012520:tid 1012711] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:18.201270 2026] [core:error] [pid 1012520:tid 1012711] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:18.206523 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/svelte/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XqwAAAJM"]
[Thu Sep 17 15:19:18.218280 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.246.241.88:37982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/old/phpinfo.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrAAAAQA"]
[Thu Sep 17 15:19:18.228241 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XpgAAAN4"]
[Thu Sep 17 15:19:18.311401 2026] [security2:error] [pid 1012520:tid 1012687] [client 104.28.198.244:22630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrgAAAKk"]
[Thu Sep 17 15:19:18.405861 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/vite/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XsAAAAN8"]
[Thu Sep 17 15:19:18.436948 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XqgAAAOE"]
[Thu Sep 17 15:19:18.495697 2026] [security2:error] [pid 1012520:tid 1012687] [client 104.28.198.244:22630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrgAAAKk"]
[Thu Sep 17 15:19:18.502352 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrwAAAKU"]
[Thu Sep 17 15:19:18.564957 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/backup/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XsQAAAMA"]
[Thu Sep 17 15:19:18.771146 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XsgAAAKw"]
[Thu Sep 17 15:19:18.796024 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/backups/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XuQAAAOo"]
[Thu Sep 17 15:19:18.945872 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/old/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XwAAAAN0"]
[Thu Sep 17 15:19:19.023652 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XugAAAPs"]
[Thu Sep 17 15:19:19.025614 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.169.98.18:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XwgAAANA"]
[Thu Sep 17 15:19:19.025727 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.169.98.18:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XwgAAANA"]
[Thu Sep 17 15:19:19.049305 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XvwAAAO0"]
[Thu Sep 17 15:19:19.079677 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.246.241.88:37990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XwwAAANg"]
[Thu Sep 17 15:19:19.182837 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/tmp/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2XxAAAAPg"]
[Thu Sep 17 15:19:19.322277 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XxgAAAJQ"]
[Thu Sep 17 15:19:19.353099 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/temp/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2XzgAAANw"]
[Thu Sep 17 15:19:19.435165 2026] [security2:error] [pid 1012520:tid 1012714] [client 37.39.192.188:44768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XywAAxHM"]
[Thu Sep 17 15:19:19.494165 2026] [security2:error] [pid 1012520:tid 1012656] [client 172.239.147.162:57288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XzQAAAIo"], referer: binance.com
[Thu Sep 17 15:19:19.533390 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/lab/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2X0QAAAKE"]
[Thu Sep 17 15:19:19.554245 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XzAAAAPQ"]
[Thu Sep 17 15:19:19.603295 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X0AAAALM"]
[Thu Sep 17 15:19:19.702225 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cronlab/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2X1AAAANo"]
[Thu Sep 17 15:19:19.728820 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/public/phpinfo.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X1QAAAK0"]
[Thu Sep 17 15:19:19.762057 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.swp"] [unique_id "aqxZVwpXMN3p_zkwXf2X2AAAAOY"]
[Thu Sep 17 15:19:19.827440 2026] [security2:error] [pid 1012520:tid 1012714] [client 103.61.184.148:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X2wAAAMQ"]
[Thu Sep 17 15:19:19.827555 2026] [security2:error] [pid 1012520:tid 1012714] [client 103.61.184.148:56719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X2wAAAMQ"]
[Thu Sep 17 15:19:19.896230 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cron/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2X3AAAAPE"]
[Thu Sep 17 15:19:19.921943 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env~"] [unique_id "aqxZVwpXMN3p_zkwXf2X3QAAALw"]
[Thu Sep 17 15:19:20.004961 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X2gAAAIY"]
[Thu Sep 17 15:19:20.086062 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/en/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X3wAAAMo"]
[Thu Sep 17 15:19:20.183305 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X3gAAAKg"]
[Thu Sep 17 15:19:20.373351 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/administrator/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X5QAAAKo"]
[Thu Sep 17 15:19:20.454079 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X5gAAANE"]
[Thu Sep 17 15:19:20.485896 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X5AAAAJU"]
[Thu Sep 17 15:19:20.574816 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/psnlink/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X6QAAAO8"]
[Thu Sep 17 15:19:20.724410 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X6gAAAJY"]
[Thu Sep 17 15:19:20.778004 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/exapi/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X9AAAAPM"]
[Thu Sep 17 15:19:20.805810 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:38002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/php-info.php"] [unique_id "aqxZWApXMN3p_zkwXf2X9QAAAPU"]
[Thu Sep 17 15:19:20.928733 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sitemaps/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X9wAAAOs"]
[Thu Sep 17 15:19:20.972029 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X7wAAAQA"]
[Thu Sep 17 15:19:21.075548 2026] [security2:error] [pid 1012520:tid 1012723] [client 172.239.147.162:60845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2X-AAAAM0"], referer: binance.com
[Thu Sep 17 15:19:21.164950 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.swp"] [unique_id "aqxZWQpXMN3p_zkwXf2YCgAAAPs"]
[Thu Sep 17 15:19:21.287185 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YDAAAAM4"]
[Thu Sep 17 15:19:21.291440 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YBwAAAOo"]
[Thu Sep 17 15:19:21.348292 2026] [security2:error] [pid 1012520:tid 1012755] [client 172.239.147.162:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YFgAAAO0"], referer: binance.com
[Thu Sep 17 15:19:21.353543 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env~"] [unique_id "aqxZWQpXMN3p_zkwXf2YFwAAAPg"]
[Thu Sep 17 15:19:21.438736 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.246.241.88:38018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpversion.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YGAAAAP4"]
[Thu Sep 17 15:19:21.554837 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YGQAAAI8"]
[Thu Sep 17 15:19:21.641796 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YHQAAAPI"]
[Thu Sep 17 15:19:21.694251 2026] [security2:error] [pid 1012520:tid 1012734] [client 154.190.208.131:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YJAAAANg"]
[Thu Sep 17 15:19:21.694337 2026] [security2:error] [pid 1012520:tid 1012734] [client 154.190.208.131:41578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YJAAAANg"]
[Thu Sep 17 15:19:21.694858 2026] [security2:error] [pid 1012520:tid 1012738] [client 185.55.149.49:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YIgAAANw"]
[Thu Sep 17 15:19:21.694924 2026] [security2:error] [pid 1012520:tid 1012738] [client 185.55.149.49:59436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YIgAAANw"]
[Thu Sep 17 15:19:21.711528 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/app/.env"] [unique_id "aqxZWQpXMN3p_zkwXf2YJQAAALA"]
[Thu Sep 17 15:19:21.829962 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YIAAAALk"]
[Thu Sep 17 15:19:21.846246 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/logs/.env"] [unique_id "aqxZWQpXMN3p_zkwXf2YKAAAANU"]
[Thu Sep 17 15:19:21.868320 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/apps/.env"] [unique_id "aqxZWQpXMN3p_zkwXf2YKQAAAL0"]
[Thu Sep 17 15:19:22.021247 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YKwAAAIY"]
[Thu Sep 17 15:19:22.150076 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:50720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/_phpinfo.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YLwAAAPk"]
[Thu Sep 17 15:19:22.180883 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/web/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YMQAAAKg"]
[Thu Sep 17 15:19:22.335142 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/site/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YNQAAANE"]
[Thu Sep 17 15:19:22.359466 2026] [security2:error] [pid 1012520:tid 1012754] [client 13.140.130.193:39782] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "coblersen.com"] [uri "/default.html"] [unique_id "aqxZWgpXMN3p_zkwXf2YNwAAAOw"]
[Thu Sep 17 15:19:22.374404 2026] [security2:error] [pid 1012520:tid 1012736] [client 85.86.29.178:59982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YNgAA2hk"], referer: https://www.adventuresofapril.com
[Thu Sep 17 15:19:22.427657 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YLgAAAOA"]
[Thu Sep 17 15:19:22.489105 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/public/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YPgAAAJY"]
[Thu Sep 17 15:19:22.529649 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cache/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YPwAAALU"]
[Thu Sep 17 15:19:22.714031 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailer/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YRwAAAPc"]
[Thu Sep 17 15:19:22.755506 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YQwAAAI4"]
[Thu Sep 17 15:19:22.801820 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.246.241.88:50736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/old_phpinfo.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YTQAAAOs"]
[Thu Sep 17 15:19:22.868581 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mail/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YTwAAAN4"]
[Thu Sep 17 15:19:22.912018 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/backend/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YUAAAAKk"]
[Thu Sep 17 15:19:22.956639 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YTAAAAMg"]
[Thu Sep 17 15:19:23.048835 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/email/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YWgAAAOI"]
[Thu Sep 17 15:19:23.077174 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/server/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YWwAAALs"]
[Thu Sep 17 15:19:23.232708 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/frontend/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YYQAAAI8"]
[Thu Sep 17 15:19:23.244546 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/smtp/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YZAAAAP0"]
[Thu Sep 17 15:19:23.266443 2026] [security2:error] [pid 1012520:tid 1012766] [client 172.239.147.162:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YZQAAAPg"], referer: binance.com
[Thu Sep 17 15:19:23.389188 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/src/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YaAAAALI"]
[Thu Sep 17 15:19:23.515190 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailing/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YcwAAAOY"]
[Thu Sep 17 15:19:23.543206 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/core/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YdAAAAPo"]
[Thu Sep 17 15:19:23.585975 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/server-info.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YdQAAAIo"]
[Thu Sep 17 15:19:23.699221 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/core/app/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YeAAAAL0"]
[Thu Sep 17 15:19:23.725309 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/notifications/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YewAAAO4"]
[Thu Sep 17 15:19:23.730643 2026] [security2:error] [pid 1012520:tid 1012678] [client 114.198.138.124:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YfQAAAKA"]
[Thu Sep 17 15:19:23.730777 2026] [security2:error] [pid 1012520:tid 1012678] [client 114.198.138.124:57372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YfQAAAKA"]
[Thu Sep 17 15:19:23.858449 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/config/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YgQAAAPE"]
[Thu Sep 17 15:19:23.957538 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/notify/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YgwAAAOc"]
[Thu Sep 17 15:19:23.959321 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YfAAAAQE"]
[Thu Sep 17 15:19:24.015961 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/private/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YhQAAAMI"]
[Thu Sep 17 15:19:24.122544 2026] [security2:error] [pid 1012520:tid 1012574] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YiAAAqDQ"]
[Thu Sep 17 15:19:24.123790 2026] [security2:error] [pid 1012520:tid 1012543] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.old"] [unique_id "aqxZXApXMN3p_zkwXf2YjQAAqBU"]
[Thu Sep 17 15:19:24.163548 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sender/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YlQAAAJI"]
[Thu Sep 17 15:19:24.172100 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/application/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YmAAAAJY"]
[Thu Sep 17 15:19:24.327503 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/bootstrap/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YpwAAAI4"]
[Thu Sep 17 15:19:24.331242 2026] [security2:error] [pid 1012520:tid 1012757] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YmgAAAO8"]
[Thu Sep 17 15:19:24.333020 2026] [security2:error] [pid 1012520:tid 1012702] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YlwAAALg"]
[Thu Sep 17 15:19:24.334372 2026] [security2:error] [pid 1012520:tid 1012692] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YmQAAAK4"]
[Thu Sep 17 15:19:24.335612 2026] [security2:error] [pid 1012520:tid 1012716] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YnAAAAMY"]
[Thu Sep 17 15:19:24.335645 2026] [security2:error] [pid 1012520:tid 1012747] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YlgAAAOU"]
[Thu Sep 17 15:19:24.346077 2026] [security2:error] [pid 1012520:tid 1012535] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.bak"] [unique_id "aqxZXApXMN3p_zkwXf2YqQAAqA0"]
[Thu Sep 17 15:19:24.346164 2026] [security2:error] [pid 1012520:tid 1012571] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.backup"] [unique_id "aqxZXApXMN3p_zkwXf2YrAAAqDE"]
[Thu Sep 17 15:19:24.369955 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/campaign/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YuwAAAJ0"]
[Thu Sep 17 15:19:24.433287 2026] [security2:error] [pid 1012520:tid 1012669] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YpAAAAJc"]
[Thu Sep 17 15:19:24.484605 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/database/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YxAAAAPI"]
[Thu Sep 17 15:19:24.542746 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YogAAAPM"]
[Thu Sep 17 15:19:24.565756 2026] [security2:error] [pid 1012520:tid 1012721] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvAAAAMs"]
[Thu Sep 17 15:19:24.567095 2026] [security2:error] [pid 1012520:tid 1012729] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvQAAANM"]
[Thu Sep 17 15:19:24.577645 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvgAAANA"]
[Thu Sep 17 15:19:24.596175 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwgAAALs"]
[Thu Sep 17 15:19:24.596565 2026] [security2:error] [pid 1012520:tid 1012663] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwwAAAJE"]
[Thu Sep 17 15:19:24.597645 2026] [security2:error] [pid 1012520:tid 1012744] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwAAAAOI"]
[Thu Sep 17 15:19:24.597922 2026] [security2:error] [pid 1012520:tid 1012710] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvwAAAMA"]
[Thu Sep 17 15:19:24.598387 2026] [security2:error] [pid 1012520:tid 1012732] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwQAAANY"]
[Thu Sep 17 15:19:24.610178 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/newsletter/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YxQAAAL0"]
[Thu Sep 17 15:19:24.643043 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/storage/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YxgAAAO4"]
[Thu Sep 17 15:19:24.682035 2026] [security2:error] [pid 1012520:tid 1012698] [client 172.239.147.162:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxZXApXMN3p_zkwXf2YxwAAALQ"], referer: binance.com
[Thu Sep 17 15:19:24.756340 2026] [security2:error] [pid 1012520:tid 1012654] [client 159.89.175.243:60633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lowlandblues.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxZXApXMN3p_zkwXf2YyAAAAIg"]
[Thu Sep 17 15:19:24.761147 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.246.241.88:50760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/server-status.php"] [unique_id "aqxZXApXMN3p_zkwXf2YyQAAAOo"]
[Thu Sep 17 15:19:24.770108 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/app/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YygAAAMk"]
[Thu Sep 17 15:19:24.798345 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/var/www/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YywAAAIY"]
[Thu Sep 17 15:19:24.895234 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/ses/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YzAAAAI0"]
[Thu Sep 17 15:19:24.954652 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/var/www/html/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YzQAAAKc"]
[Thu Sep 17 15:19:24.962335 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/apps/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YzgAAAPk"]
[Thu Sep 17 15:19:25.096645 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sendgrid/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y1AAAAKY"]
[Thu Sep 17 15:19:25.110642 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/current/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y1QAAALw"]
[Thu Sep 17 15:19:25.163559 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y1gAAANE"]
[Thu Sep 17 15:19:25.262382 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sparkpost/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y2gAAAJY"]
[Thu Sep 17 15:19:25.264009 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/release/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y2wAAAMc"]
[Thu Sep 17 15:19:25.361979 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/web/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y3wAAAMY"]
[Thu Sep 17 15:19:25.418752 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/releases/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y4wAAAK8"]
[Thu Sep 17 15:19:25.426766 2026] [security2:error] [pid 1012520:tid 1012775] [client 156.192.234.52:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5AAAAQE"]
[Thu Sep 17 15:19:25.427335 2026] [security2:error] [pid 1012520:tid 1012775] [client 156.192.234.52:58239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5AAAAQE"]
[Thu Sep 17 15:19:25.470945 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/postmark/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5gAAAMg"]
[Thu Sep 17 15:19:25.552939 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/site/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5wAAAKI"]
[Thu Sep 17 15:19:25.571107 2026] [security2:error] [pid 1012520:tid 1012585] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/api/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y8gABBD8"]
[Thu Sep 17 15:19:25.571160 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/shared/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y7gAAAJ0"]
[Thu Sep 17 15:19:25.571343 2026] [security2:error] [pid 1012520:tid 1012575] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env~"] [unique_id "aqxZXQpXMN3p_zkwXf2Y6QABBDU"]
[Thu Sep 17 15:19:25.571352 2026] [security2:error] [pid 1012520:tid 1012581] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.swp"] [unique_id "aqxZXQpXMN3p_zkwXf2Y6gABBDs"]
[Thu Sep 17 15:19:25.588526 2026] [security2:error] [pid 1012520:tid 1012573] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/.env.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y6AABBDM"]
[Thu Sep 17 15:19:25.630268 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailgun/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_AAAAPM"]
[Thu Sep 17 15:19:25.718557 2026] [security2:error] [pid 1012520:tid 1012598] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/app/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZAgABBEw"]
[Thu Sep 17 15:19:25.718574 2026] [security2:error] [pid 1012520:tid 1012587] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/backend/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZBAABBEE"]
[Thu Sep 17 15:19:25.718865 2026] [security2:error] [pid 1012520:tid 1012600] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/server/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZBwABBE4"]
[Thu Sep 17 15:19:25.725559 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/deploy/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZCQAAALI"]
[Thu Sep 17 15:19:25.742918 2026] [security2:error] [pid 1012520:tid 1012763] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y-gAAAPU"]
[Thu Sep 17 15:19:25.743540 2026] [security2:error] [pid 1012520:tid 1012677] [client 159.89.175.243:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.175.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lowlandblues.co"] [uri "/xmlrpc.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZAQAAAJ8"]
[Thu Sep 17 15:19:25.744970 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/public/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDAAAANg"]
[Thu Sep 17 15:19:25.793517 2026] [security2:error] [pid 1012520:tid 1012760] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_QAAAPI"]
[Thu Sep 17 15:19:25.793711 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y-wAAALY"]
[Thu Sep 17 15:19:25.809860 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mandrill/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZEAAAAMA"]
[Thu Sep 17 15:19:25.821513 2026] [security2:error] [pid 1012520:tid 1012721] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_wAAAMs"]
[Thu Sep 17 15:19:25.823603 2026] [security2:error] [pid 1012520:tid 1012670] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_gAAAJg"]
[Thu Sep 17 15:19:25.825647 2026] [security2:error] [pid 1012520:tid 1012729] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZAAAAANM"]
[Thu Sep 17 15:19:25.879981 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/build/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZFAAAAPo"]
[Thu Sep 17 15:19:25.901219 2026] [security2:error] [pid 1012520:tid 1012601] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/web/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGgABBE8"]
[Thu Sep 17 15:19:25.901219 2026] [security2:error] [pid 1012520:tid 1012589] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/client/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGwABBEM"]
[Thu Sep 17 15:19:25.901238 2026] [security2:error] [pid 1012520:tid 1012584] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/src/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGAABBD4"]
[Thu Sep 17 15:19:25.901270 2026] [security2:error] [pid 1012520:tid 1012607] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/config/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGQABBFU"]
[Thu Sep 17 15:19:25.902243 2026] [security2:error] [pid 1012520:tid 1012593] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/public/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZHQABBEc"]
[Thu Sep 17 15:19:25.902297 2026] [security2:error] [pid 1012520:tid 1012599] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/frontend/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZHAABBE0"]
[Thu Sep 17 15:19:25.905588 2026] [security2:error] [pid 1012520:tid 1012595] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/var/www/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZHgABBEk"]
[Thu Sep 17 15:19:25.919053 2026] [security2:error] [pid 1012520:tid 1012776] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDQAAAQI"]
[Thu Sep 17 15:19:25.920595 2026] [security2:error] [pid 1012520:tid 1012663] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDwAAAJE"]
[Thu Sep 17 15:19:25.922671 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDgAAALs"]
[Thu Sep 17 15:19:25.938978 2026] [security2:error] [pid 1012520:tid 1012583] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/var/www/html/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZIgAAvz0"]
[Thu Sep 17 15:19:25.994211 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailjet/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZJAAAAKg"]
[Thu Sep 17 15:19:26.000254 2026] [security2:error] [pid 1012520:tid 1012596] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/laravel/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZJQAAiEo"]
[Thu Sep 17 15:19:26.002598 2026] [security2:error] [pid 1012520:tid 1012604] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/application/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZJgAA6lI"]
[Thu Sep 17 15:19:26.019972 2026] [security2:error] [pid 1012520:tid 1012603] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/apps/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKAAAhlE"]
[Thu Sep 17 15:19:26.036358 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/dist/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKQAAAI0"]
[Thu Sep 17 15:19:26.084512 2026] [security2:error] [pid 1012520:tid 1012610] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/backup/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKwAA8Vg"]
[Thu Sep 17 15:19:26.084520 2026] [security2:error] [pid 1012520:tid 1012614] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/dev/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLgAA8Vw"]
[Thu Sep 17 15:19:26.084564 2026] [security2:error] [pid 1012520:tid 1012590] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/prod/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKgAA8UQ"]
[Thu Sep 17 15:19:26.084579 2026] [security2:error] [pid 1012520:tid 1012611] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/back/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLQAA8Vk"]
[Thu Sep 17 15:19:26.084613 2026] [security2:error] [pid 1012520:tid 1012631] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/staging/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMAAA8W0"]
[Thu Sep 17 15:19:26.084641 2026] [security2:error] [pid 1012520:tid 1012615] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/production/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLwAA8V0"]
[Thu Sep 17 15:19:26.084650 2026] [security2:error] [pid 1012520:tid 1012628] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/test/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMQAA8Wo"]
[Thu Sep 17 15:19:26.084692 2026] [security2:error] [pid 1012520:tid 1012612] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/cms/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLAAA8Vo"]
[Thu Sep 17 15:19:26.094798 2026] [security2:error] [pid 1012520:tid 1012627] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/old/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMgAA-Wk"]
[Thu Sep 17 15:19:26.111275 2026] [security2:error] [pid 1012520:tid 1012629] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/new/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMwAAqms"]
[Thu Sep 17 15:19:26.123532 2026] [security2:error] [pid 1012520:tid 1012565] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/node-api/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZNgAA5ys"]
[Thu Sep 17 15:19:26.123532 2026] [security2:error] [pid 1012520:tid 1012569] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/api-backend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZNQAA5y8"]
[Thu Sep 17 15:19:26.123576 2026] [security2:error] [pid 1012520:tid 1012588] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/admin-app/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZNAAA50I"]
[Thu Sep 17 15:19:26.167588 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZXgpXMN3p_zkwXf2ZOQAAALw"]
[Thu Sep 17 15:19:26.172520 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/brevo/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZOgAAANE"]
[Thu Sep 17 15:19:26.188527 2026] [security2:error] [pid 1012520:tid 1012609] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/public_html/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZPAAAxFc"]
[Thu Sep 17 15:19:26.190751 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/public_html/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZPQAAAMw"]
[Thu Sep 17 15:19:26.205708 2026] [security2:error] [pid 1012520:tid 1012623] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/current/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZPwAAxGU"]
[Thu Sep 17 15:19:26.251894 2026] [security2:error] [pid 1012520:tid 1012622] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/administrator/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZOwAAxGQ"]
[Thu Sep 17 15:19:26.269635 2026] [security2:error] [pid 1012520:tid 1012608] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/server/api/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZQwAAklY"]
[Thu Sep 17 15:19:26.269639 2026] [security2:error] [pid 1012520:tid 1012632] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZQQAAkm4"]
[Thu Sep 17 15:19:26.269715 2026] [security2:error] [pid 1012520:tid 1012624] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.docker/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRAAAkmY"]
[Thu Sep 17 15:19:26.269763 2026] [security2:error] [pid 1012520:tid 1012642] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/server/backend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZQgAAkng"]
[Thu Sep 17 15:19:26.270008 2026] [security2:error] [pid 1012520:tid 1012525] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/aws/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRQAAkgM"]
[Thu Sep 17 15:19:26.270064 2026] [security2:error] [pid 1012520:tid 1012643] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/stripe/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRwAAknk"]
[Thu Sep 17 15:19:26.270123 2026] [security2:error] [pid 1012520:tid 1012637] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.aws/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRgAAknM"]
[Thu Sep 17 15:19:26.281707 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZJwAAAKE"]
[Thu Sep 17 15:19:26.296373 2026] [security2:error] [pid 1012520:tid 1012633] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/v1/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTQAAkm8"]
[Thu Sep 17 15:19:26.308534 2026] [security2:error] [pid 1012520:tid 1012616] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/v2/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZUAAAkl4"]
[Thu Sep 17 15:19:26.308533 2026] [security2:error] [pid 1012520:tid 1012635] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/media/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTwAAknE"]
[Thu Sep 17 15:19:26.308590 2026] [security2:error] [pid 1012520:tid 1012619] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/v3/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTgAAkmE"]
[Thu Sep 17 15:19:26.346436 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/htdocs/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZUwAAAJM"]
[Thu Sep 17 15:19:26.419428 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/transactional/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZXAAAAJo"]
[Thu Sep 17 15:19:26.489264 2026] [security2:error] [pid 1012520:tid 1012544] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.git/config.bak"] [unique_id "aqxZXgpXMN3p_zkwXf2ZdwAAkhY"]
[Thu Sep 17 15:19:26.504152 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/www/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfAAAALI"]
[Thu Sep 17 15:19:26.504168 2026] [security2:error] [pid 1012520:tid 1012660] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZVQAAAI4"]
[Thu Sep 17 15:19:26.510266 2026] [security2:error] [pid 1012520:tid 1012751] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZVAAAAOk"]
[Thu Sep 17 15:19:26.516597 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/backend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfwAAAPI"]
[Thu Sep 17 15:19:26.529512 2026] [security2:error] [pid 1012520:tid 1012764] [client 49.51.195.195:50572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTAAAAPY"]
[Thu Sep 17 15:19:26.573697 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/bulk/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZigAAAK0"]
[Thu Sep 17 15:19:26.638398 2026] [security2:error] [pid 1012520:tid 1012740] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZXwAAAN4"]
[Thu Sep 17 15:19:26.665451 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/html/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZiwAAAPo"]
[Thu Sep 17 15:19:26.680336 2026] [security2:error] [pid 1012520:tid 1012730] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZYwAAANQ"]
[Thu Sep 17 15:19:26.696313 2026] [security2:error] [pid 1012520:tid 1012745] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfQAAAOM"]
[Thu Sep 17 15:19:26.714814 2026] [security2:error] [pid 1012520:tid 1012677] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZgwAAAJ8"]
[Thu Sep 17 15:19:26.715496 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/server/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZkAAAALs"]
[Thu Sep 17 15:19:26.719354 2026] [security2:error] [pid 1012520:tid 1012769] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZggAAAPs"]
[Thu Sep 17 15:19:26.779894 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/aws/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZmAAAAPc"]
[Thu Sep 17 15:19:26.829078 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/live/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZnAAAAIY"]
[Thu Sep 17 15:19:26.908350 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/frontend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZqgAAAOw"]
[Thu Sep 17 15:19:26.918271 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.246.241.88:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZqwAAALc"]
[Thu Sep 17 15:19:26.944921 2026] [security2:error] [pid 1012520:tid 1012549] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.aws/credentials.bak"] [unique_id "aqxZXgpXMN3p_zkwXf2ZrwAAkhs"]
[Thu Sep 17 15:19:26.961255 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/azure/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZsQAAAMc"]
[Thu Sep 17 15:19:26.987271 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/prod/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZswAAAKA"]
[Thu Sep 17 15:19:27.108521 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/src/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZtAAAAL4"]
[Thu Sep 17 15:19:27.127470 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/gcp/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZtQAAAQE"]
[Thu Sep 17 15:19:27.142081 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/dev/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZtwAAAJo"]
[Thu Sep 17 15:19:27.269614 2026] [security2:error] [pid 1012520:tid 1012734] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhAAAANg"]
[Thu Sep 17 15:19:27.278180 2026] [security2:error] [pid 1012520:tid 1012697] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZgQAAALM"]
[Thu Sep 17 15:19:27.281096 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhQAAALY"]
[Thu Sep 17 15:19:27.288501 2026] [security2:error] [pid 1012520:tid 1012670] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZiAAAAJg"]
[Thu Sep 17 15:19:27.297182 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/staging/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZvgAAAKY"]
[Thu Sep 17 15:19:27.301803 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/core/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZvwAAANM"]
[Thu Sep 17 15:19:27.304183 2026] [security2:error] [pid 1012520:tid 1012742] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZiQAAAOA"]
[Thu Sep 17 15:19:27.311491 2026] [security2:error] [pid 1012520:tid 1012738] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhwAAANw"]
[Thu Sep 17 15:19:27.312634 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cloud/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZwAAAAK0"]
[Thu Sep 17 15:19:27.336537 2026] [security2:error] [pid 1012520:tid 1012721] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhgAAAMs"]
[Thu Sep 17 15:19:27.336537 2026] [security2:error] [pid 1012520:tid 1012741] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfgAAAN8"]
[Thu Sep 17 15:19:27.408709 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZlQAAAKw"]
[Thu Sep 17 15:19:27.413801 2026] [security2:error] [pid 1012520:tid 1012714] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZrAAAAMQ"]
[Thu Sep 17 15:19:27.413880 2026] [security2:error] [pid 1012520:tid 1012774] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZowAAAQA"]
[Thu Sep 17 15:19:27.416254 2026] [security2:error] [pid 1012520:tid 1012709] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZlwAAAL8"]
[Thu Sep 17 15:19:27.417849 2026] [security2:error] [pid 1012520:tid 1012707] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZlgAAAL0"]
[Thu Sep 17 15:19:27.425801 2026] [security2:error] [pid 1012520:tid 1012682] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2ZvQAAAKQ"]
[Thu Sep 17 15:19:27.434787 2026] [security2:error] [pid 1012520:tid 1012679] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZsgAAAKE"]
[Thu Sep 17 15:19:27.437022 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZsAAAAME"]
[Thu Sep 17 15:19:27.450612 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/opt/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZxQAAAKI"]
[Thu Sep 17 15:19:27.466188 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/infrastructure/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZyQAAAJ8"]
[Thu Sep 17 15:19:27.469847 2026] [security2:error] [pid 1012520:tid 1012527] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.ssh/id_rsa"] [unique_id "aqxZXwpXMN3p_zkwXf2ZywAAkgU"]
[Thu Sep 17 15:19:27.484747 2026] [security2:error] [pid 1012520:tid 1012526] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/id_rsa"] [unique_id "aqxZXwpXMN3p_zkwXf2ZzQAAkgQ"]
[Thu Sep 17 15:19:27.495224 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/core/app/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z0gAAAKc"]
[Thu Sep 17 15:19:27.605344 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/laravel/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z2QAAAIs"]
[Thu Sep 17 15:19:27.614632 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/docker/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z2gAAAJE"]
[Thu Sep 17 15:19:27.616631 2026] [security2:error] [pid 1012520:tid 1012686] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z0AAAAKg"]
[Thu Sep 17 15:19:27.686015 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/config/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z6gAAAI0"]
[Thu Sep 17 15:19:27.766466 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/symfony/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z7gAAAJo"]
[Thu Sep 17 15:19:27.783621 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/k8s/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8QAAAIU"]
[Thu Sep 17 15:19:27.882963 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.246.241.88:50790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z-AAAAKo"]
[Thu Sep 17 15:19:27.883571 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/private/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z9wAAAPw"]
[Thu Sep 17 15:19:27.940401 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/kubernetes/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z-gAAAKM"]
[Thu Sep 17 15:19:27.973634 2026] [security2:error] [pid 1012520:tid 1012732] [client 159.89.175.243:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.175.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lowlandblues.co"] [uri "/wp-login.php"] [unique_id "aqxZXwpXMN3p_zkwXf2aAAAAANY"]
[Thu Sep 17 15:19:28.076044 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/application/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aBQAAALA"]
[Thu Sep 17 15:19:28.126887 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/terraform/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aCAAAAN8"]
[Thu Sep 17 15:19:28.231495 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/wordpress/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aCwAAANM"]
[Thu Sep 17 15:19:28.267416 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/bootstrap/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aDAAAAN4"]
[Thu Sep 17 15:19:28.267647 2026] [security2:error] [pid 1012520:tid 1012698] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2ZzgAAALQ"]
[Thu Sep 17 15:19:28.306006 2026] [security2:error] [pid 1012520:tid 1012752] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1QAAAOo"]
[Thu Sep 17 15:19:28.311870 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1AAAkho"]
[Thu Sep 17 15:19:28.334241 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1wAAknU"]
[Thu Sep 17 15:19:28.336533 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1gAAkn8"]
[Thu Sep 17 15:19:28.354007 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/ansible/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aDwAAAKE"]
[Thu Sep 17 15:19:28.383503 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/wp/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aEgAAAOI"]
[Thu Sep 17 15:19:28.415863 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z4QAAkjY"]
[Thu Sep 17 15:19:28.421087 2026] [security2:error] [pid 1012520:tid 1012678] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z3gAAAKA"]
[Thu Sep 17 15:19:28.424156 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z2wAAkjQ"]
[Thu Sep 17 15:19:28.427138 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z4gAAkhI"]
[Thu Sep 17 15:19:28.432033 2026] [security2:error] [pid 1012520:tid 1012749] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z7wAAAOc"]
[Thu Sep 17 15:19:28.433411 2026] [security2:error] [pid 1012520:tid 1012654] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8wAAAIg"]
[Thu Sep 17 15:19:28.434912 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z4AAAkic"]
[Thu Sep 17 15:19:28.435087 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z3wAAkhQ"]
[Thu Sep 17 15:19:28.441030 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8gAAkh4"]
[Thu Sep 17 15:19:28.442400 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z5AAAkjo"]
[Thu Sep 17 15:19:28.458252 2026] [security2:error] [pid 1012520:tid 1012735] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8AAAANk"]
[Thu Sep 17 15:19:28.463331 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/database/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aFAAAAKU"]
[Thu Sep 17 15:19:28.529100 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.git/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aIAAAAPc"]
[Thu Sep 17 15:19:28.534511 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cms/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aIgAAAKc"]
[Thu Sep 17 15:19:28.596651 2026] [deflate:error] [pid 1012520:tid 1012766] (104)Connection reset by peer: [client 34.95.61.66:53606] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:19:28.635813 2026] [security2:error] [pid 1012520:tid 1012577] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config.php"] [unique_id "aqxZYApXMN3p_zkwXf2aNQAA7Tc"]
[Thu Sep 17 15:19:28.655725 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/storage/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aNgAAAOU"]
[Thu Sep 17 15:19:28.689286 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/drupal/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aOAAAALc"]
[Thu Sep 17 15:19:28.786830 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZYApXMN3p_zkwXf2aPQAAAM4"]
[Thu Sep 17 15:19:28.818401 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/ci/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aQQAAAI4"]
[Thu Sep 17 15:19:28.841186 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/joomla/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aRwAAAJ4"]
[Thu Sep 17 15:19:28.853891 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/var/www/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aSgAAAMA"]
[Thu Sep 17 15:19:28.863935 2026] [security2:error] [pid 1012520:tid 1012772] [client 186.105.232.15:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYApXMN3p_zkwXf2aRAAAAP4"]
[Thu Sep 17 15:19:28.864056 2026] [security2:error] [pid 1012520:tid 1012772] [client 186.105.232.15:61120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYApXMN3p_zkwXf2aRAAAAP4"]
[Thu Sep 17 15:19:28.948632 2026] [cgid:error] [pid 1012520:tid 1012725] (32)Broken pipe: [client 34.95.61.66:53610] AH02651: Error writing request body to script /usr/local/cpanel/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:19:28.990721 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/magento/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aTQAAAKY"]
[Thu Sep 17 15:19:28.991553 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cd/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aTgAAAMo"]
[Thu Sep 17 15:19:29.046680 2026] [security2:error] [pid 1012520:tid 1012668] [client 37.139.53.148:60534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pger.net"] [uri "/football/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aAQAAAJY"], referer: http://pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:19:29.047001 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/var/www/html/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aUAAAANw"]
[Thu Sep 17 15:19:29.079335 2026] [deflate:error] [pid 1012520:tid 1012715] (104)Connection reset by peer: [client 34.95.61.66:53610] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:19:29.141090 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/shopify/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aUQAAAQM"]
[Thu Sep 17 15:19:29.152576 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/jenkins/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aUgAAAPI"]
[Thu Sep 17 15:19:29.243795 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/current/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aVAAAAOs"]
[Thu Sep 17 15:19:29.258016 2026] [security2:error] [pid 1012520:tid 1012721] [client 186.22.253.1:33082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aUwAAyyw"], referer: https://www.bing.com/
[Thu Sep 17 15:19:29.293737 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/prestashop/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aVQAAANs"]
[Thu Sep 17 15:19:29.333405 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/gitlab/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aVwAAAIk"]
[Thu Sep 17 15:19:29.370353 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aHQAA7S4"]
[Thu Sep 17 15:19:29.377467 2026] [security2:error] [pid 1012520:tid 1012666] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aIQAAAJQ"]
[Thu Sep 17 15:19:29.378848 2026] [security2:error] [pid 1012520:tid 1012733] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aIwAAANc"]
[Thu Sep 17 15:19:29.381821 2026] [security2:error] [pid 1012520:tid 1012759] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aJAAAAPE"]
[Thu Sep 17 15:19:29.424583 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aMwAA7UE"]
[Thu Sep 17 15:19:29.426914 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aLQAA7TM"]
[Thu Sep 17 15:19:29.426960 2026] [security2:error] [pid 1012520:tid 1012669] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aJgAAAJc"]
[Thu Sep 17 15:19:29.438186 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/release/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aXwAAAQA"]
[Thu Sep 17 15:19:29.455259 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/codeigniter/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aYAAAAOo"]
[Thu Sep 17 15:19:29.519934 2026] [security2:error] [pid 1012520:tid 1012740] [client 45.169.98.18:50291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aYgAAAN4"]
[Thu Sep 17 15:19:29.520032 2026] [security2:error] [pid 1012520:tid 1012740] [client 45.169.98.18:50291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aYgAAAN4"]
[Thu Sep 17 15:19:29.534978 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/github/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aYwAAALw"]
[Thu Sep 17 15:19:29.547596 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aZAAAAOc"]
[Thu Sep 17 15:19:29.613952 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cakephp/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aaQAAAQI"]
[Thu Sep 17 15:19:29.631768 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/releases/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2abAAAAJM"]
[Thu Sep 17 15:19:29.734307 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.246.241.88:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZYQpXMN3p_zkwXf2afAAAAMc"]
[Thu Sep 17 15:19:29.770117 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/zend/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2afQAAAPc"]
[Thu Sep 17 15:19:29.776949 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/actions/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2afgAAAKc"]
[Thu Sep 17 15:19:29.822896 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/shared/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2ahAAAAJE"]
[Thu Sep 17 15:19:29.922423 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/yii/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aiQAAAQE"]
[Thu Sep 17 15:19:29.925500 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/circleci/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aigAAAM4"]
[Thu Sep 17 15:19:30.022712 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/deploy/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2ajQAAAJ4"]
[Thu Sep 17 15:19:30.076470 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/laravel5/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2akQAAAKk"]
[Thu Sep 17 15:19:30.116798 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/travis/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2akgAAAOQ"]
[Thu Sep 17 15:19:30.156461 2026] [security2:error] [pid 1012520:tid 1012716] [client 66.96.214.58:38664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aXgAAAMY"]
[Thu Sep 17 15:19:30.220808 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/build/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2alwAAAIY"]
[Thu Sep 17 15:19:30.229700 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxZYgpXMN3p_zkwXf2amAAAAJo"]
[Thu Sep 17 15:19:30.232884 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/v1/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2amQAAAMk"]
[Thu Sep 17 15:19:30.257563 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aSQAAALY"]
[Thu Sep 17 15:19:30.257618 2026] [security2:error] [pid 1012520:tid 1012708] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aOgAAAL4"]
[Thu Sep 17 15:19:30.257806 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aMgAA7S0"]
[Thu Sep 17 15:19:30.257962 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aLgAA7Uw"]
[Thu Sep 17 15:19:30.257980 2026] [security2:error] [pid 1012520:tid 1012659] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aOQAAAI0"]
[Thu Sep 17 15:19:30.281491 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aNwAA7UA"]
[Thu Sep 17 15:19:30.283241 2026] [security2:error] [pid 1012520:tid 1012712] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aOwAAAMI"]
[Thu Sep 17 15:19:30.284151 2026] [security2:error] [pid 1012520:tid 1012651] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aPAAAAIU"]
[Thu Sep 17 15:19:30.296090 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/buildkite/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2amgAAAOk"]
[Thu Sep 17 15:19:30.304713 2026] [security2:error] [pid 1012520:tid 1012688] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aPgAAAKo"]
[Thu Sep 17 15:19:30.312458 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxZYgpXMN3p_zkwXf2amwAAALk"]
[Thu Sep 17 15:19:30.386495 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/v2/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2aoAAAAJw"]
[Thu Sep 17 15:19:30.405617 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aeQAAANA"]
[Thu Sep 17 15:19:30.405617 2026] [security2:error] [pid 1012520:tid 1012680] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aawAAAKI"]
[Thu Sep 17 15:19:30.407274 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2adwAAAMM"]
[Thu Sep 17 15:19:30.408035 2026] [security2:error] [pid 1012520:tid 1012696] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2alQAAALI"]
[Thu Sep 17 15:19:30.408620 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aZwAA7VU"]
[Thu Sep 17 15:19:30.410168 2026] [security2:error] [pid 1012520:tid 1012683] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2adAAAAKU"]
[Thu Sep 17 15:19:30.410869 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aegAAAJI"]
[Thu Sep 17 15:19:30.415322 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dist/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2aowAAAN0"]
[Thu Sep 17 15:19:30.458855 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxZYgpXMN3p_zkwXf2apAAAAIo"]
[Thu Sep 17 15:19:30.491711 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mysql/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2apgAAAMw"]
[Thu Sep 17 15:19:30.528242 2026] [security2:error] [pid 1012520:tid 1012744] [client 37.139.53.148:60720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pger.net"] [uri "/wp-login.php"] [unique_id "aqxZYgpXMN3p_zkwXf2apQAAAOI"], referer: http://www.pger.net/wp-login.php?action=register
[Thu Sep 17 15:19:30.530723 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.246.241.88:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZYgpXMN3p_zkwXf2apwAAAMs"]
[Thu Sep 17 15:19:30.539386 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/v3/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2aqQAAAOc"]
[Thu Sep 17 15:19:30.578656 2026] [security2:error] [pid 1012520:tid 1012736] [client 103.61.184.148:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYgpXMN3p_zkwXf2aqwAAANo"]
[Thu Sep 17 15:19:30.578778 2026] [security2:error] [pid 1012520:tid 1012736] [client 103.61.184.148:57642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYgpXMN3p_zkwXf2aqwAAANo"]
[Thu Sep 17 15:19:30.604681 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/public_html/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2arQAAALQ"]
[Thu Sep 17 15:19:30.658522 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/postgres/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2arwAAAQI"]
[Thu Sep 17 15:19:30.693125 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/v1/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2asAAAAMQ"]
[Thu Sep 17 15:19:30.810522 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/htdocs/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2atQAAAJE"]
[Thu Sep 17 15:19:30.846458 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/v2/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2atgAAALs"]
[Thu Sep 17 15:19:30.847388 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mongodb/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2atwAAALc"]
[Thu Sep 17 15:19:30.852478 2026] [security2:error] [pid 1012520:tid 1012565] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/aws.php"] [unique_id "aqxZYgpXMN3p_zkwXf2auwABASs"]
[Thu Sep 17 15:19:30.852502 2026] [security2:error] [pid 1012520:tid 1012609] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/stripe.php"] [unique_id "aqxZYgpXMN3p_zkwXf2avQABAVc"]
[Thu Sep 17 15:19:30.853939 2026] [security2:error] [pid 1012520:tid 1012622] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/mail.php"] [unique_id "aqxZYgpXMN3p_zkwXf2avwABAWQ"]
[Thu Sep 17 15:19:30.864428 2026] [security2:error] [pid 1012520:tid 1012644] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/nexmo.php"] [unique_id "aqxZYgpXMN3p_zkwXf2axwABAXo"]
[Thu Sep 17 15:19:30.864494 2026] [security2:error] [pid 1012520:tid 1012624] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/config.inc.php"] [unique_id "aqxZYgpXMN3p_zkwXf2axQABAWY"]
[Thu Sep 17 15:19:30.888328 2026] [security2:error] [pid 1012520:tid 1012633] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php.bak"] [unique_id "aqxZYgpXMN3p_zkwXf2aywABAW8"]
[Thu Sep 17 15:19:30.888328 2026] [security2:error] [pid 1012520:tid 1012616] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php.old"] [unique_id "aqxZYgpXMN3p_zkwXf2azAABAV4"]
[Thu Sep 17 15:19:30.888801 2026] [security2:error] [pid 1012520:tid 1012637] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php"] [unique_id "aqxZYgpXMN3p_zkwXf2azQABAXM"]
[Thu Sep 17 15:19:30.977139 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2augABAS8"]
[Thu Sep 17 15:19:30.977259 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2avAABAUI"]
[Thu Sep 17 15:19:30.982329 2026] [security2:error] [pid 1012520:tid 1012655] [client 186.22.253.1:33037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a0QAAiXE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818122733&hideanons=1&limit=250&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:30.999233 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/rest/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2a2gAAAKY"]
[Thu Sep 17 15:19:31.001219 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/www/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2a2wAAALY"]
[Thu Sep 17 15:19:31.031403 2026] [security2:error] [pid 1012520:tid 1012619] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php.new"] [unique_id "aqxZYwpXMN3p_zkwXf2a3QABAWE"]
[Thu Sep 17 15:19:31.031924 2026] [security2:error] [pid 1012520:tid 1012544] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/.wp-config.php.swp"] [unique_id "aqxZYwpXMN3p_zkwXf2a3AABARY"]
[Thu Sep 17 15:19:31.044858 2026] [security2:error] [pid 1012520:tid 1012597] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/wp-content/mysql.sql"] [unique_id "aqxZYwpXMN3p_zkwXf2a4gABAUs"]
[Thu Sep 17 15:19:31.070993 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:50830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxZYwpXMN3p_zkwXf2a5wAAAJs"]
[Thu Sep 17 15:19:31.120612 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/redis/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a6QAAAJY"]
[Thu Sep 17 15:19:31.152739 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/graphql/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a6wAAAK0"]
[Thu Sep 17 15:19:31.188128 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/html/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a8AAAAIU"]
[Thu Sep 17 15:19:31.273198 2026] [security2:error] [pid 1012520:tid 1012716] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a0wAAAMY"]
[Thu Sep 17 15:19:31.275596 2026] [security2:error] [pid 1012520:tid 1012667] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a1gAAAJU"]
[Thu Sep 17 15:19:31.276380 2026] [security2:error] [pid 1012520:tid 1012725] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a1wAAAM8"]
[Thu Sep 17 15:19:31.288793 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a8wAAAPk"]
[Thu Sep 17 15:19:31.288894 2026] [security2:error] [pid 1012520:tid 1012746] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a1QAAAOQ"]
[Thu Sep 17 15:19:31.304756 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/gateway/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a9QAAAQM"]
[Thu Sep 17 15:19:31.310855 2026] [security2:error] [pid 1012520:tid 1012652] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a2AAAAIY"]
[Thu Sep 17 15:19:31.360252 2026] [security2:error] [pid 1012520:tid 1012659] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a4AAAAI0"]
[Thu Sep 17 15:19:31.363676 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a4QABAVY"]
[Thu Sep 17 15:19:31.379323 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a5QABAWc"]
[Thu Sep 17 15:19:31.380213 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/live/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a-gAAAK4"]
[Thu Sep 17 15:19:31.380704 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a5gABAXw"]
[Thu Sep 17 15:19:31.381937 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a5AABAWI"]
[Thu Sep 17 15:19:31.400325 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a7gABAXY"]
[Thu Sep 17 15:19:31.403085 2026] [security2:error] [pid 1012520:tid 1012738] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a7wAAANw"]
[Thu Sep 17 15:19:31.412693 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a7QABAQA"]
[Thu Sep 17 15:19:31.442982 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a-wAAAKU"]
[Thu Sep 17 15:19:31.459019 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/microservice/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a_AAAAOo"]
[Thu Sep 17 15:19:31.460391 2026] [security2:error] [pid 1012520:tid 1012626] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/terraform.tfstate.backup"] [unique_id "aqxZYwpXMN3p_zkwXf2a_wABAWg"]
[Thu Sep 17 15:19:31.541459 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxZYwpXMN3p_zkwXf2bBgAAAN0"]
[Thu Sep 17 15:19:31.569960 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/prod/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bBwAAAM0"]
[Thu Sep 17 15:19:31.602107 2026] [security2:error] [pid 1012520:tid 1012682] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bBAAAAKQ"]
[Thu Sep 17 15:19:31.610989 2026] [security2:error] [pid 1012520:tid 1012762] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bBQAAAPQ"]
[Thu Sep 17 15:19:31.613960 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/service/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bCAAAAOg"]
[Thu Sep 17 15:19:31.625596 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/kafka/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bCQAAAKE"]
[Thu Sep 17 15:19:31.626073 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env~"] [unique_id "aqxZYwpXMN3p_zkwXf2bCgAAAIo"]
[Thu Sep 17 15:19:31.759881 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dev/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bDAAAAOY"]
[Thu Sep 17 15:19:31.768608 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/v3/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bDQAAAJ0"]
[Thu Sep 17 15:19:31.783862 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/queue/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bDgAAAJM"]
[Thu Sep 17 15:19:31.921188 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/dev/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bOAAAAJA"]
[Thu Sep 17 15:19:31.954803 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/staging/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bPAAAALA"]
[Thu Sep 17 15:19:31.960670 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/worker/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bPQAAAJY"]
[Thu Sep 17 15:19:31.965052 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.246.241.88:50840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php.old"] [unique_id "aqxZYwpXMN3p_zkwXf2bPgAAAK8"]
[Thu Sep 17 15:19:32.079443 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/staging/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bQAAAAOw"]
[Thu Sep 17 15:19:32.144754 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/job/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bRAAAAPw"]
[Thu Sep 17 15:19:32.149790 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/opt/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bRQAAALM"]
[Thu Sep 17 15:19:32.195303 2026] [security2:error] [pid 1012520:tid 1012698] [client 154.190.208.131:42177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bSgAAALQ"]
[Thu Sep 17 15:19:32.196607 2026] [security2:error] [pid 1012520:tid 1012698] [client 154.190.208.131:42177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bSgAAALQ"]
[Thu Sep 17 15:19:32.234166 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/vendor/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bSwAAAMY"]
[Thu Sep 17 15:19:32.297276 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bFgAA_hk"]
[Thu Sep 17 15:19:32.308375 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/test/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bTgAAAQM"]
[Thu Sep 17 15:19:32.320767 2026] [security2:error] [pid 1012520:tid 1012523] [remote 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bEAAA_gE"]
[Thu Sep 17 15:19:32.323762 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bEQAA_mA"]
[Thu Sep 17 15:19:32.326159 2026] [security2:error] [pid 1012520:tid 1012638] [remote 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bJwAA_nQ"]
[Thu Sep 17 15:19:32.327296 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bLAAAAME"]
[Thu Sep 17 15:19:32.335872 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bUQAAAI0"]
[Thu Sep 17 15:19:32.340074 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/laravel/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bUgAAAJ4"]
[Thu Sep 17 15:19:32.342032 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bLQAAALs"]
[Thu Sep 17 15:19:32.346098 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bGwAA_ns"]
[Thu Sep 17 15:19:32.354777 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bFwAA_gk"]
[Thu Sep 17 15:19:32.390497 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/lib/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bVQAAAMA"]
[Thu Sep 17 15:19:32.413728 2026] [security2:error] [pid 1012520:tid 1012745] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bLgAAAOM"]
[Thu Sep 17 15:19:32.416652 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bVwAAANA"]
[Thu Sep 17 15:19:32.418997 2026] [security2:error] [pid 1012520:tid 1012673] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bNgAAAJs"]
[Thu Sep 17 15:19:32.422531 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bMgAAALY"]
[Thu Sep 17 15:19:32.422535 2026] [security2:error] [pid 1012520:tid 1012719] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bMQAAAMk"]
[Thu Sep 17 15:19:32.422558 2026] [security2:error] [pid 1012520:tid 1012672] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bNwAAAJo"]
[Thu Sep 17 15:19:32.422566 2026] [security2:error] [pid 1012520:tid 1012720] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bNAAAAMo"]
[Thu Sep 17 15:19:32.423113 2026] [security2:error] [pid 1012520:tid 1012655] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bMwAAAIk"]
[Thu Sep 17 15:19:32.436378 2026] [security2:error] [pid 1012520:tid 1012727] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bOQAAANE"]
[Thu Sep 17 15:19:32.461507 2026] [security2:error] [pid 1012520:tid 1012715] [client 185.55.149.49:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bWAAAAMU"]
[Thu Sep 17 15:19:32.461589 2026] [security2:error] [pid 1012520:tid 1012715] [client 185.55.149.49:60072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bWAAAAMU"]
[Thu Sep 17 15:19:32.522858 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bYAAAAN0"]
[Thu Sep 17 15:19:32.532602 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/symfony/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bYwAAAM0"]
[Thu Sep 17 15:19:32.548107 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/resources/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bZgAAAPQ"]
[Thu Sep 17 15:19:32.563772 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/qa/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bZwAAAOg"]
[Thu Sep 17 15:19:32.627370 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bagAAALU"]
[Thu Sep 17 15:19:32.701806 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/assets/.env"] [unique_id "aqxZZApXMN3p_zkwXf2begAAAJk"]
[Thu Sep 17 15:19:32.712242 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bewAAAOc"]
[Thu Sep 17 15:19:32.746506 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.246.241.88:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php~"] [unique_id "aqxZZApXMN3p_zkwXf2bgAAAANk"]
[Thu Sep 17 15:19:32.787341 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bgwAAAIw"]
[Thu Sep 17 15:19:32.846823 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/preview/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bhAAAAJY"]
[Thu Sep 17 15:19:32.860701 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/uploads/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bhQAAAK8"]
[Thu Sep 17 15:19:32.998888 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bjgAAALM"]
[Thu Sep 17 15:19:33.016280 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/internal/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bjwAAAKg"]
[Thu Sep 17 15:19:33.085753 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wordpress/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkAAAAKk"]
[Thu Sep 17 15:19:33.096316 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkQAAALQ"]
[Thu Sep 17 15:19:33.110432 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/beta/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkgAAAMY"]
[Thu Sep 17 15:19:33.177432 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/tools/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkwAAAJU"]
[Thu Sep 17 15:19:33.262307 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2blQAAAM8"]
[Thu Sep 17 15:19:33.273574 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2blgAAAOQ"]
[Thu Sep 17 15:19:33.324438 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/uat/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bmAAAAPs"]
[Thu Sep 17 15:19:33.331288 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/scripts/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bmQAAAOk"]
[Thu Sep 17 15:19:33.368613 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bmwAAAIY"]
[Thu Sep 17 15:19:33.378949 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bXAAA_hE"]
[Thu Sep 17 15:19:33.414819 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bXgAA_h0"]
[Thu Sep 17 15:19:33.418384 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bXwAA_g8"]
[Thu Sep 17 15:19:33.459639 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cms/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bngAAAP8"]
[Thu Sep 17 15:19:33.467131 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.246.241.88:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/info.php.bak"] [unique_id "aqxZZQpXMN3p_zkwXf2bnwAAAQM"]
[Thu Sep 17 15:19:33.468493 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2boAAAANg"]
[Thu Sep 17 15:19:33.483221 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/bin/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2boQAAAM4"]
[Thu Sep 17 15:19:33.517112 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/stage/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bogAAAJQ"]
[Thu Sep 17 15:19:33.547376 2026] [security2:error] [pid 1012520:tid 1012684] [client 172.239.147.162:63422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bhgAAAKY"], referer: binance.com
[Thu Sep 17 15:19:33.578141 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bpgAAANQ"]
[Thu Sep 17 15:19:33.635431 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sbin/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2brwAAAPE"]
[Thu Sep 17 15:19:33.640371 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/drupal/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bsAAAALI"]
[Thu Sep 17 15:19:33.661121 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bswAAAK4"]
[Thu Sep 17 15:19:33.668997 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/development/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2btAAAAIs"]
[Thu Sep 17 15:19:33.730964 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2btgAAAL8"]
[Thu Sep 17 15:19:33.793728 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/local/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2btwAAAKU"]
[Thu Sep 17 15:19:33.821615 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/joomla/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2buAAAAMU"]
[Thu Sep 17 15:19:33.823473 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2buQAAAJI"]
[Thu Sep 17 15:19:33.841866 2026] [security2:error] [pid 1012520:tid 1012685] [client 114.198.138.124:58019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZQpXMN3p_zkwXf2bvAAAAKc"]
[Thu Sep 17 15:19:33.841953 2026] [security2:error] [pid 1012520:tid 1012685] [client 114.198.138.124:58019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZQpXMN3p_zkwXf2bvAAAAKc"]
[Thu Sep 17 15:19:33.856988 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/production/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bvQAAAJE"]
[Thu Sep 17 15:19:33.921382 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bvwAAAPg"]
[Thu Sep 17 15:19:33.948367 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/portal/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bwAAAALE"]
[Thu Sep 17 15:19:34.004817 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bwQAAAN0"]
[Thu Sep 17 15:19:34.009336 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/magento/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bwgAAAM0"]
[Thu Sep 17 15:19:34.031195 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/config/app/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bwwAAAQQ"]
[Thu Sep 17 15:19:34.074992 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bxAAAANM"]
[Thu Sep 17 15:19:34.100274 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/dashboard/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bxwAAAIc"]
[Thu Sep 17 15:19:34.153018 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2byQAAAIg"]
[Thu Sep 17 15:19:34.193276 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/shopify/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bygAAAN4"]
[Thu Sep 17 15:19:34.208976 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.204.169.220:43534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2bywAAAOE"]
[Thu Sep 17 15:19:34.254793 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/panel/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bzAAAAOc"]
[Thu Sep 17 15:19:34.257629 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bYQAA_hU"]
[Thu Sep 17 15:19:34.260252 2026] [security2:error] [pid 1012520:tid 1012656] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bawAAAIo"]
[Thu Sep 17 15:19:34.262987 2026] [security2:error] [pid 1012520:tid 1012675] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfQAAAJ0"]
[Thu Sep 17 15:19:34.263925 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bbAAA_l8"]
[Thu Sep 17 15:19:34.263944 2026] [security2:error] [pid 1012520:tid 1012553] [remote 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bZQAA_h8"]
[Thu Sep 17 15:19:34.264074 2026] [security2:error] [pid 1012520:tid 1012758] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bgQAAAPA"]
[Thu Sep 17 15:19:34.264345 2026] [security2:error] [pid 1012520:tid 1012679] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2baQAAAKE"]
[Thu Sep 17 15:19:34.265909 2026] [security2:error] [pid 1012520:tid 1012748] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfgAAAOY"]
[Thu Sep 17 15:19:34.267149 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2baAAAAO0"]
[Thu Sep 17 15:19:34.272014 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bzQAAALw"]
[Thu Sep 17 15:19:34.273936 2026] [security2:error] [pid 1012520:tid 1012763] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfAAAAPU"]
[Thu Sep 17 15:19:34.279088 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bcQAA_jE"]
[Thu Sep 17 15:19:34.283280 2026] [security2:error] [pid 1012520:tid 1012665] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfwAAAJM"]
[Thu Sep 17 15:19:34.304745 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bbQAA_g0"]
[Thu Sep 17 15:19:34.356296 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b0gAAAKs"]
[Thu Sep 17 15:19:34.374328 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/prestashop/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b1AAAALQ"]
[Thu Sep 17 15:19:34.385260 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZQpXMN3p_zkwXf2bpwAAALY"]
[Thu Sep 17 15:19:34.386721 2026] [security2:error] [pid 1012520:tid 1012727] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZQpXMN3p_zkwXf2brgAAANE"]
[Thu Sep 17 15:19:34.387739 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZQpXMN3p_zkwXf2brQAAAMM"]
[Thu Sep 17 15:19:34.409964 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/crm/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b1QAAAPs"]
[Thu Sep 17 15:19:34.445720 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b1gAAAI0"]
[Thu Sep 17 15:19:34.535543 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b6wAAALk"]
[Thu Sep 17 15:19:34.555458 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/codeigniter/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b7AAAALs"]
[Thu Sep 17 15:19:34.563216 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/erp/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b7QAAAMo"]
[Thu Sep 17 15:19:34.599257 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.246.241.88:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php.save"] [unique_id "aqxZZgpXMN3p_zkwXf2b7gAAAOk"]
[Thu Sep 17 15:19:34.600184 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b3AAA6zc"]
[Thu Sep 17 15:19:34.608229 2026] [security2:error] [pid 1012520:tid 1012745] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b5wAAAOM"]
[Thu Sep 17 15:19:34.608915 2026] [security2:error] [pid 1012520:tid 1012666] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b5gAAAJQ"]
[Thu Sep 17 15:19:34.609104 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b6AAAANA"]
[Thu Sep 17 15:19:34.621237 2026] [security2:error] [pid 1012520:tid 1012710] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b5QAAAMA"]
[Thu Sep 17 15:19:34.626351 2026] [security2:error] [pid 1012520:tid 1012684] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b6QAAAKY"]
[Thu Sep 17 15:19:34.649175 2026] [security2:error] [pid 1012520:tid 1012613] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b9gAA61s"]
[Thu Sep 17 15:19:34.649218 2026] [security2:error] [pid 1012520:tid 1012563] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b-AAA6yk"]
[Thu Sep 17 15:19:34.649305 2026] [security2:error] [pid 1012520:tid 1012564] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/infos.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b-QAA6yo"]
[Thu Sep 17 15:19:34.649910 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b-gAAAJI"]
[Thu Sep 17 15:19:34.651882 2026] [security2:error] [pid 1012520:tid 1012730] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b6gAAANQ"]
[Thu Sep 17 15:19:34.717034 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/shop/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b_wAAAM0"]
[Thu Sep 17 15:19:34.728267 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cAAAAAQQ"]
[Thu Sep 17 15:19:34.741224 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cakephp/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cAgAAAMc"]
[Thu Sep 17 15:19:34.750201 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b8QAA6zw"]
[Thu Sep 17 15:19:34.782908 2026] [security2:error] [pid 1012520:tid 1012636] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/php_info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cBAAA63I"]
[Thu Sep 17 15:19:34.797693 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cBQAAAPc"]
[Thu Sep 17 15:19:34.825655 2026] [security2:error] [pid 1012520:tid 1012695] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b_gAAALE"]
[Thu Sep 17 15:19:34.828443 2026] [security2:error] [pid 1012520:tid 1012596] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/php.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cCgAA60o"]
[Thu Sep 17 15:19:34.828470 2026] [security2:error] [pid 1012520:tid 1012604] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/php-info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cCwAA61I"]
[Thu Sep 17 15:19:34.829147 2026] [security2:error] [pid 1012520:tid 1012606] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/infophp.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cDAAA61Q"]
[Thu Sep 17 15:19:34.830675 2026] [security2:error] [pid 1012520:tid 1012603] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cDgAA61E"]
[Thu Sep 17 15:19:34.832194 2026] [security2:error] [pid 1012520:tid 1012610] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cDwAA61g"]
[Thu Sep 17 15:19:34.832252 2026] [security2:error] [pid 1012520:tid 1012611] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/admin_phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cEAAA61k"]
[Thu Sep 17 15:19:34.832278 2026] [security2:error] [pid 1012520:tid 1012567] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/api/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cEQAA6y0"]
[Thu Sep 17 15:19:34.860535 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.204.169.220:41684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cFQAAAMQ"]
[Thu Sep 17 15:19:34.862943 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cFgAAAN4"]
[Thu Sep 17 15:19:34.870514 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/store/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cFwAAAOc"]
[Thu Sep 17 15:19:34.879101 2026] [security2:error] [pid 1012520:tid 1012589] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/public/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cGQAA60M"]
[Thu Sep 17 15:19:34.925453 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/zend/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cGwAAAJ0"]
[Thu Sep 17 15:19:34.949870 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cHgAAAKE"]
[Thu Sep 17 15:19:35.016797 2026] [security2:error] [pid 1012520:tid 1012599] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/database.sql"] [unique_id "aqxZZwpXMN3p_zkwXf2cKAAA600"]
[Thu Sep 17 15:19:35.024985 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/saas/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cMAAAANs"]
[Thu Sep 17 15:19:35.032212 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cMQAAAKQ"]
[Thu Sep 17 15:19:35.109932 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/yii/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cOwAAAJM"]
[Thu Sep 17 15:19:35.154762 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cQAAAAKM"]
[Thu Sep 17 15:19:35.178145 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/client/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cQQAAANI"]
[Thu Sep 17 15:19:35.257194 2026] [security2:error] [pid 1012520:tid 1012718] [client 172.239.147.162:51980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPwAAAMg"], referer: binance.com
[Thu Sep 17 15:19:35.259473 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cRgAAAPw"]
[Thu Sep 17 15:19:35.300374 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/laravel5/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cSAAAAJs"]
[Thu Sep 17 15:19:35.302737 2026] [security2:error] [pid 1012520:tid 1012752] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cAwAAAOo"]
[Thu Sep 17 15:19:35.332674 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/project/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cSgAAAPs"]
[Thu Sep 17 15:19:35.349869 2026] [security2:error] [pid 1012520:tid 1012750] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cBwAAAOg"]
[Thu Sep 17 15:19:35.357601 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cSwAAAIY"]
[Thu Sep 17 15:19:35.357964 2026] [security2:error] [pid 1012520:tid 1012739] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cBgAAAN0"]
[Thu Sep 17 15:19:35.369997 2026] [security2:error] [pid 1012520:tid 1012729] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cCQAAANM"]
[Thu Sep 17 15:19:35.428472 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cNQAAAK8"]
[Thu Sep 17 15:19:35.429109 2026] [security2:error] [pid 1012520:tid 1012697] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPAAAALM"]
[Thu Sep 17 15:19:35.430962 2026] [security2:error] [pid 1012520:tid 1012669] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cMwAAAJc"]
[Thu Sep 17 15:19:35.431046 2026] [security2:error] [pid 1012520:tid 1012735] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cNAAAANk"]
[Thu Sep 17 15:19:35.434400 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cOgAAAQE"]
[Thu Sep 17 15:19:35.436781 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cTwAAAM4"]
[Thu Sep 17 15:19:35.466729 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.204.169.220:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/php.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cUQAAANc"]
[Thu Sep 17 15:19:35.482773 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/v1/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cUwAAAMU"]
[Thu Sep 17 15:19:35.483189 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/admin-panel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cVAAAAJI"]
[Thu Sep 17 15:19:35.506519 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cVwAAAN8"]
[Thu Sep 17 15:19:35.599111 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cZAAAAN4"]
[Thu Sep 17 15:19:35.638586 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/control-panel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2ccQAAALA"]
[Thu Sep 17 15:19:35.645305 2026] [security2:error] [pid 1012520:tid 1012619] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/settings.php"] [unique_id "aqxZZwpXMN3p_zkwXf2ccgAA62E"]
[Thu Sep 17 15:19:35.668348 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/v2/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cdQAAAPY"]
[Thu Sep 17 15:19:35.688454 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cegAAANI"]
[Thu Sep 17 15:19:35.773458 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.246.241.88:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cfQAAAP4"]
[Thu Sep 17 15:19:35.787140 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cfgAAAMg"]
[Thu Sep 17 15:19:35.792495 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/user-panel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cfwAAAJU"]
[Thu Sep 17 15:19:35.832177 2026] [security2:error] [pid 1012520:tid 1012597] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/public-api/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cgAAA60s"]
[Thu Sep 17 15:19:35.854055 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/v3/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cgwAAAOo"]
[Thu Sep 17 15:19:35.872327 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2chQAAAPo"]
[Thu Sep 17 15:19:35.950416 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/node/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2ciQAAAIY"]
[Thu Sep 17 15:19:35.953476 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cigAAAJk"]
[Thu Sep 17 15:19:36.041606 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/v1/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cjQAAAJg"]
[Thu Sep 17 15:19:36.057301 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cjgAAANM"]
[Thu Sep 17 15:19:36.106086 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/express/.env"] [unique_id "aqxZaApXMN3p_zkwXf2ckAAAAJo"]
[Thu Sep 17 15:19:36.164488 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxZaApXMN3p_zkwXf2ckQAAAK8"]
[Thu Sep 17 15:19:36.175315 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.204.169.220:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/i.php"] [unique_id "aqxZaApXMN3p_zkwXf2ckgAAAN0"]
[Thu Sep 17 15:19:36.227565 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/v2/.env"] [unique_id "aqxZaApXMN3p_zkwXf2ckwAAANk"]
[Thu Sep 17 15:19:36.251522 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxZaApXMN3p_zkwXf2clAAAAJc"]
[Thu Sep 17 15:19:36.256650 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/next/.env"] [unique_id "aqxZaApXMN3p_zkwXf2clQAAAOM"]
[Thu Sep 17 15:19:36.257406 2026] [security2:error] [pid 1012520:tid 1012743] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cGAAAAOE"]
[Thu Sep 17 15:19:36.258779 2026] [security2:error] [pid 1012520:tid 1012686] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPQAAAKg"]
[Thu Sep 17 15:19:36.260586 2026] [security2:error] [pid 1012520:tid 1012732] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cOQAAANY"]
[Thu Sep 17 15:19:36.263013 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cRAAAALY"]
[Thu Sep 17 15:19:36.268258 2026] [security2:error] [pid 1012520:tid 1012760] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPgAAAPI"]
[Thu Sep 17 15:19:36.283812 2026] [security2:error] [pid 1012520:tid 1012706] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cOAAAALw"]
[Thu Sep 17 15:19:36.408574 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/nuxt/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cmQAAAIw"]
[Thu Sep 17 15:19:36.410316 2026] [security2:error] [pid 1012520:tid 1012681] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cewAAAKM"]
[Thu Sep 17 15:19:36.411323 2026] [security2:error] [pid 1012520:tid 1012665] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2ceAAAAJM"]
[Thu Sep 17 15:19:36.411620 2026] [security2:error] [pid 1012520:tid 1012608] [remote 110.249.201.132:33024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/"] [unique_id "aqxZaApXMN3p_zkwXf2cmgAAs1Y"]
[Thu Sep 17 15:19:36.412008 2026] [security2:error] [pid 1012520:tid 1012763] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cdAAAAPU"]
[Thu Sep 17 15:19:36.412234 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cYgAA62Q"]
[Thu Sep 17 15:19:36.412713 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cYAAA61c"]
[Thu Sep 17 15:19:36.412749 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/rest/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cmwAAAI8"]
[Thu Sep 17 15:19:36.413143 2026] [security2:error] [pid 1012520:tid 1012731] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cWQAAANU"]
[Thu Sep 17 15:19:36.414765 2026] [security2:error] [pid 1012520:tid 1012761] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cdgAAAPM"]
[Thu Sep 17 15:19:36.414813 2026] [security2:error] [pid 1012520:tid 1012757] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2ccwAAAO8"]
[Thu Sep 17 15:19:36.415671 2026] [security2:error] [pid 1012520:tid 1012688] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cYQAAAKo"]
[Thu Sep 17 15:19:36.420410 2026] [security2:error] [pid 1012520:tid 1012709] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cjwAAAL8"]
[Thu Sep 17 15:19:36.564837 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cnQAAAIg"]
[Thu Sep 17 15:19:36.564987 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/nest/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cngAAAJE"]
[Thu Sep 17 15:19:36.598240 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/graphql/.env"] [unique_id "aqxZaApXMN3p_zkwXf2coAAAAN4"]
[Thu Sep 17 15:19:36.639268 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxZaApXMN3p_zkwXf2coQAAALA"]
[Thu Sep 17 15:19:36.721337 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/react/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cogAAALQ"]
[Thu Sep 17 15:19:36.734934 2026] [security2:error] [pid 1012520:tid 1012630] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/nextjs-app/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cqwAAw2w"]
[Thu Sep 17 15:19:36.735001 2026] [security2:error] [pid 1012520:tid 1012522] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/web.config.old"] [unique_id "aqxZaApXMN3p_zkwXf2cqQAAwwA"]
[Thu Sep 17 15:19:36.735085 2026] [security2:error] [pid 1012520:tid 1012623] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.htpasswd.bak"] [unique_id "aqxZaApXMN3p_zkwXf2cpAAAw2U"]
[Thu Sep 17 15:19:36.747299 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cvgAAAJs"]
[Thu Sep 17 15:19:36.778283 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/gateway/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cwAAAANM"]
[Thu Sep 17 15:19:36.820344 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.204.169.220:41722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/pi.php"] [unique_id "aqxZaApXMN3p_zkwXf2cygAAAPQ"]
[Thu Sep 17 15:19:36.859079 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxZaApXMN3p_zkwXf2czgAAANA"]
[Thu Sep 17 15:19:36.881813 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/vue/.env"] [unique_id "aqxZaApXMN3p_zkwXf2czwAAAJQ"]
[Thu Sep 17 15:19:36.939722 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxZaApXMN3p_zkwXf2c0QAAAI4"]
[Thu Sep 17 15:19:36.947643 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.246.241.88:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxZaApXMN3p_zkwXf2c0gAAAMk"]
[Thu Sep 17 15:19:36.965817 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/microservice/.env"] [unique_id "aqxZaApXMN3p_zkwXf2c0wAAAJ8"]
[Thu Sep 17 15:19:37.030764 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/angular/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c1AAAAO0"]
[Thu Sep 17 15:19:37.035626 2026] [security2:error] [pid 1012520:tid 1012662] [client 156.192.234.52:59129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c1QAAAJA"]
[Thu Sep 17 15:19:37.037096 2026] [security2:error] [pid 1012520:tid 1012662] [client 156.192.234.52:59129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c1QAAAJA"]
[Thu Sep 17 15:19:37.078081 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c2gAAAPI"]
[Thu Sep 17 15:19:37.150168 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/service/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c3AAAAOY"]
[Thu Sep 17 15:19:37.167724 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c4AAAAJY"]
[Thu Sep 17 15:19:37.182468 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/svelte/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c4gAAANg"]
[Thu Sep 17 15:19:37.201993 2026] [security2:error] [pid 1012520:tid 1012674] [client 74.7.241.138:43422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cnAAAnAM"]
[Thu Sep 17 15:19:37.202010 2026] [security2:error] [pid 1012520:tid 1012674] [client 74.7.241.138:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cnAAAnAM"]
[Thu Sep 17 15:19:37.250039 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c5wAAAPU"]
[Thu Sep 17 15:19:37.317070 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cqAAAw3Y"]
[Thu Sep 17 15:19:37.318792 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cpgAAw3w"]
[Thu Sep 17 15:19:37.320746 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2crQAAwww"]
[Thu Sep 17 15:19:37.331789 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/vite/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c6wAAAP0"]
[Thu Sep 17 15:19:37.335310 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/v3/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c7QAAAQM"]
[Thu Sep 17 15:19:37.352391 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c7gAAAME"]
[Thu Sep 17 15:19:37.352558 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c7gAAAME"]
[Thu Sep 17 15:19:37.358032 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c7wAAAP8"]
[Thu Sep 17 15:19:37.374760 2026] [security2:error] [pid 1012520:tid 1012670] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cvwAAAJg"]
[Thu Sep 17 15:19:37.382631 2026] [security2:error] [pid 1012520:tid 1012746] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cyAAAAOQ"]
[Thu Sep 17 15:19:37.382646 2026] [security2:error] [pid 1012520:tid 1012685] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxAAAAKc"]
[Thu Sep 17 15:19:37.382732 2026] [security2:error] [pid 1012520:tid 1012750] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cwgAAAOg"]
[Thu Sep 17 15:19:37.384181 2026] [security2:error] [pid 1012520:tid 1012655] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cwwAAAIk"]
[Thu Sep 17 15:19:37.389261 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxwAAAK8"]
[Thu Sep 17 15:19:37.390839 2026] [security2:error] [pid 1012520:tid 1012691] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxQAAAK0"]
[Thu Sep 17 15:19:37.392154 2026] [security2:error] [pid 1012520:tid 1012672] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cwQAAAJo"]
[Thu Sep 17 15:19:37.395877 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxgAAALs"]
[Thu Sep 17 15:19:37.395980 2026] [security2:error] [pid 1012520:tid 1012739] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cyQAAAN0"]
[Thu Sep 17 15:19:37.419028 2026] [security2:error] [pid 1012520:tid 1012676] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c2wAAAJ4"]
[Thu Sep 17 15:19:37.420416 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c1wAAw3c"]
[Thu Sep 17 15:19:37.433432 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:41724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/pinfo.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c9AAAAKM"]
[Thu Sep 17 15:19:37.435178 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c2AAAw3s"]
[Thu Sep 17 15:19:37.439422 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c9QAAAMQ"]
[Thu Sep 17 15:19:37.480878 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/backup/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c9gAAAOc"]
[Thu Sep 17 15:19:37.501506 2026] [security2:error] [pid 1012520:tid 1012602] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.local.old"] [unique_id "aqxZaQpXMN3p_zkwXf2c-wAA7FA"]
[Thu Sep 17 15:19:37.513573 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c_AAAAJ0"]
[Thu Sep 17 15:19:37.516418 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/dev/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c_gAAALA"]
[Thu Sep 17 15:19:37.579727 2026] [security2:error] [pid 1012520:tid 1012529] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/node/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dAgAA7Ac"]
[Thu Sep 17 15:19:37.603312 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dBgAAANE"]
[Thu Sep 17 15:19:37.629453 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/backups/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dBwAAAJk"]
[Thu Sep 17 15:19:37.640300 2026] [security2:error] [pid 1012520:tid 1012699] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c_wAAALU"]
[Thu Sep 17 15:19:37.640310 2026] [security2:error] [pid 1012520:tid 1012764] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dAAAAAPY"]
[Thu Sep 17 15:19:37.697256 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/staging/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dCgAAAJ8"]
[Thu Sep 17 15:19:37.707977 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dDAAAAKg"]
[Thu Sep 17 15:19:37.776988 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/old/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dDwAAAIU"]
[Thu Sep 17 15:19:37.862903 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dFwAAAJs"]
[Thu Sep 17 15:19:37.877616 2026] [security2:error] [pid 1012520:tid 1012763] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dGQAAAPU"]
[Thu Sep 17 15:19:37.877719 2026] [security2:error] [pid 1012520:tid 1012763] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dGQAAAPU"]
[Thu Sep 17 15:19:37.878080 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/vendor/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dGAAAAJM"]
[Thu Sep 17 15:19:37.878181 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dGgAAALM"]
[Thu Sep 17 15:19:37.930753 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/tmp/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dGwAAAO8"]
[Thu Sep 17 15:19:38.001378 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dHAAAAKo"]
[Thu Sep 17 15:19:38.061365 2026] [autoindex:error] [pid 1012520:tid 1012658] [client 143.110.154.194:40452] AH01276: Cannot serve directory /home1/seandav5/public_html/ocdpeers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:19:38.065931 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/lib/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dHwAAAME"]
[Thu Sep 17 15:19:38.075900 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dIAAAANc"]
[Thu Sep 17 15:19:38.078305 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/temp/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dIQAAAP8"]
[Thu Sep 17 15:19:38.126438 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.204.169.220:41730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/test.php"] [unique_id "aqxZagpXMN3p_zkwXf2dIgAAAMs"]
[Thu Sep 17 15:19:38.177965 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dIwAAALs"]
[Thu Sep 17 15:19:38.241901 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/lab/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dJAAAAIo"]
[Thu Sep 17 15:19:38.246336 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/resources/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dJQAAAN8"]
[Thu Sep 17 15:19:38.254972 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dJgAAAMU"]
[Thu Sep 17 15:19:38.374466 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dKQAAANo"]
[Thu Sep 17 15:19:38.375246 2026] [security2:error] [pid 1012520:tid 1012687] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dCQAAAKk"]
[Thu Sep 17 15:19:38.383520 2026] [security2:error] [pid 1012520:tid 1012765] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aqxZagpXMN3p_zkwXf2dKgAAAPc"]
[Thu Sep 17 15:19:38.383587 2026] [security2:error] [pid 1012520:tid 1012765] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aqxZagpXMN3p_zkwXf2dKgAAAPc"]
[Thu Sep 17 15:19:38.397019 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cronlab/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLAAAAOs"]
[Thu Sep 17 15:19:38.434702 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/assets/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLQAAAIg"]
[Thu Sep 17 15:19:38.465967 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLgAAAM8"]
[Thu Sep 17 15:19:38.555123 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cron/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLwAAAMg"]
[Thu Sep 17 15:19:38.556036 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dMAAAAK4"]
[Thu Sep 17 15:19:38.624999 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/uploads/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dMgAAAOo"]
[Thu Sep 17 15:19:38.636928 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dMwAAAKA"]
[Thu Sep 17 15:19:38.712747 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/en/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dNQAAAN4"]
[Thu Sep 17 15:19:38.722724 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dNgAAALc"]
[Thu Sep 17 15:19:38.751324 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxZagpXMN3p_zkwXf2dNwAAAKU"]
[Thu Sep 17 15:19:38.820596 2026] [security2:error] [pid 1012520:tid 1012759] [client 192.178.6.4:43350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxZagpXMN3p_zkwXf2dOQAAAPE"]
[Thu Sep 17 15:19:38.824223 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/internal/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dOgAAAMc"]
[Thu Sep 17 15:19:38.827184 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dOwAAALk"]
[Thu Sep 17 15:19:38.910624 2026] [security2:error] [pid 1012520:tid 1012747] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/aa.php"] [unique_id "aqxZagpXMN3p_zkwXf2dRQAAAOU"]
[Thu Sep 17 15:19:38.910743 2026] [security2:error] [pid 1012520:tid 1012747] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/aa.php"] [unique_id "aqxZagpXMN3p_zkwXf2dRQAAAOU"]
[Thu Sep 17 15:19:38.910953 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dRAAAAPk"]
[Thu Sep 17 15:19:38.930411 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/administrator/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dQQAAAO4"]
[Thu Sep 17 15:19:38.989877 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZagpXMN3p_zkwXf2dQwAAANI"]
[Thu Sep 17 15:19:39.010525 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/tools/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dRgAAAL4"]
[Thu Sep 17 15:19:39.043101 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dRwAAAL0"]
[Thu Sep 17 15:19:39.068083 2026] [security2:error] [pid 1012520:tid 1012743] [client 110.249.202.132:60230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/160-Welcome-week.jpg"] [unique_id "aqxZawpXMN3p_zkwXf2dSAAAAOE"]
[Thu Sep 17 15:19:39.084110 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/psnlink/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dSQAAAOI"]
[Thu Sep 17 15:19:39.122055 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dSgAAANA"]
[Thu Sep 17 15:19:39.195700 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/scripts/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dSwAAALg"]
[Thu Sep 17 15:19:39.221722 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dTAAAAI4"]
[Thu Sep 17 15:19:39.232205 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/exapi/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dTQAAAMk"]
[Thu Sep 17 15:19:39.255285 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.204.169.220:41742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/p.php"] [unique_id "aqxZawpXMN3p_zkwXf2dUAAAAQE"]
[Thu Sep 17 15:19:39.297062 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dUgAAALY"]
[Thu Sep 17 15:19:39.380496 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sitemaps/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dVgAAANg"]
[Thu Sep 17 15:19:39.386145 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/bin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dVwAAANY"]
[Thu Sep 17 15:19:39.413419 2026] [security2:error] [pid 1012520:tid 1012776] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/z70.php"] [unique_id "aqxZawpXMN3p_zkwXf2dWAAAAQI"]
[Thu Sep 17 15:19:39.413502 2026] [security2:error] [pid 1012520:tid 1012776] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/z70.php"] [unique_id "aqxZawpXMN3p_zkwXf2dWAAAAQI"]
[Thu Sep 17 15:19:39.430409 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dWQAAAJs"]
[Thu Sep 17 15:19:39.453668 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.246.241.88:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxZawpXMN3p_zkwXf2dWgAAAJc"]
[Thu Sep 17 15:19:39.534175 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dXQAAAO8"]
[Thu Sep 17 15:19:39.574268 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sbin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dXgAAAJY"]
[Thu Sep 17 15:19:39.627016 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dXwAAALw"]
[Thu Sep 17 15:19:39.671628 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.32.0.94:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZawpXMN3p_zkwXf2dXAAAAPM"]
[Thu Sep 17 15:19:39.685977 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:61708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dYwAAAKs"]
[Thu Sep 17 15:19:39.690158 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:61708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dYwAAAKs"]
[Thu Sep 17 15:19:39.738394 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dZQAAAJg"]
[Thu Sep 17 15:19:39.765785 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/local/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dZgAAAMs"]
[Thu Sep 17 15:19:39.864553 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dagAAAK8"]
[Thu Sep 17 15:19:39.867866 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.204.169.220:41746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/debug.php"] [unique_id "aqxZawpXMN3p_zkwXf2dawAAAL8"]
[Thu Sep 17 15:19:39.953098 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/portal/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dbQAAAMU"]
[Thu Sep 17 15:19:39.959520 2026] [security2:error] [pid 1012520:tid 1012737] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/f35.php"] [unique_id "aqxZawpXMN3p_zkwXf2dbgAAANs"]
[Thu Sep 17 15:19:39.959618 2026] [security2:error] [pid 1012520:tid 1012737] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/f35.php"] [unique_id "aqxZawpXMN3p_zkwXf2dbgAAANs"]
[Thu Sep 17 15:19:39.960292 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dbwAAAJI"]
[Thu Sep 17 15:19:39.988933 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.169.98.18:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dcQAAAKw"]
[Thu Sep 17 15:19:39.989018 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.169.98.18:50854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dcQAAAKw"]
[Thu Sep 17 15:19:40.079631 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dcgAAAMY"]
[Thu Sep 17 15:19:40.097039 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.32.0.94:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZawpXMN3p_zkwXf2dcAAAANo"]
[Thu Sep 17 15:19:40.149318 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dashboard/.env"] [unique_id "aqxZbApXMN3p_zkwXf2ddAAAAOw"]
[Thu Sep 17 15:19:40.164670 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxZbApXMN3p_zkwXf2ddQAAAM0"]
[Thu Sep 17 15:19:40.248834 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/www/phpinfo.php"] [unique_id "aqxZbApXMN3p_zkwXf2ddgAAAIo"]
[Thu Sep 17 15:19:40.253755 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/logs/.env"] [unique_id "aqxZbApXMN3p_zkwXf2ddwAAAKE"]
[Thu Sep 17 15:19:40.295635 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxZbApXMN3p_zkwXf2deAAAAIg"]
[Thu Sep 17 15:19:40.341372 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/panel/.env"] [unique_id "aqxZbApXMN3p_zkwXf2deQAAAMw"]
[Thu Sep 17 15:19:40.416938 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dfAAAAKI"]
[Thu Sep 17 15:19:40.458072 2026] [security2:error] [pid 1012520:tid 1012667] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/adminfuns.php"] [unique_id "aqxZbApXMN3p_zkwXf2dgQAAAJU"]
[Thu Sep 17 15:19:40.458152 2026] [security2:error] [pid 1012520:tid 1012667] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/adminfuns.php"] [unique_id "aqxZbApXMN3p_zkwXf2dgQAAAJU"]
[Thu Sep 17 15:19:40.520803 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.204.169.220:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZbApXMN3p_zkwXf2dggAAAJE"]
[Thu Sep 17 15:19:40.524722 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/crm/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dgwAAAIs"]
[Thu Sep 17 15:19:40.535302 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dhQAAAOo"]
[Thu Sep 17 15:19:40.638743 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxZbApXMN3p_zkwXf2diAAAALk"]
[Thu Sep 17 15:19:40.710126 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/erp/.env"] [unique_id "aqxZbApXMN3p_zkwXf2digAAAKY"]
[Thu Sep 17 15:19:40.710138 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cache/.env"] [unique_id "aqxZbApXMN3p_zkwXf2diQAAAN4"]
[Thu Sep 17 15:19:40.730034 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxZbApXMN3p_zkwXf2diwAAAPk"]
[Thu Sep 17 15:19:40.829385 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxZbApXMN3p_zkwXf2djQAAAJk"]
[Thu Sep 17 15:19:40.862652 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailer/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dkAAAANQ"]
[Thu Sep 17 15:19:40.899793 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/shop/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dkgAAAL0"]
[Thu Sep 17 15:19:40.956508 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dlAAAAOM"]
[Thu Sep 17 15:19:40.965784 2026] [security2:error] [pid 1012520:tid 1012744] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/av.php"] [unique_id "aqxZbApXMN3p_zkwXf2dlQAAAOI"]
[Thu Sep 17 15:19:40.965870 2026] [security2:error] [pid 1012520:tid 1012744] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/av.php"] [unique_id "aqxZbApXMN3p_zkwXf2dlQAAAOI"]
[Thu Sep 17 15:19:41.014556 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mail/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dlgAAANA"]
[Thu Sep 17 15:19:41.035933 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.246.241.88:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dmAAAALU"]
[Thu Sep 17 15:19:41.036341 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dlwAAAJQ"]
[Thu Sep 17 15:19:41.085471 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/store/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dmQAAAMk"]
[Thu Sep 17 15:19:41.110127 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dmgAAAQE"]
[Thu Sep 17 15:19:41.116147 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.204.169.220:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dmwAAAOc"]
[Thu Sep 17 15:19:41.165194 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/email/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dnQAAAO0"]
[Thu Sep 17 15:19:41.187642 2026] [security2:error] [pid 1012520:tid 1012727] [client 103.61.184.148:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dnwAAANE"]
[Thu Sep 17 15:19:41.187761 2026] [security2:error] [pid 1012520:tid 1012727] [client 103.61.184.148:58178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dnwAAANE"]
[Thu Sep 17 15:19:41.207364 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2doAAAANk"]
[Thu Sep 17 15:19:41.277997 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/saas/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2doQAAALY"]
[Thu Sep 17 15:19:41.307615 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dowAAAQI"]
[Thu Sep 17 15:19:41.317253 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/smtp/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dpAAAAJs"]
[Thu Sep 17 15:19:41.398307 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dqAAAAMI"]
[Thu Sep 17 15:19:41.465862 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/client/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dqgAAAOY"]
[Thu Sep 17 15:19:41.468100 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailing/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dqwAAANU"]
[Thu Sep 17 15:19:41.479996 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/dex.php"] [unique_id "aqxZbQpXMN3p_zkwXf2drAAAAO8"]
[Thu Sep 17 15:19:41.480108 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/dex.php"] [unique_id "aqxZbQpXMN3p_zkwXf2drAAAAO8"]
[Thu Sep 17 15:19:41.499861 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2drQAAAJY"]
[Thu Sep 17 15:19:41.606332 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2drgAAAPM"]
[Thu Sep 17 15:19:41.619716 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/notifications/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2drwAAAQM"]
[Thu Sep 17 15:19:41.652407 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/project/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dsAAAAPs"]
[Thu Sep 17 15:19:41.682367 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dsQAAALw"]
[Thu Sep 17 15:19:41.704307 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dsgAAANc"]
[Thu Sep 17 15:19:41.774163 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/notify/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dswAAAM4"]
[Thu Sep 17 15:19:41.798025 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dtAAAAK8"]
[Thu Sep 17 15:19:41.843404 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/admin-panel/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2duQAAAJo"]
[Thu Sep 17 15:19:41.918903 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.204.169.220:60018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2duwAAAJg"]
[Thu Sep 17 15:19:41.925150 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sender/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dvAAAAJI"]
[Thu Sep 17 15:19:41.939590 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dvwAAAKw"]
[Thu Sep 17 15:19:41.992186 2026] [security2:error] [pid 1012520:tid 1012774] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/chosen.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dwAAAAQA"]
[Thu Sep 17 15:19:41.992297 2026] [security2:error] [pid 1012520:tid 1012774] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/chosen.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dwAAAAQA"]
[Thu Sep 17 15:19:42.036934 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/control-panel/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dwQAAAKQ"]
[Thu Sep 17 15:19:42.058103 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dwgAAAKk"]
[Thu Sep 17 15:19:42.077083 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/campaign/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dwwAAAPA"]
[Thu Sep 17 15:19:42.162658 2026] [security2:error] [pid 1012520:tid 1012550] [remote 216.73.217.142:2617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxZbgpXMN3p_zkwXf2dxAABBBw"]
[Thu Sep 17 15:19:42.163896 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dxQAAANo"]
[Thu Sep 17 15:19:42.223526 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/user-panel/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dxgAAAM0"]
[Thu Sep 17 15:19:42.227071 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/newsletter/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dxwAAAOs"]
[Thu Sep 17 15:19:42.273205 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dyAAAAKE"]
[Thu Sep 17 15:19:42.366367 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dywAAAJU"]
[Thu Sep 17 15:19:42.378430 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/ses/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dzAAAAPo"]
[Thu Sep 17 15:19:42.414103 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/node/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dzgAAAOo"]
[Thu Sep 17 15:19:42.421591 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/site/phpinfo.php"] [unique_id "aqxZbgpXMN3p_zkwXf2dzwAAAOw"]
[Thu Sep 17 15:19:42.481287 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d0AAAAJ4"]
[Thu Sep 17 15:19:42.492791 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "moneysmartlatina.com"] [uri "/1.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d0QAAALc"]
[Thu Sep 17 15:19:42.492865 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/1.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d0QAAALc"]
[Thu Sep 17 15:19:42.492950 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/1.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d0QAAALc"]
[Thu Sep 17 15:19:42.529744 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sendgrid/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d0gAAAKM"]
[Thu Sep 17 15:19:42.579390 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d0wAAAPg"]
[Thu Sep 17 15:19:42.592623 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.204.169.220:60022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d1AAAAKg"]
[Thu Sep 17 15:19:42.600280 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/express/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d1QAAAPE"]
[Thu Sep 17 15:19:42.670506 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d1gAAAMc"]
[Thu Sep 17 15:19:42.679925 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sparkpost/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d1wAAALk"]
[Thu Sep 17 15:19:42.717356 2026] [security2:error] [pid 1012520:tid 1012722] [client 154.190.208.131:41435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d2AAAAMw"]
[Thu Sep 17 15:19:42.717445 2026] [security2:error] [pid 1012520:tid 1012722] [client 154.190.208.131:41435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d2AAAAMw"]
[Thu Sep 17 15:19:42.760743 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d2wAAAKY"]
[Thu Sep 17 15:19:42.788144 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/next/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d3AAAAN4"]
[Thu Sep 17 15:19:42.831287 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/postmark/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d3gAAAPk"]
[Thu Sep 17 15:19:42.870424 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d4wAAAJk"]
[Thu Sep 17 15:19:42.949281 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d5gAAANQ"]
[Thu Sep 17 15:19:42.970951 2026] [security2:error] [pid 1012520:tid 1012675] [client 45.181.99.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "threadalittlelight.com"] [uri "/index.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d5AAAAJ0"], referer: https://threadalittlelight.com
[Thu Sep 17 15:19:42.975336 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/nuxt/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d5wAAAOM"]
[Thu Sep 17 15:19:42.987242 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailgun/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d6AAAANA"]
[Thu Sep 17 15:19:43.005459 2026] [security2:error] [pid 1012520:tid 1012699] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/radio.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d6QAAALU"]
[Thu Sep 17 15:19:43.005524 2026] [security2:error] [pid 1012520:tid 1012699] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/radio.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d6QAAALU"]
[Thu Sep 17 15:19:43.080001 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d6gAAALg"]
[Thu Sep 17 15:19:43.111117 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.246.241.88:55596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d6wAAAL4"]
[Thu Sep 17 15:19:43.140835 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mandrill/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d7AAAAOc"]
[Thu Sep 17 15:19:43.162289 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/nest/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d7gAAAO0"]
[Thu Sep 17 15:19:43.192898 2026] [security2:error] [pid 1012520:tid 1012707] [client 185.55.149.49:60709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d8AAAAL0"]
[Thu Sep 17 15:19:43.192968 2026] [security2:error] [pid 1012520:tid 1012707] [client 185.55.149.49:60709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d8AAAAL0"]
[Thu Sep 17 15:19:43.193722 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d7QAAAJA"]
[Thu Sep 17 15:19:43.284644 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d8QAAANk"]
[Thu Sep 17 15:19:43.295735 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailjet/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d8gAAAPI"]
[Thu Sep 17 15:19:43.332733 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.204.169.220:60038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d8wAAAPY"]
[Thu Sep 17 15:19:43.349160 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/react/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d9AAAALY"]
[Thu Sep 17 15:19:43.450396 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/brevo/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d-AAAAIY"]
[Thu Sep 17 15:19:43.493875 2026] [security2:error] [pid 1012520:tid 1012748] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/blacks.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d-gAAAOY"]
[Thu Sep 17 15:19:43.493961 2026] [security2:error] [pid 1012520:tid 1012748] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/blacks.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d-gAAAOY"]
[Thu Sep 17 15:19:43.522482 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d-wAAANU"]
[Thu Sep 17 15:19:43.538301 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/vue/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d_AAAALM"]
[Thu Sep 17 15:19:43.603388 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/transactional/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d_gAAAJM"]
[Thu Sep 17 15:19:43.627815 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d_wAAAPs"]
[Thu Sep 17 15:19:43.733514 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/angular/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eAQAAANc"]
[Thu Sep 17 15:19:43.769162 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/bulk/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eAgAAAKc"]
[Thu Sep 17 15:19:43.901387 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eCQAAAQA"]
[Thu Sep 17 15:19:43.915839 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/svelte/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eCgAAAKQ"]
[Thu Sep 17 15:19:43.922920 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/aws/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eCwAAAKk"]
[Thu Sep 17 15:19:43.996375 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.204.169.220:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZbwpXMN3p_zkwXf2eDwAAAJI"]
[Thu Sep 17 15:19:44.009542 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eEAAAAL8"]
[Thu Sep 17 15:19:44.044011 2026] [security2:error] [pid 1012520:tid 1012778] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/alfa.php"] [unique_id "aqxZcApXMN3p_zkwXf2eEQAAAQQ"]
[Thu Sep 17 15:19:44.044070 2026] [security2:error] [pid 1012520:tid 1012778] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/alfa.php"] [unique_id "aqxZcApXMN3p_zkwXf2eEQAAAQQ"]
[Thu Sep 17 15:19:44.080294 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/azure/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eEgAAAM0"]
[Thu Sep 17 15:19:44.094677 2026] [access_compat:error] [pid 1012520:tid 1012753] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/wedding-salon-2
[Thu Sep 17 15:19:44.101919 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/vite/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eFAAAAIo"]
[Thu Sep 17 15:19:44.112246 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eFQAAAIg"]
[Thu Sep 17 15:19:44.126402 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZcApXMN3p_zkwXf2eFgAAAM4"]
[Thu Sep 17 15:19:44.201387 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eFwAAAK4"]
[Thu Sep 17 15:19:44.230358 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/gcp/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eGQAAAPo"]
[Thu Sep 17 15:19:44.278117 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eGgAAAKs"]
[Thu Sep 17 15:19:44.288272 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/backup/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eGwAAAOo"]
[Thu Sep 17 15:19:44.381417 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cloud/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eHwAAAMA"]
[Thu Sep 17 15:19:44.474871 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/backups/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eIQAAAM8"]
[Thu Sep 17 15:19:44.531442 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/infrastructure/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eIwAAALk"]
[Thu Sep 17 15:19:44.564320 2026] [security2:error] [pid 1012520:tid 1012773] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/w.php"] [unique_id "aqxZcApXMN3p_zkwXf2eJAAAAP8"]
[Thu Sep 17 15:19:44.564382 2026] [security2:error] [pid 1012520:tid 1012773] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/w.php"] [unique_id "aqxZcApXMN3p_zkwXf2eJAAAAP8"]
[Thu Sep 17 15:19:44.571020 2026] [security2:error] [pid 1012520:tid 1012754] [client 114.198.138.124:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcApXMN3p_zkwXf2eIgAAAOw"]
[Thu Sep 17 15:19:44.571103 2026] [security2:error] [pid 1012520:tid 1012754] [client 114.198.138.124:62108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcApXMN3p_zkwXf2eIgAAAOw"]
[Thu Sep 17 15:19:44.620548 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eJQAAAMw"]
[Thu Sep 17 15:19:44.664078 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/old/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eJgAAAN4"]
[Thu Sep 17 15:19:44.683205 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/docker/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eJwAAAPk"]
[Thu Sep 17 15:19:44.703367 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eKQAAAJk"]
[Thu Sep 17 15:19:44.780300 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eLAAAAOQ"]
[Thu Sep 17 15:19:44.803251 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.246.241.88:55608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZcApXMN3p_zkwXf2eLgAAAKY"]
[Thu Sep 17 15:19:44.833563 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/k8s/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eLwAAAOI"]
[Thu Sep 17 15:19:44.849643 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/tmp/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eMAAAANA"]
[Thu Sep 17 15:19:44.865495 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eMgAAALU"]
[Thu Sep 17 15:19:44.898745 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZcApXMN3p_zkwXf2eLQAAAOM"]
[Thu Sep 17 15:19:44.951390 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eNwAAAMo"]
[Thu Sep 17 15:19:44.983454 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/kubernetes/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eOQAAAQE"]
[Thu Sep 17 15:19:45.038213 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/temp/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eOgAAANw"]
[Thu Sep 17 15:19:45.050020 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eOwAAAOc"]
[Thu Sep 17 15:19:45.091166 2026] [security2:error] [pid 1012520:tid 1012707] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp_blog_footer.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ePAAAAL0"]
[Thu Sep 17 15:19:45.091229 2026] [security2:error] [pid 1012520:tid 1012707] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp_blog_footer.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ePAAAAL0"]
[Thu Sep 17 15:19:45.132807 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ePQAAANk"]
[Thu Sep 17 15:19:45.133628 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/terraform/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ePgAAAPI"]
[Thu Sep 17 15:19:45.162137 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.204.169.220:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/php-info.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ePwAAAPY"]
[Thu Sep 17 15:19:45.222810 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eQgAAAPQ"]
[Thu Sep 17 15:19:45.240591 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/lab/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eRAAAAIY"]
[Thu Sep 17 15:19:45.286607 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/ansible/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eRgAAAJw"]
[Thu Sep 17 15:19:45.317132 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eRwAAAMI"]
[Thu Sep 17 15:19:45.373643 2026] [security2:error] [pid 1012520:tid 1012700] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eQAAAALY"]
[Thu Sep 17 15:19:45.421693 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTAAAAP0"]
[Thu Sep 17 15:19:45.427218 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cronlab/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTQAAAJM"]
[Thu Sep 17 15:19:45.433215 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTgAAAPM"]
[Thu Sep 17 15:19:45.438033 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.git/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTwAAAKA"]
[Thu Sep 17 15:19:45.497570 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eUgAAAPs"]
[Thu Sep 17 15:19:45.558142 2026] [security2:error] [pid 1012520:tid 1012661] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eUAAAAI8"]
[Thu Sep 17 15:19:45.589762 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/ci/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eWAAAAI0"]
[Thu Sep 17 15:19:45.593971 2026] [security2:error] [pid 1012520:tid 1012739] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/sss.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eWQAAAN0"]
[Thu Sep 17 15:19:45.594046 2026] [security2:error] [pid 1012520:tid 1012739] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/sss.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eWQAAAN0"]
[Thu Sep 17 15:19:45.596172 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eWwAAAJg"]
[Thu Sep 17 15:19:45.611518 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cron/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eXAAAAKQ"]
[Thu Sep 17 15:19:45.644765 2026] [security2:error] [pid 1012520:tid 1012613] [remote 47.128.23.119:48504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ec235nothing.cyberpunkonline.net"] [uri "/robots.txt"] [unique_id "aqxZcQpXMN3p_zkwXf2eXQAA_Fs"]
[Thu Sep 17 15:19:45.698395 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eYQAAAJI"]
[Thu Sep 17 15:19:45.741658 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cd/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eZAAAAM0"]
[Thu Sep 17 15:19:45.753927 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.204.169.220:60078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpversion.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eZQAAAMs"]
[Thu Sep 17 15:19:45.783347 2026] [security2:error] [pid 1012520:tid 1012716] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eXwAAAMY"]
[Thu Sep 17 15:19:45.797197 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/en/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eZwAAAPc"]
[Thu Sep 17 15:19:45.813097 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eaAAAAIo"]
[Thu Sep 17 15:19:45.893364 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/jenkins/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ebAAAAK4"]
[Thu Sep 17 15:19:45.898669 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.246.241.88:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/core/phpinfo.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ebQAAAQA"]
[Thu Sep 17 15:19:45.932741 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ebwAAAPo"]
[Thu Sep 17 15:19:45.971340 2026] [security2:error] [pid 1012520:tid 1012724] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eawAAAM4"]
[Thu Sep 17 15:19:46.026746 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ecwAAAPg"]
[Thu Sep 17 15:19:46.034467 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/administrator/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ecgAAAJ4"]
[Thu Sep 17 15:19:46.043458 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/gitlab/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2edQAAAKI"]
[Thu Sep 17 15:19:46.103820 2026] [security2:error] [pid 1012520:tid 1012717] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/b8.php"] [unique_id "aqxZcgpXMN3p_zkwXf2eeAAAAMc"]
[Thu Sep 17 15:19:46.103941 2026] [security2:error] [pid 1012520:tid 1012717] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/b8.php"] [unique_id "aqxZcgpXMN3p_zkwXf2eeAAAAMc"]
[Thu Sep 17 15:19:46.167564 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eeQAAAP8"]
[Thu Sep 17 15:19:46.196934 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/github/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eegAAAOw"]
[Thu Sep 17 15:19:46.222613 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/psnlink/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eewAAAN4"]
[Thu Sep 17 15:19:46.265983 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2efAAAAPk"]
[Thu Sep 17 15:19:46.329617 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.204.169.220:60090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/_phpinfo.php"] [unique_id "aqxZcgpXMN3p_zkwXf2egQAAALk"]
[Thu Sep 17 15:19:46.352224 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/actions/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eggAAAIk"]
[Thu Sep 17 15:19:46.362825 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ehQAAAOM"]
[Thu Sep 17 15:19:46.403224 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/exapi/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ehgAAANQ"]
[Thu Sep 17 15:19:46.433855 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eiAAAAMo"]
[Thu Sep 17 15:19:46.509307 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/circleci/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eigAAAL4"]
[Thu Sep 17 15:19:46.533317 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eiwAAANw"]
[Thu Sep 17 15:19:46.589030 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sitemaps/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ejAAAAJQ"]
[Thu Sep 17 15:19:46.618312 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ekAAAANE"]
[Thu Sep 17 15:19:46.624307 2026] [security2:error] [pid 1012520:tid 1012735] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/xex.php"] [unique_id "aqxZcgpXMN3p_zkwXf2ekQAAANk"]
[Thu Sep 17 15:19:46.624399 2026] [security2:error] [pid 1012520:tid 1012735] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/xex.php"] [unique_id "aqxZcgpXMN3p_zkwXf2ekQAAANk"]
[Thu Sep 17 15:19:46.639656 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.246.241.88:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxZcgpXMN3p_zkwXf2ekgAAAKg"]
[Thu Sep 17 15:19:46.665539 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/travis/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2elAAAAQI"]
[Thu Sep 17 15:19:46.685740 2026] [security2:error] [pid 1012520:tid 1012756] [client 156.192.234.52:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcgpXMN3p_zkwXf2elQAAAO4"]
[Thu Sep 17 15:19:46.687160 2026] [security2:error] [pid 1012520:tid 1012756] [client 156.192.234.52:59817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcgpXMN3p_zkwXf2elQAAAO4"]
[Thu Sep 17 15:19:46.736333 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2elgAAAJc"]
[Thu Sep 17 15:19:46.811755 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2emwAAALY"]
[Thu Sep 17 15:19:46.827841 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/buildkite/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2enQAAAQM"]
[Thu Sep 17 15:19:46.892027 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eoAAAAPs"]
[Thu Sep 17 15:19:46.915404 2026] [security2:error] [pid 1012520:tid 1012697] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcgpXMN3p_zkwXf2emgAAALM"]
[Thu Sep 17 15:19:46.984790 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mysql/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2epAAAAKc"]
[Thu Sep 17 15:19:46.984790 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2epQAAANU"]
[Thu Sep 17 15:19:47.011061 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZcwpXMN3p_zkwXf2epwAAAOY"]
[Thu Sep 17 15:19:47.045591 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZcgpXMN3p_zkwXf2enAAAAKo"]
[Thu Sep 17 15:19:47.067183 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eqAAAAKQ"]
[Thu Sep 17 15:19:47.127521 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ass.php"] [unique_id "aqxZcwpXMN3p_zkwXf2eqQAAAO8"]
[Thu Sep 17 15:19:47.127588 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ass.php"] [unique_id "aqxZcwpXMN3p_zkwXf2eqQAAAO8"]
[Thu Sep 17 15:19:47.140409 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/postgres/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eqgAAAJs"]
[Thu Sep 17 15:19:47.170071 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eqwAAAPE"]
[Thu Sep 17 15:19:47.241127 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ergAAAOg"]
[Thu Sep 17 15:19:47.313600 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mongodb/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2esAAAAK8"]
[Thu Sep 17 15:19:47.322587 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2esQAAAIo"]
[Thu Sep 17 15:19:47.399667 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2etgAAAPo"]
[Thu Sep 17 15:19:47.469681 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/redis/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2evQAAAIs"]
[Thu Sep 17 15:19:47.508974 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2evgAAAKs"]
[Thu Sep 17 15:19:47.550324 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "aqxZcwpXMN3p_zkwXf2evwAAAKM"]
[Thu Sep 17 15:19:47.591386 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.204.169.220:60116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/server-info.php"] [unique_id "aqxZcwpXMN3p_zkwXf2ewAAAAM4"]
[Thu Sep 17 15:19:47.600135 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ewQAAAIc"]
[Thu Sep 17 15:19:47.622584 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/elasticsearch/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ewwAAALc"]
[Thu Sep 17 15:19:47.640890 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/jybkxer.php"] [unique_id "aqxZcwpXMN3p_zkwXf2exAAAAME"]
[Thu Sep 17 15:19:47.640999 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/jybkxer.php"] [unique_id "aqxZcwpXMN3p_zkwXf2exAAAAME"]
[Thu Sep 17 15:19:47.665284 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZcwpXMN3p_zkwXf2euwAAAKI"]
[Thu Sep 17 15:19:47.722121 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2exwAAAMA"]
[Thu Sep 17 15:19:47.775361 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/rabbitmq/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eyQAAAMw"]
[Thu Sep 17 15:19:47.782395 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "aqxZcwpXMN3p_zkwXf2eygAAAN4"]
[Thu Sep 17 15:19:47.853189 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ezQAAALk"]
[Thu Sep 17 15:19:47.864915 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/logs/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ezgAAAIk"]
[Thu Sep 17 15:19:47.927155 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/kafka/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2e0QAAAOQ"]
[Thu Sep 17 15:19:47.971821 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2e1AAAAJk"]
[Thu Sep 17 15:19:48.068243 2026] [security2:error] [pid 1012520:tid 1012729] [client 195.2.78.191:60520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxZcwpXMN3p_zkwXf2e0wAAANM"], referer: http://sqlerudition.com/tag/tips-and-tricks/
[Thu Sep 17 15:19:48.082040 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/queue/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e2gAAAMQ"]
[Thu Sep 17 15:19:48.082040 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e2QAAANI"]
[Thu Sep 17 15:19:48.138150 2026] [security2:error] [pid 1012520:tid 1012755] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wsd.php"] [unique_id "aqxZdApXMN3p_zkwXf2e3QAAAO0"]
[Thu Sep 17 15:19:48.138284 2026] [security2:error] [pid 1012520:tid 1012755] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wsd.php"] [unique_id "aqxZdApXMN3p_zkwXf2e3QAAAO0"]
[Thu Sep 17 15:19:48.159889 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e3gAAANE"]
[Thu Sep 17 15:19:48.233478 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/worker/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e3wAAAOs"]
[Thu Sep 17 15:19:48.261089 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e4AAAAPY"]
[Thu Sep 17 15:19:48.297502 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.204.169.220:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/server-status.php"] [unique_id "aqxZdApXMN3p_zkwXf2e4gAAANw"]
[Thu Sep 17 15:19:48.299581 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "aqxZdApXMN3p_zkwXf2e4QAAAQI"]
[Thu Sep 17 15:19:48.342763 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e5gAAAL0"]
[Thu Sep 17 15:19:48.385837 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/job/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e6QAAALY"]
[Thu Sep 17 15:19:48.412217 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cache/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e6gAAANk"]
[Thu Sep 17 15:19:48.417847 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e6wAAAQM"]
[Thu Sep 17 15:19:48.515386 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e7AAAALM"]
[Thu Sep 17 15:19:48.536845 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/test/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e8AAAAKc"]
[Thu Sep 17 15:19:48.592592 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailer/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e8gAAAKo"]
[Thu Sep 17 15:19:48.626563 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e8wAAAJg"]
[Thu Sep 17 15:19:48.628683 2026] [security2:error] [pid 1012520:tid 1012712] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/media.php"] [unique_id "aqxZdApXMN3p_zkwXf2e9AAAAMI"]
[Thu Sep 17 15:19:48.628775 2026] [security2:error] [pid 1012520:tid 1012712] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/media.php"] [unique_id "aqxZdApXMN3p_zkwXf2e9AAAAMI"]
[Thu Sep 17 15:19:48.688635 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/qa/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e9wAAAKk"]
[Thu Sep 17 15:19:48.764474 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e-AAAAPU"]
[Thu Sep 17 15:19:48.781709 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mail/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e-QAAAPw"]
[Thu Sep 17 15:19:48.841099 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/preview/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e_wAAAL8"]
[Thu Sep 17 15:19:48.885976 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fAAAAAOg"]
[Thu Sep 17 15:19:48.968428 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fBAAAANo"]
[Thu Sep 17 15:19:48.968469 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/email/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fBQAAAM0"]
[Thu Sep 17 15:19:48.994569 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/beta/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fBgAAAPo"]
[Thu Sep 17 15:19:49.054249 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fCQAAAKs"]
[Thu Sep 17 15:19:49.139831 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fCwAAANs"]
[Thu Sep 17 15:19:49.140895 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ops.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fDAAAAPA"]
[Thu Sep 17 15:19:49.140973 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ops.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fDAAAAPA"]
[Thu Sep 17 15:19:49.149102 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/uat/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fDQAAAJU"]
[Thu Sep 17 15:19:49.157124 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/smtp/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fDgAAAM4"]
[Thu Sep 17 15:19:49.220392 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fEgAAAKI"]
[Thu Sep 17 15:19:49.253263 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fCgAAAKM"]
[Thu Sep 17 15:19:49.296152 2026] [security2:error] [pid 1012520:tid 1012653] [client 92.72.180.217:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fDwAAhz8"]
[Thu Sep 17 15:19:49.303779 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/stage/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fGAAAAOI"]
[Thu Sep 17 15:19:49.321261 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fGgAAALU"]
[Thu Sep 17 15:19:49.339125 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailing/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fGwAAAOQ"]
[Thu Sep 17 15:19:49.417970 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fHwAAANQ"]
[Thu Sep 17 15:19:49.453642 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/development/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fIwAAANI"]
[Thu Sep 17 15:19:49.521135 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/notifications/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fJwAAAOc"]
[Thu Sep 17 15:19:49.556377 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fKQAAANE"]
[Thu Sep 17 15:19:49.567329 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fJAAAAMQ"]
[Thu Sep 17 15:19:49.605704 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/production/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fLAAAAIw"]
[Thu Sep 17 15:19:49.667509 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fLgAAAJ8"]
[Thu Sep 17 15:19:49.670868 2026] [security2:error] [pid 1012520:tid 1012719] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/BDKR28WP.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fLwAAAMk"]
[Thu Sep 17 15:19:49.670965 2026] [security2:error] [pid 1012520:tid 1012719] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/BDKR28WP.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fLwAAAMk"]
[Thu Sep 17 15:19:49.702306 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/notify/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fMAAAALY"]
[Thu Sep 17 15:19:49.706838 2026] [security2:error] [pid 1012520:tid 1012776] [client 92.72.180.217:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fKwABAkA"]
[Thu Sep 17 15:19:49.723964 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.204.169.220:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZdQpXMN3p_zkwXf2fMQAAANY"]
[Thu Sep 17 15:19:49.761117 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/config/app/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fMgAAANk"]
[Thu Sep 17 15:19:49.773224 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fNQAAAJM"]
[Thu Sep 17 15:19:49.873759 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fOgAAALM"]
[Thu Sep 17 15:19:49.882055 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sender/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fOwAAAIU"]
[Thu Sep 17 15:19:49.919774 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.32.0.94:40746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpinfo.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fPAAAAI0"]
[Thu Sep 17 15:19:49.979984 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fPwAAAOU"]
[Thu Sep 17 15:19:50.064238 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/campaign/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fQgAAANU"]
[Thu Sep 17 15:19:50.089830 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.95.61.66:38424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fRQAAAKo"]
[Thu Sep 17 15:19:50.180373 2026] [security2:error] [pid 1012520:tid 1012682] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/mac.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fRgAAAKQ"]
[Thu Sep 17 15:19:50.180492 2026] [security2:error] [pid 1012520:tid 1012682] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/mac.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fRgAAAKQ"]
[Thu Sep 17 15:19:50.247195 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/newsletter/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fRwAAAPI"]
[Thu Sep 17 15:19:50.324340 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.204.169.220:39412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fSQAAAPU"]
[Thu Sep 17 15:19:50.380518 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.32.0.94:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/info.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUAAAAP0"]
[Thu Sep 17 15:19:50.394265 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.95.61.66:53080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/info.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUQAAAN8"]
[Thu Sep 17 15:19:50.433399 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/ses/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fUgAAANg"]
[Thu Sep 17 15:19:50.474797 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.169.98.18:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUwAAAK8"]
[Thu Sep 17 15:19:50.474931 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.169.98.18:51411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUwAAAK8"]
[Thu Sep 17 15:19:50.616148 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sendgrid/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fVwAAAMc"]
[Thu Sep 17 15:19:50.676528 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.95.61.66:53086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/php.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fXAAAAPA"]
[Thu Sep 17 15:19:50.686338 2026] [security2:error] [pid 1012520:tid 1012703] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wmore1.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fXgAAALk"]
[Thu Sep 17 15:19:50.686408 2026] [security2:error] [pid 1012520:tid 1012703] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wmore1.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fXgAAALk"]
[Thu Sep 17 15:19:50.798807 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sparkpost/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fYQAAAOI"]
[Thu Sep 17 15:19:50.847793 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.32.0.94:45152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/php.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fYwAAAIs"]
[Thu Sep 17 15:19:50.911863 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2faQAAAKs"]
[Thu Sep 17 15:19:50.912019 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:62321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2faQAAAKs"]
[Thu Sep 17 15:19:50.934301 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.61.66:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/i.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fawAAAI4"]
[Thu Sep 17 15:19:50.982191 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/postmark/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fbQAAANE"]
[Thu Sep 17 15:19:51.003698 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.204.169.220:39416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fbwAAALU"]
[Thu Sep 17 15:19:51.165307 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailgun/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2fcwAAANk"]
[Thu Sep 17 15:19:51.182277 2026] [security2:error] [pid 1012520:tid 1012752] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/z60.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fdgAAAOo"]
[Thu Sep 17 15:19:51.182393 2026] [security2:error] [pid 1012520:tid 1012752] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/z60.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fdgAAAOo"]
[Thu Sep 17 15:19:51.241883 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.95.61.66:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxZdwpXMN3p_zkwXf2feAAAAJ8"]
[Thu Sep 17 15:19:51.297961 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.32.0.94:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/i.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fegAAALY"]
[Thu Sep 17 15:19:51.333371 2026] [security2:error] [pid 1012520:tid 1012730] [client 104.28.198.244:22758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fewAAANQ"]
[Thu Sep 17 15:19:51.333517 2026] [security2:error] [pid 1012520:tid 1012730] [client 104.28.198.244:22758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fewAAANQ"]
[Thu Sep 17 15:19:51.349324 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mandrill/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2ffgAAAKc"]
[Thu Sep 17 15:19:51.411682 2026] [security2:error] [pid 1012520:tid 1012671] [client 195.2.78.191:52485] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.78.191" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.sqlerudition.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fgwAAAJk"], referer: https://www.sqlerudition.com/suppress-the-error-number-severity-level-and-state-number-in-the-error-output/
[Thu Sep 17 15:19:51.411818 2026] [security2:error] [pid 1012520:tid 1012671] [client 195.2.78.191:52485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sqlerudition.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fgwAAAJk"], referer: https://www.sqlerudition.com/suppress-the-error-number-severity-level-and-state-number-in-the-error-output/
[Thu Sep 17 15:19:51.532250 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailjet/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2fhgAAAKk"]
[Thu Sep 17 15:19:51.549749 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:53108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fhwAAAJg"]
[Thu Sep 17 15:19:51.684150 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/pJPoKA.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fiQAAAO8"]
[Thu Sep 17 15:19:51.684268 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/pJPoKA.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fiQAAAO8"]
[Thu Sep 17 15:19:51.713498 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/brevo/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2figAAAK0"]
[Thu Sep 17 15:19:51.721983 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.204.169.220:39420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fiwAAAPw"]
[Thu Sep 17 15:19:51.754102 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/pi.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fjQAAAPE"]
[Thu Sep 17 15:19:51.755573 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "aqxZdwpXMN3p_zkwXf2fjAAAAQQ"]
[Thu Sep 17 15:19:51.889546 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.95.61.66:53116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/test.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fkQAAAP0"]
[Thu Sep 17 15:19:51.897350 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/transactional/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2fkgAAANg"]
[Thu Sep 17 15:19:51.929361 2026] [security2:error] [pid 1012520:tid 1012765] [client 103.61.184.148:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fkwAAAPc"]
[Thu Sep 17 15:19:51.929454 2026] [security2:error] [pid 1012520:tid 1012765] [client 103.61.184.148:58732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fkwAAAPc"]
[Thu Sep 17 15:19:51.984512 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "aqxZdwpXMN3p_zkwXf2flQAAAMY"]
[Thu Sep 17 15:19:52.081348 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/bulk/.env"] [unique_id "aqxZeApXMN3p_zkwXf2fmgAAAM4"]
[Thu Sep 17 15:19:52.163891 2026] [security2:error] [pid 1012520:tid 1012614] [remote 216.73.217.142:9521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxZeApXMN3p_zkwXf2fnQAAzFw"]
[Thu Sep 17 15:19:52.206715 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/24.php"] [unique_id "aqxZeApXMN3p_zkwXf2fngAAAPA"]
[Thu Sep 17 15:19:52.206824 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/24.php"] [unique_id "aqxZeApXMN3p_zkwXf2fngAAAPA"]
[Thu Sep 17 15:19:52.228339 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.32.0.94:45186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/pinfo.php"] [unique_id "aqxZeApXMN3p_zkwXf2foAAAAP8"]
[Thu Sep 17 15:19:52.252056 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.95.61.66:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/p.php"] [unique_id "aqxZeApXMN3p_zkwXf2fogAAAKw"]
[Thu Sep 17 15:19:52.269096 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/aws/.env"] [unique_id "aqxZeApXMN3p_zkwXf2fpAAAAIs"]
[Thu Sep 17 15:19:52.320299 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.204.169.220:39436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZeApXMN3p_zkwXf2fpQAAAME"]
[Thu Sep 17 15:19:52.457294 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/azure/.env"] [unique_id "aqxZeApXMN3p_zkwXf2frQAAAM8"]
[Thu Sep 17 15:19:52.642724 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/gcp/.env"] [unique_id "aqxZeApXMN3p_zkwXf2f8AAAAKY"]
[Thu Sep 17 15:19:52.696510 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/test.php"] [unique_id "aqxZeApXMN3p_zkwXf2f9gAAALw"]
[Thu Sep 17 15:19:52.708241 2026] [security2:error] [pid 1012520:tid 1012675] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/xxw.php"] [unique_id "aqxZeApXMN3p_zkwXf2f-AAAAJ0"]
[Thu Sep 17 15:19:52.708322 2026] [security2:error] [pid 1012520:tid 1012675] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/xxw.php"] [unique_id "aqxZeApXMN3p_zkwXf2f-AAAAJ0"]
[Thu Sep 17 15:19:52.719749 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.95.61.66:53140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxZeApXMN3p_zkwXf2f-QAAANs"]
[Thu Sep 17 15:19:52.824425 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cloud/.env"] [unique_id "aqxZeApXMN3p_zkwXf2f_AAAAKU"]
[Thu Sep 17 15:19:52.914704 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.204.169.220:39438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZeApXMN3p_zkwXf2gBAAAAP4"]
[Thu Sep 17 15:19:53.016264 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/infrastructure/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gBQAAAOQ"]
[Thu Sep 17 15:19:53.087543 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gCgAAANk"]
[Thu Sep 17 15:19:53.198883 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/docker/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gEAAAAKo"]
[Thu Sep 17 15:19:53.220109 2026] [security2:error] [pid 1012520:tid 1012755] [client 154.190.208.131:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEQAAAO0"]
[Thu Sep 17 15:19:53.220418 2026] [security2:error] [pid 1012520:tid 1012672] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/min.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEgAAAJo"]
[Thu Sep 17 15:19:53.220509 2026] [security2:error] [pid 1012520:tid 1012672] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/min.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEgAAAJo"]
[Thu Sep 17 15:19:53.226252 2026] [security2:error] [pid 1012520:tid 1012755] [client 154.190.208.131:42040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEQAAAO0"]
[Thu Sep 17 15:19:53.280480 2026] [security2:error] [pid 1012520:tid 1012727] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/backup/"] [unique_id "aqxZeApXMN3p_zkwXf2f9wAA0Qg"], referer: http://www.24eastyard.com/backup/
[Thu Sep 17 15:19:53.360992 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:45200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gDQAAAIw"]
[Thu Sep 17 15:19:53.379920 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/k8s/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gGQAAAOg"]
[Thu Sep 17 15:19:53.418839 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.95.61.66:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gGwAAAIc"]
[Thu Sep 17 15:19:53.565491 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/kubernetes/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gHwAAAK4"]
[Thu Sep 17 15:19:53.568546 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.204.169.220:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZeQpXMN3p_zkwXf2gIAAAAIU"]
[Thu Sep 17 15:19:53.659515 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:45200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/p.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gIwAAAPE"]
[Thu Sep 17 15:19:53.724914 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/n30n.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gKQAAAJE"]
[Thu Sep 17 15:19:53.725039 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/n30n.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gKQAAAJE"]
[Thu Sep 17 15:19:53.738156 2026] [security2:error] [pid 1012520:tid 1012693] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/wp/"] [unique_id "aqxZeQpXMN3p_zkwXf2gKAAAryY"], referer: http://www.24eastyard.com/wp/
[Thu Sep 17 15:19:53.755628 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/terraform/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gKwAAAPo"]
[Thu Sep 17 15:19:53.802121 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.95.61.66:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gLAAAAJA"]
[Thu Sep 17 15:19:53.926480 2026] [security2:error] [pid 1012520:tid 1012734] [client 185.55.149.49:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gMAAAANg"]
[Thu Sep 17 15:19:53.926556 2026] [security2:error] [pid 1012520:tid 1012734] [client 185.55.149.49:54168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gMAAAANg"]
[Thu Sep 17 15:19:53.935778 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/ansible/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gMQAAAJU"]
[Thu Sep 17 15:19:54.102725 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.61.66:53178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gOQAAAP8"]
[Thu Sep 17 15:19:54.102738 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:39448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZegpXMN3p_zkwXf2gOAAAANI"]
[Thu Sep 17 15:19:54.113799 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.32.0.94:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/debug.php"] [unique_id "aqxZegpXMN3p_zkwXf2gOgAAAPc"]
[Thu Sep 17 15:19:54.116984 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.git/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gOwAAAJs"]
[Thu Sep 17 15:19:54.199762 2026] [security2:error] [pid 1012520:tid 1012729] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/new/"] [unique_id "aqxZegpXMN3p_zkwXf2gPwAA0yo"], referer: http://www.24eastyard.com/new/
[Thu Sep 17 15:19:54.243057 2026] [security2:error] [pid 1012520:tid 1012706] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/bnmtp.php"] [unique_id "aqxZegpXMN3p_zkwXf2gQAAAALw"]
[Thu Sep 17 15:19:54.243170 2026] [security2:error] [pid 1012520:tid 1012706] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/bnmtp.php"] [unique_id "aqxZegpXMN3p_zkwXf2gQAAAALw"]
[Thu Sep 17 15:19:54.268458 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gQQAAAJ0"]
[Thu Sep 17 15:19:54.298073 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/ci/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gQgAAAPk"]
[Thu Sep 17 15:19:54.455859 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.95.61.66:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gSgAAAL4"]
[Thu Sep 17 15:19:54.478219 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cd/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gSwAAAPY"]
[Thu Sep 17 15:19:54.494894 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gTAAAAOM"]
[Thu Sep 17 15:19:54.564386 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.32.0.94:37780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gTQAAAPg"]
[Thu Sep 17 15:19:54.656632 2026] [security2:error] [pid 1012520:tid 1012661] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/wordpress/"] [unique_id "aqxZegpXMN3p_zkwXf2gUgAAj1Q"], referer: http://www.24eastyard.com/wordpress/
[Thu Sep 17 15:19:54.661578 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/jenkins/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gUwAAAOs"]
[Thu Sep 17 15:19:54.721136 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gVQAAAKA"]
[Thu Sep 17 15:19:54.728123 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:39464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php~"] [unique_id "aqxZegpXMN3p_zkwXf2gVwAAAMo"]
[Thu Sep 17 15:19:54.747348 2026] [security2:error] [pid 1012520:tid 1012669] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ebkid.php"] [unique_id "aqxZegpXMN3p_zkwXf2gWAAAAJc"